From 38a777ceb5c99737e2acd056bdc604c03c4ef383 Mon Sep 17 00:00:00 2001 From: Adam Jackson Date: Tue, 19 Jan 2021 19:52:41 -0500 Subject: [PATCH 01/74] Disable int10 and vbe on RHEL Disable DRI1 Stop overriding the vendor name --- xorg-x11-server.spec | 22 ++++++++++++++++------ 1 file changed, 16 insertions(+), 6 deletions(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index de26148..a34bf8c 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.10 -Release: 1%{?gitdate:.%{gitdate}}%{?dist} +Release: 2%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -357,15 +357,20 @@ export CFLAGS="$RPM_OPT_FLAGS -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1" export CXXFLAGS="$RPM_OPT_FLAGS -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1" export LDFLAGS="$RPM_LD_FLAGS -specs=/usr/lib/rpm/redhat/redhat-hardened-ld" +%if !0%{?rhel} %ifnarch %{ix86} x86_64 +%global int10_arch 1 +%endif +%endif + +%if %{undefined int10_arch} %global no_int10 --disable-vbe --disable-int10-module %endif %global kdrive --enable-kdrive --enable-xephyr --disable-xfake --disable-xfbdev %global xservers --enable-xvfb --enable-xnest %{kdrive} --enable-xorg %global default_font_path "catalogue:/etc/X11/fontpath.d,built-ins" -%global dri_flags --enable-dri --enable-dri2 %{?!rhel:--enable-dri3} --enable-suid-wrapper --enable-glamor -%global bodhi_flags --with-vendor-name="Fedora Project" +%global dri_flags --disable-dri --enable-dri2 %{?!rhel:--enable-dri3} --enable-suid-wrapper --enable-glamor autoreconf -f -v --install || exit 1 @@ -374,7 +379,7 @@ autoreconf -f -v --install || exit 1 --enable-xwayland-eglstream \ --disable-static \ --with-pic \ - %{?no_int10} --with-int10=x86emu \ + %{?no_int10} \ --with-default-font-path=%{default_font_path} \ --with-module-dir=%{_libdir}/xorg/modules \ --with-builderstring="Build ID: %{name} %{version}-%{release}" \ @@ -388,7 +393,7 @@ autoreconf -f -v --install || exit 1 --disable-unit-tests \ --enable-dmx \ --enable-xwayland \ - %{dri_flags} %{?bodhi_flags} \ + %{dri_flags} \ ${CONFIGURE} make V=1 %{?_smp_mflags} @@ -485,7 +490,7 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %{_libdir}/xorg/modules/libshadowfb.so %{_libdir}/xorg/modules/libvgahw.so %{_libdir}/xorg/modules/libwfb.so -%ifarch %{ix86} x86_64 +%if %{defined int10_arch} %{_libdir}/xorg/modules/libint10.so %{_libdir}/xorg/modules/libvbe.so %endif @@ -551,6 +556,11 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Tue Jan 19 2021 Adam Jackson - 1.20.10-2 +- Disable int10 and vbe on RHEL +- Disable DRI1 +- Stop overriding the vendor name + * Wed Dec 2 2020 Olivier Fourdan - 1.20.10-1 - xserver 1.20.10 (CVE-2020-14360, CVE-2020-25712) From 29f0985634f7e10e348dba264bcac14ea57d015a Mon Sep 17 00:00:00 2001 From: Adam Jackson Date: Tue, 19 Jan 2021 20:11:43 -0500 Subject: [PATCH 02/74] fix thinko --- xorg-x11-server.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index a34bf8c..54bbc3d 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -358,7 +358,7 @@ export CXXFLAGS="$RPM_OPT_FLAGS -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1" export LDFLAGS="$RPM_LD_FLAGS -specs=/usr/lib/rpm/redhat/redhat-hardened-ld" %if !0%{?rhel} -%ifnarch %{ix86} x86_64 +%ifarch %{ix86} x86_64 %global int10_arch 1 %endif %endif From 11999b23073dc485f86a13e43408cbe140345df2 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 28 Jan 2021 00:18:09 +0000 Subject: [PATCH 03/74] - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- xorg-x11-server.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 54bbc3d..fdf77f6 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.10 -Release: 2%{?gitdate:.%{gitdate}}%{?dist} +Release: 3%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -556,6 +556,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Thu Jan 28 2021 Fedora Release Engineering - 1.20.10-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild + * Tue Jan 19 2021 Adam Jackson - 1.20.10-2 - Disable int10 and vbe on RHEL - Disable DRI1 From b1458e4567cd8795d5d660be512877750cde9c2f Mon Sep 17 00:00:00 2001 From: Olivier Fourdan Date: Mon, 1 Feb 2021 11:26:56 +0100 Subject: [PATCH 04/74] Remove Xwayland from the xserver builds --- 0001-dix-Add-GetCurrentClient-helper.patch | 116 ----- ...p_viewport-wayland-extension-support.patch | 119 ----- ...fer_damage-instead-of-surface-damage.patch | 160 ------ ...e-output-modes-to-xrandr-output-mode.patch | 207 -------- ...ayland-Use-RandR-1.2-interface-rev-2.patch | 139 ------ ...xwayland-Add-per-client-private-data.patch | 80 --- ...port-for-storing-per-client-per-outp.patch | 149 ------ ...port-for-randr-resolution-change-emu.patch | 462 ------------------ ...lRRModeToDisplayMode-helper-function.patch | 101 ---- ...VidModeGetCurrentRRMode-helper-to-th.patch | 193 -------- ...mode-mode-changing-emulation-support.patch | 236 --------- ...dow_should_enable_viewport-Add-extra.patch | 57 --- ...AYLAND_RANDR_EMU_MONITOR_RECTS-prope.patch | 205 -------- ...lient-id-for-the-window-manager-clie.patch | 137 ------ ...Reuse-viewport-instead-of-recreating.patch | 50 -- ...Recurse-on-finding-the-none-wm-owner.patch | 81 --- ...ndow_get_none_wm_owner-return-a-Wind.patch | 82 ---- ...-emulation-on-client-toplevel-resize.patch | 121 ----- ...eck-resolution-change-emulation-when.patch | 45 -- ...Also-hook-screen-s-MoveWindow-method.patch | 83 ---- ...lated-modes-not-being-removed-when-s.patch | 63 --- ...l_window_check_resolution_change_emu.patch | 48 -- ...ting-of-_XWAYLAND_RANDR_EMU_MONITOR_.patch | 76 --- ...unnecessary-xwl_window_is_toplevel-c.patch | 49 -- ...ndow_get_client_toplevel-non-recursi.patch | 37 -- xorg-x11-server.spec | 51 +- 26 files changed, 5 insertions(+), 3142 deletions(-) delete mode 100644 0001-dix-Add-GetCurrentClient-helper.patch delete mode 100644 0002-xwayland-Add-wp_viewport-wayland-extension-support.patch delete mode 100644 0003-xwayland-Use-buffer_damage-instead-of-surface-damage.patch delete mode 100644 0004-xwayland-Add-fake-output-modes-to-xrandr-output-mode.patch delete mode 100644 0005-xwayland-Use-RandR-1.2-interface-rev-2.patch delete mode 100644 0006-xwayland-Add-per-client-private-data.patch delete mode 100644 0007-xwayland-Add-support-for-storing-per-client-per-outp.patch delete mode 100644 0008-xwayland-Add-support-for-randr-resolution-change-emu.patch delete mode 100644 0009-xwayland-Add-xwlRRModeToDisplayMode-helper-function.patch delete mode 100644 0010-xwayland-Add-xwlVidModeGetCurrentRRMode-helper-to-th.patch delete mode 100644 0011-xwayland-Add-vidmode-mode-changing-emulation-support.patch delete mode 100644 0012-xwayland-xwl_window_should_enable_viewport-Add-extra.patch delete mode 100644 0013-xwayland-Set-_XWAYLAND_RANDR_EMU_MONITOR_RECTS-prope.patch delete mode 100644 0014-xwayland-Cache-client-id-for-the-window-manager-clie.patch delete mode 100644 0015-xwayland-Reuse-viewport-instead-of-recreating.patch delete mode 100644 0016-xwayland-Recurse-on-finding-the-none-wm-owner.patch delete mode 100644 0017-xwayland-Make-window_get_none_wm_owner-return-a-Wind.patch delete mode 100644 0018-xwayland-Check-emulation-on-client-toplevel-resize.patch delete mode 100644 0019-xwayland-Also-check-resolution-change-emulation-when.patch delete mode 100644 0020-xwayland-Also-hook-screen-s-MoveWindow-method.patch delete mode 100644 0021-xwayland-Fix-emulated-modes-not-being-removed-when-s.patch delete mode 100644 0022-xwayland-Call-xwl_window_check_resolution_change_emu.patch delete mode 100644 0023-xwayland-Fix-setting-of-_XWAYLAND_RANDR_EMU_MONITOR_.patch delete mode 100644 0024-xwayland-Remove-unnecessary-xwl_window_is_toplevel-c.patch delete mode 100644 0025-xwayland-Make-window_get_client_toplevel-non-recursi.patch diff --git a/0001-dix-Add-GetCurrentClient-helper.patch b/0001-dix-Add-GetCurrentClient-helper.patch deleted file mode 100644 index 3da345c..0000000 --- a/0001-dix-Add-GetCurrentClient-helper.patch +++ /dev/null @@ -1,116 +0,0 @@ -From a815e5f51f75684a53d8fa14b596e03b738cd281 Mon Sep 17 00:00:00 2001 -From: Hans de Goede -Date: Thu, 29 Aug 2019 14:18:28 +0200 -Subject: [PATCH xserver 01/25] dix: Add GetCurrentClient helper -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Request-handlers as registered in the requestVector array, always get -passed the clientPtr for the client which sent the request. -But the implementation of many request-handlers typically consists of -a generic handler calling implementation specific callbacks and / or -various helpers often multiple levels deep and in many cases the clientPtr -does not get passed to the callbacks / helpers. - -This means that in some places where we would like to have access to the -current-client, we cannot easily access it and fixing this would require -a lot of work and often would involve ABI breakage. - -This commit adds a GetCurrentClient helper which can be used as a -shortcut to get access to the clienPtr for the currently being processed -request without needing a lot of refactoring and ABI breakage. - -Note using this new GetCurrentClient helper is only safe for code -which only runs from the main thread, this new variable MUST NOT be used -by code which runs from signal handlers or from the input-thread. - -The specific use-case which resulted in the creation of this patch is adding -support for emulation of randr / vidmode resolution changes to Xwayland. -This emulation will not actually change the monitor resolution instead it -will scale any window with a size which exactly matches the requested -resolution to fill the entire monitor. The main use-case for this is -games which are hard-coded to render at a specific resolution and have -sofar relied on randr / vidmode to change the monitor resolution when going -fullscreen. - -To make this emulation as robust as possible (e.g. avoid accidentally scaling -windows from other apps) we want to make the emulated resolution a per client -state. But e.g. the RRSetCrtc function does not take a client pointer; and is -a (used) part of the Xorg server ABI (note the problem is not just limited -to RRSetCrtc). - -Reviewed-by: Olivier Fourdan -Reviewed-by: Michel Dänzer -Signed-off-by: Hans de Goede -(cherry picked from commit 834a467af978ac7a24ed17b8c8e58b6cddb4faf9) ---- - dix/dispatch.c | 23 ++++++++++++++++++++++- - include/dix.h | 1 + - 2 files changed, 23 insertions(+), 1 deletion(-) - -diff --git a/dix/dispatch.c b/dix/dispatch.c -index a33bfaa9e..2b1cf1a74 100644 ---- a/dix/dispatch.c -+++ b/dix/dispatch.c -@@ -148,6 +148,7 @@ xConnSetupPrefix connSetupPrefix; - PaddingInfo PixmapWidthPaddingInfo[33]; - - static ClientPtr grabClient; -+static ClientPtr currentClient; /* Client for the request currently being dispatched */ - - #define GrabNone 0 - #define GrabActive 1 -@@ -176,6 +177,23 @@ volatile char isItTimeToYield; - #define SAME_SCREENS(a, b) (\ - (a.pScreen == b.pScreen)) - -+ClientPtr -+GetCurrentClient(void) -+{ -+ if (in_input_thread()) { -+ static Bool warned; -+ -+ if (!warned) { -+ ErrorF("[dix] Error GetCurrentClient called from input-thread\n"); -+ warned = TRUE; -+ } -+ -+ return NULL; -+ } -+ -+ return currentClient; -+} -+ - void - SetInputCheck(HWEventQueuePtr c0, HWEventQueuePtr c1) - { -@@ -474,9 +492,12 @@ Dispatch(void) - result = BadLength; - else { - result = XaceHookDispatch(client, client->majorOp); -- if (result == Success) -+ if (result == Success) { -+ currentClient = client; - result = - (*client->requestVector[client->majorOp]) (client); -+ currentClient = NULL; -+ } - } - if (!SmartScheduleSignalEnable) - SmartScheduleTime = GetTimeInMillis(); -diff --git a/include/dix.h b/include/dix.h -index b6e2bcfde..d65060cb6 100644 ---- a/include/dix.h -+++ b/include/dix.h -@@ -148,6 +148,7 @@ typedef struct _TimeStamp { - } TimeStamp; - - /* dispatch.c */ -+extern _X_EXPORT ClientPtr GetCurrentClient(void); - - extern _X_EXPORT void SetInputCheck(HWEventQueuePtr /*c0 */ , - HWEventQueuePtr /*c1 */ ); --- -2.28.0 - diff --git a/0002-xwayland-Add-wp_viewport-wayland-extension-support.patch b/0002-xwayland-Add-wp_viewport-wayland-extension-support.patch deleted file mode 100644 index e4518a0..0000000 --- a/0002-xwayland-Add-wp_viewport-wayland-extension-support.patch +++ /dev/null @@ -1,119 +0,0 @@ -From 0a3046286e69b171c319ff419c94cf62929246bf Mon Sep 17 00:00:00 2001 -From: Robert Mader -Date: Mon, 22 Jan 2018 22:02:32 +0100 -Subject: [PATCH xserver 02/25] xwayland: Add wp_viewport wayland extension - support -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -This commit adds support for the wayland wp_viewport extension, note -nothing uses this yet. - -This is a preparation patch for adding support for fake mode-changes through -xrandr for apps which want to change the resolution when going fullscreen. - -[hdegoede@redhat.com: Split the code for the extension out into its own patch] - -Reviewed-by: Olivier Fourdan -Acked-by: Michel Dänzer -Signed-off-by: Hans de Goede -(cherry picked from commit 47bba4625339592d08b375bcd8e51029c0000850) ---- - hw/xwayland/Makefile.am | 9 ++++++++- - hw/xwayland/meson.build | 3 +++ - hw/xwayland/xwayland.c | 3 +++ - hw/xwayland/xwayland.h | 2 ++ - 4 files changed, 16 insertions(+), 1 deletion(-) - -diff --git a/hw/xwayland/Makefile.am b/hw/xwayland/Makefile.am -index bc1cb8506..49aae3d8b 100644 ---- a/hw/xwayland/Makefile.am -+++ b/hw/xwayland/Makefile.am -@@ -71,7 +71,9 @@ Xwayland_built_sources += \ - xdg-output-unstable-v1-protocol.c \ - xdg-output-unstable-v1-client-protocol.h \ - linux-dmabuf-unstable-v1-client-protocol.h \ -- linux-dmabuf-unstable-v1-protocol.c -+ linux-dmabuf-unstable-v1-protocol.c \ -+ viewporter-client-protocol.h \ -+ viewporter-protocol.c - - if XWAYLAND_EGLSTREAM - Xwayland_built_sources += \ -@@ -120,6 +122,11 @@ linux-dmabuf-unstable-v1-protocol.c : $(WAYLAND_PROTOCOLS_DATADIR)/unstable/linu - linux-dmabuf-unstable-v1-client-protocol.h : $(WAYLAND_PROTOCOLS_DATADIR)/unstable/linux-dmabuf/linux-dmabuf-unstable-v1.xml - $(AM_V_GEN)$(WAYLAND_SCANNER) client-header < $< > $@ - -+viewporter-protocol.c: $(WAYLAND_PROTOCOLS_DATADIR)/stable/viewporter/viewporter.xml -+ $(AM_V_GEN)$(WAYLAND_SCANNER) @SCANNER_ARG@ < $< > $@ -+viewporter-client-protocol.h: $(WAYLAND_PROTOCOLS_DATADIR)/stable/viewporter/viewporter.xml -+ $(AM_V_GEN)$(WAYLAND_SCANNER) client-header < $< > $@ -+ - wayland-eglstream-client-protocol.h : $(WAYLAND_EGLSTREAM_DATADIR)/wayland-eglstream.xml - $(AM_V_GEN)$(WAYLAND_SCANNER) client-header < $< > $@ - wayland-eglstream-controller-client-protocol.h : $(WAYLAND_EGLSTREAM_DATADIR)/wayland-eglstream-controller.xml -diff --git a/hw/xwayland/meson.build b/hw/xwayland/meson.build -index 36bf2133a..4a8d171bb 100644 ---- a/hw/xwayland/meson.build -+++ b/hw/xwayland/meson.build -@@ -21,6 +21,7 @@ tablet_xml = join_paths(protodir, 'unstable', 'tablet', 'tablet-unstable-v2.xml' - kbgrab_xml = join_paths(protodir, 'unstable', 'xwayland-keyboard-grab', 'xwayland-keyboard-grab-unstable-v1.xml') - xdg_output_xml = join_paths(protodir, 'unstable', 'xdg-output', 'xdg-output-unstable-v1.xml') - dmabuf_xml = join_paths(protodir, 'unstable', 'linux-dmabuf', 'linux-dmabuf-unstable-v1.xml') -+viewporter_xml = join_paths(protodir, 'stable', 'viewporter', 'viewporter.xml') - - client_header = generator(scanner, - output : '@BASENAME@-client-protocol.h', -@@ -43,12 +44,14 @@ srcs += client_header.process(tablet_xml) - srcs += client_header.process(kbgrab_xml) - srcs += client_header.process(xdg_output_xml) - srcs += client_header.process(dmabuf_xml) -+srcs += client_header.process(viewporter_xml) - srcs += code.process(relative_xml) - srcs += code.process(pointer_xml) - srcs += code.process(tablet_xml) - srcs += code.process(kbgrab_xml) - srcs += code.process(xdg_output_xml) - srcs += code.process(dmabuf_xml) -+srcs += code.process(viewporter_xml) - - xwayland_glamor = [] - eglstream_srcs = [] -diff --git a/hw/xwayland/xwayland.c b/hw/xwayland/xwayland.c -index b353167c3..a70c1002f 100644 ---- a/hw/xwayland/xwayland.c -+++ b/hw/xwayland/xwayland.c -@@ -912,6 +912,9 @@ registry_global(void *data, struct wl_registry *registry, uint32_t id, - wl_registry_bind(registry, id, &zxdg_output_manager_v1_interface, 1); - xwl_screen_init_xdg_output(xwl_screen); - } -+ else if (strcmp(interface, "wp_viewporter") == 0) { -+ xwl_screen->viewporter = wl_registry_bind(registry, id, &wp_viewporter_interface, 1); -+ } - #ifdef XWL_HAS_GLAMOR - else if (xwl_screen->glamor) { - xwl_glamor_init_wl_registry(xwl_screen, registry, id, interface, -diff --git a/hw/xwayland/xwayland.h b/hw/xwayland/xwayland.h -index b9495b313..91ae21eeb 100644 ---- a/hw/xwayland/xwayland.h -+++ b/hw/xwayland/xwayland.h -@@ -48,6 +48,7 @@ - #include "xwayland-keyboard-grab-unstable-v1-client-protocol.h" - #include "xdg-output-unstable-v1-client-protocol.h" - #include "linux-dmabuf-unstable-v1-client-protocol.h" -+#include "viewporter-client-protocol.h" - - struct xwl_format { - uint32_t format; -@@ -151,6 +152,7 @@ struct xwl_screen { - struct zwp_pointer_constraints_v1 *pointer_constraints; - struct zwp_xwayland_keyboard_grab_manager_v1 *wp_grab; - struct zxdg_output_manager_v1 *xdg_output_manager; -+ struct wp_viewporter *viewporter; - uint32_t serial; - - #define XWL_FORMAT_ARGB8888 (1 << 0) --- -2.28.0 - diff --git a/0003-xwayland-Use-buffer_damage-instead-of-surface-damage.patch b/0003-xwayland-Use-buffer_damage-instead-of-surface-damage.patch deleted file mode 100644 index 0627415..0000000 --- a/0003-xwayland-Use-buffer_damage-instead-of-surface-damage.patch +++ /dev/null @@ -1,160 +0,0 @@ -From 30859f64d1718d1476648dcddbb3d81c2f932828 Mon Sep 17 00:00:00 2001 -From: Robert Mader -Date: Tue, 2 Jul 2019 12:03:12 +0200 -Subject: [PATCH xserver 03/25] xwayland: Use buffer_damage instead of surface - damage if available -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -When a viewport is set, damage will only work properly when using -wl_surface_damage_buffer instead of wl_surface_damage. - -When no viewport is set, there should be no difference between -surface and buffer damage. - -This is a preparation patch for using viewport to add support for fake -mode-changes through xrandr for apps which want to change the resolution -when going fullscreen. - -Changes by Hans de Goede : --Split the damage changes out into their own patch --Add xwl_surface_damage helper --Also use buffer_damage / the new helper for the present and cursor code - -Reviewed-by: Olivier Fourdan -Acked-by: Michel Dänzer -Signed-off-by: Hans de Goede -(cherry picked from commit 7c6f17790d3aedb164481264b0f05a8a14103731) ---- - hw/xwayland/xwayland-cursor.c | 12 ++++++------ - hw/xwayland/xwayland-present.c | 10 +++++----- - hw/xwayland/xwayland.c | 29 +++++++++++++++++++++++------ - hw/xwayland/xwayland.h | 3 +++ - 4 files changed, 37 insertions(+), 17 deletions(-) - -diff --git a/hw/xwayland/xwayland-cursor.c b/hw/xwayland/xwayland-cursor.c -index 66720bcc0..cbc715061 100644 ---- a/hw/xwayland/xwayland-cursor.c -+++ b/hw/xwayland/xwayland-cursor.c -@@ -165,9 +165,9 @@ xwl_seat_set_cursor(struct xwl_seat *xwl_seat) - xwl_seat->x_cursor->bits->yhot); - wl_surface_attach(xwl_cursor->surface, - xwl_shm_pixmap_get_wl_buffer(pixmap), 0, 0); -- wl_surface_damage(xwl_cursor->surface, 0, 0, -- xwl_seat->x_cursor->bits->width, -- xwl_seat->x_cursor->bits->height); -+ xwl_surface_damage(xwl_seat->xwl_screen, xwl_cursor->surface, 0, 0, -+ xwl_seat->x_cursor->bits->width, -+ xwl_seat->x_cursor->bits->height); - - xwl_cursor->frame_cb = wl_surface_frame(xwl_cursor->surface); - wl_callback_add_listener(xwl_cursor->frame_cb, &frame_listener, xwl_cursor); -@@ -217,9 +217,9 @@ xwl_tablet_tool_set_cursor(struct xwl_tablet_tool *xwl_tablet_tool) - xwl_seat->x_cursor->bits->yhot); - wl_surface_attach(xwl_cursor->surface, - xwl_shm_pixmap_get_wl_buffer(pixmap), 0, 0); -- wl_surface_damage(xwl_cursor->surface, 0, 0, -- xwl_seat->x_cursor->bits->width, -- xwl_seat->x_cursor->bits->height); -+ xwl_surface_damage(xwl_seat->xwl_screen, xwl_cursor->surface, 0, 0, -+ xwl_seat->x_cursor->bits->width, -+ xwl_seat->x_cursor->bits->height); - - xwl_cursor->frame_cb = wl_surface_frame(xwl_cursor->surface); - wl_callback_add_listener(xwl_cursor->frame_cb, &frame_listener, xwl_cursor); -diff --git a/hw/xwayland/xwayland-present.c b/hw/xwayland/xwayland-present.c -index d177abdd8..f4027f91e 100644 ---- a/hw/xwayland/xwayland-present.c -+++ b/hw/xwayland/xwayland-present.c -@@ -505,11 +505,11 @@ xwl_present_flip(WindowPtr present_window, - /* Realign timer */ - xwl_present_reset_timer(xwl_present_window); - -- wl_surface_damage(xwl_window->surface, -- damage_box->x1 - present_window->drawable.x, -- damage_box->y1 - present_window->drawable.y, -- damage_box->x2 - damage_box->x1, -- damage_box->y2 - damage_box->y1); -+ xwl_surface_damage(xwl_window->xwl_screen, xwl_window->surface, -+ damage_box->x1 - present_window->drawable.x, -+ damage_box->y1 - present_window->drawable.y, -+ damage_box->x2 - damage_box->x1, -+ damage_box->y2 - damage_box->y1); - - wl_surface_commit(xwl_window->surface); - -diff --git a/hw/xwayland/xwayland.c b/hw/xwayland/xwayland.c -index a70c1002f..811257b00 100644 ---- a/hw/xwayland/xwayland.c -+++ b/hw/xwayland/xwayland.c -@@ -792,6 +792,16 @@ xwl_destroy_window(WindowPtr window) - return ret; - } - -+void xwl_surface_damage(struct xwl_screen *xwl_screen, -+ struct wl_surface *surface, -+ int32_t x, int32_t y, int32_t width, int32_t height) -+{ -+ if (wl_surface_get_version(surface) >= WL_SURFACE_DAMAGE_BUFFER_SINCE_VERSION) -+ wl_surface_damage_buffer(surface, x, y, width, height); -+ else -+ wl_surface_damage(surface, x, y, width, height); -+} -+ - static void - xwl_window_post_damage(struct xwl_window *xwl_window) - { -@@ -828,13 +838,15 @@ xwl_window_post_damage(struct xwl_window *xwl_window) - */ - if (RegionNumRects(region) > 256) { - box = RegionExtents(region); -- wl_surface_damage(xwl_window->surface, box->x1, box->y1, -- box->x2 - box->x1, box->y2 - box->y1); -+ xwl_surface_damage(xwl_screen, xwl_window->surface, box->x1, box->y1, -+ box->x2 - box->x1, box->y2 - box->y1); - } else { - box = RegionRects(region); -- for (i = 0; i < RegionNumRects(region); i++, box++) -- wl_surface_damage(xwl_window->surface, box->x1, box->y1, -- box->x2 - box->x1, box->y2 - box->y1); -+ for (i = 0; i < RegionNumRects(region); i++, box++) { -+ xwl_surface_damage(xwl_screen, xwl_window->surface, -+ box->x1, box->y1, -+ box->x2 - box->x1, box->y2 - box->y1); -+ } - } - - xwl_window_create_frame_callback(xwl_window); -@@ -893,8 +905,13 @@ registry_global(void *data, struct wl_registry *registry, uint32_t id, - struct xwl_screen *xwl_screen = data; - - if (strcmp(interface, "wl_compositor") == 0) { -+ uint32_t request_version = 1; -+ -+ if (version >= WL_SURFACE_DAMAGE_BUFFER_SINCE_VERSION) -+ request_version = WL_SURFACE_DAMAGE_BUFFER_SINCE_VERSION; -+ - xwl_screen->compositor = -- wl_registry_bind(registry, id, &wl_compositor_interface, 1); -+ wl_registry_bind(registry, id, &wl_compositor_interface, request_version); - } - else if (strcmp(interface, "wl_shm") == 0) { - xwl_screen->shm = wl_registry_bind(registry, id, &wl_shm_interface, 1); -diff --git a/hw/xwayland/xwayland.h b/hw/xwayland/xwayland.h -index 91ae21eeb..1244d2e91 100644 ---- a/hw/xwayland/xwayland.h -+++ b/hw/xwayland/xwayland.h -@@ -382,6 +382,9 @@ struct xwl_output { - void xwl_window_create_frame_callback(struct xwl_window *xwl_window); - - void xwl_sync_events (struct xwl_screen *xwl_screen); -+void xwl_surface_damage(struct xwl_screen *xwl_screen, -+ struct wl_surface *surface, -+ int32_t x, int32_t y, int32_t width, int32_t height); - - void xwl_screen_roundtrip (struct xwl_screen *xwl_screen); - --- -2.28.0 - diff --git a/0004-xwayland-Add-fake-output-modes-to-xrandr-output-mode.patch b/0004-xwayland-Add-fake-output-modes-to-xrandr-output-mode.patch deleted file mode 100644 index 45d52a9..0000000 --- a/0004-xwayland-Add-fake-output-modes-to-xrandr-output-mode.patch +++ /dev/null @@ -1,207 +0,0 @@ -From 32987e08e7f1e79ee50ce032cc6c1b6d28e6a50d Mon Sep 17 00:00:00 2001 -From: Hans de Goede -Date: Wed, 26 Jun 2019 16:46:54 +0200 -Subject: [PATCH xserver 04/25] xwayland: Add fake output modes to xrandr - output mode lists -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -This is a preparation patch for adding support for apps which want to -change the resolution when they go fullscreen because they are hardcoded -to render at a specific resolution, e.g. 640x480. - -Follow up patches will fake the mode-switch these apps want by using -WPviewport to scale there pixmap to cover the entire output. - -Reviewed-by: Olivier Fourdan -Acked-by: Michel Dänzer -Signed-off-by: Hans de Goede -(cherry picked from commit 0d656d796071fb637e4969ea800855fe5d1c9728) ---- - hw/xwayland/xwayland-output.c | 112 ++++++++++++++++++++++++++++++++-- - hw/xwayland/xwayland.c | 17 ++++++ - hw/xwayland/xwayland.h | 1 + - 3 files changed, 124 insertions(+), 6 deletions(-) - -diff --git a/hw/xwayland/xwayland-output.c b/hw/xwayland/xwayland-output.c -index ae646c663..4036ba681 100644 ---- a/hw/xwayland/xwayland-output.c -+++ b/hw/xwayland/xwayland-output.c -@@ -208,14 +208,110 @@ update_screen_size(struct xwl_output *xwl_output, int width, int height) - update_desktop_dimensions(); - } - -+/* From hw/xfree86/common/xf86DefModeSet.c with some obscure modes dropped */ -+const int32_t xwl_output_fake_modes[][2] = { -+ /* 4:3 (1.33) */ -+ { 2048, 1536 }, -+ { 1920, 1440 }, -+ { 1600, 1200 }, -+ { 1440, 1080 }, -+ { 1400, 1050 }, -+ { 1280, 1024 }, /* 5:4 (1.25) */ -+ { 1280, 960 }, -+ { 1152, 864 }, -+ { 1024, 768 }, -+ { 800, 600 }, -+ { 640, 480 }, -+ { 320, 240 }, -+ /* 16:10 (1.6) */ -+ { 2560, 1600 }, -+ { 1920, 1200 }, -+ { 1680, 1050 }, -+ { 1440, 900 }, -+ { 1280, 800 }, -+ { 720, 480 }, /* 3:2 (1.5) */ -+ { 640, 400 }, -+ { 320, 200 }, -+ /* 16:9 (1.77) */ -+ { 5120, 2880 }, -+ { 4096, 2304 }, -+ { 3840, 2160 }, -+ { 3200, 1800 }, -+ { 2880, 1620 }, -+ { 2560, 1440 }, -+ { 2048, 1152 }, -+ { 1920, 1080 }, -+ { 1600, 900 }, -+ { 1368, 768 }, -+ { 1280, 720 }, -+ { 1024, 576 }, -+ { 864, 486 }, -+ { 720, 400 }, -+ { 640, 350 }, -+}; -+ -+/* Build an array with RRModes the first mode is the actual output mode, the -+ * rest are fake modes from the xwl_output_fake_modes list. We do this for apps -+ * which want to change resolution when they go fullscreen. -+ * When an app requests a mode-change, we fake it using WPviewport. -+ */ -+static RRModePtr * -+output_get_rr_modes(struct xwl_output *xwl_output, -+ int32_t width, int32_t height, -+ int *count) -+{ -+ struct xwl_screen *xwl_screen = xwl_output->xwl_screen; -+ RRModePtr *rr_modes; -+ int i; -+ -+ rr_modes = xallocarray(ARRAY_SIZE(xwl_output_fake_modes) + 1, sizeof(RRModePtr)); -+ if (!rr_modes) -+ goto err; -+ -+ /* Add actual output mode */ -+ rr_modes[0] = xwayland_cvt(width, height, xwl_output->refresh / 1000.0, 0, 0); -+ if (!rr_modes[0]) -+ goto err; -+ -+ *count = 1; -+ -+ if (!xwl_screen_has_resolution_change_emulation(xwl_screen)) -+ return rr_modes; -+ -+ /* Add fake modes */ -+ for (i = 0; i < ARRAY_SIZE(xwl_output_fake_modes); i++) { -+ /* Skip actual output mode, already added */ -+ if (xwl_output_fake_modes[i][0] == width && -+ xwl_output_fake_modes[i][1] == height) -+ continue; -+ -+ /* Skip modes which are too big, avoid downscaling */ -+ if (xwl_output_fake_modes[i][0] > width || -+ xwl_output_fake_modes[i][1] > height) -+ continue; -+ -+ rr_modes[*count] = xwayland_cvt(xwl_output_fake_modes[i][0], -+ xwl_output_fake_modes[i][1], -+ xwl_output->refresh / 1000.0, 0, 0); -+ if (!rr_modes[*count]) -+ goto err; -+ -+ (*count)++; -+ } -+ -+ return rr_modes; -+err: -+ FatalError("Failed to allocate memory for list of RR modes"); -+} -+ - static void - apply_output_change(struct xwl_output *xwl_output) - { - struct xwl_screen *xwl_screen = xwl_output->xwl_screen; - struct xwl_output *it; -- int mode_width, mode_height; -+ int mode_width, mode_height, count; - int width = 0, height = 0, has_this_output = 0; -- RRModePtr randr_mode; -+ RRModePtr *randr_modes; - Bool need_rotate; - - /* Clear out the "done" received flags */ -@@ -234,12 +330,16 @@ apply_output_change(struct xwl_output *xwl_output) - mode_height = xwl_output->width; - } - -- randr_mode = xwayland_cvt(mode_width, mode_height, -- xwl_output->refresh / 1000.0, 0, 0); -- RROutputSetModes(xwl_output->randr_output, &randr_mode, 1, 1); -- RRCrtcNotify(xwl_output->randr_crtc, randr_mode, -+ /* Build a fresh modes array using the current refresh rate */ -+ randr_modes = output_get_rr_modes(xwl_output, mode_width, mode_height, &count); -+ RROutputSetModes(xwl_output->randr_output, randr_modes, count, 1); -+ RRCrtcNotify(xwl_output->randr_crtc, randr_modes[0], - xwl_output->x, xwl_output->y, - xwl_output->rotation, NULL, 1, &xwl_output->randr_output); -+ /* RROutputSetModes takes ownership of the passed in modes, so we only -+ * have to free the pointer array. -+ */ -+ free(randr_modes); - - xorg_list_for_each_entry(it, &xwl_screen->output_list, link) { - /* output done event is sent even when some property -diff --git a/hw/xwayland/xwayland.c b/hw/xwayland/xwayland.c -index 811257b00..e84515f94 100644 ---- a/hw/xwayland/xwayland.c -+++ b/hw/xwayland/xwayland.c -@@ -154,6 +154,23 @@ xwl_screen_get(ScreenPtr screen) - return dixLookupPrivate(&screen->devPrivates, &xwl_screen_private_key); - } - -+static Bool -+xwl_screen_has_viewport_support(struct xwl_screen *xwl_screen) -+{ -+ return wl_compositor_get_version(xwl_screen->compositor) >= -+ WL_SURFACE_DAMAGE_BUFFER_SINCE_VERSION && -+ xwl_screen->viewporter != NULL; -+} -+ -+Bool -+xwl_screen_has_resolution_change_emulation(struct xwl_screen *xwl_screen) -+{ -+ /* Resolution change emulation is only supported in rootless mode and -+ * it requires viewport support. -+ */ -+ return xwl_screen->rootless && xwl_screen_has_viewport_support(xwl_screen); -+} -+ - static void - xwl_window_set_allow_commits(struct xwl_window *xwl_window, Bool allow, - const char *debug_msg) -diff --git a/hw/xwayland/xwayland.h b/hw/xwayland/xwayland.h -index 1244d2e91..200e18a8d 100644 ---- a/hw/xwayland/xwayland.h -+++ b/hw/xwayland/xwayland.h -@@ -391,6 +391,7 @@ void xwl_screen_roundtrip (struct xwl_screen *xwl_screen); - Bool xwl_screen_init_cursor(struct xwl_screen *xwl_screen); - - struct xwl_screen *xwl_screen_get(ScreenPtr screen); -+Bool xwl_screen_has_resolution_change_emulation(struct xwl_screen *xwl_screen); - - void xwl_tablet_tool_set_cursor(struct xwl_tablet_tool *tool); - void xwl_seat_set_cursor(struct xwl_seat *xwl_seat); --- -2.28.0 - diff --git a/0005-xwayland-Use-RandR-1.2-interface-rev-2.patch b/0005-xwayland-Use-RandR-1.2-interface-rev-2.patch deleted file mode 100644 index 7493da6..0000000 --- a/0005-xwayland-Use-RandR-1.2-interface-rev-2.patch +++ /dev/null @@ -1,139 +0,0 @@ -From 09dcf01f5ea8d1f828a58e54edd608e6918d0b59 Mon Sep 17 00:00:00 2001 -From: Robert Mader -Date: Mon, 22 Jan 2018 17:57:38 +0100 -Subject: [PATCH xserver 05/25] xwayland: Use RandR 1.2 interface (rev 2) -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -This adds the RandR 1.2 interface to xwayland and allows modes -advertised by the compositor to be set in an undistructive manner. - -With this patch, applications that try to set the resolution will usually -succeed and work while other apps using the same xwayland -instance are not affected at all. - -The RandR 1.2 interface will be needed to implement fake-mode-setting and -already makes applications work much cleaner and predictive when a mode -was set. - -[hdegoede@redhat.com: Make crtc_set only succeed if the mode matches - the desktop resolution] - -Reviewed-by: Olivier Fourdan -Acked-by: Michel Dänzer -Signed-off-by: Hans de Goede -(cherry picked from commit e89872f51aa834fa9d94a4ca4822f03b0341ab4f) ---- - hw/xwayland/xwayland-output.c | 81 +++++++++++++++++++++++++++++++++++ - 1 file changed, 81 insertions(+) - -diff --git a/hw/xwayland/xwayland-output.c b/hw/xwayland/xwayland-output.c -index 4036ba681..633ebb89e 100644 ---- a/hw/xwayland/xwayland-output.c -+++ b/hw/xwayland/xwayland-output.c -@@ -524,12 +524,80 @@ xwl_randr_get_info(ScreenPtr pScreen, Rotation * rotations) - return TRUE; - } - -+#ifdef RANDR_10_INTERFACE - static Bool - xwl_randr_set_config(ScreenPtr pScreen, - Rotation rotation, int rate, RRScreenSizePtr pSize) - { - return FALSE; - } -+#endif -+ -+#if RANDR_12_INTERFACE -+static Bool -+xwl_randr_screen_set_size(ScreenPtr pScreen, -+ CARD16 width, -+ CARD16 height, -+ CARD32 mmWidth, CARD32 mmHeight) -+{ -+ return TRUE; -+} -+ -+static Bool -+xwl_randr_crtc_set(ScreenPtr pScreen, -+ RRCrtcPtr crtc, -+ RRModePtr mode, -+ int x, -+ int y, -+ Rotation rotation, -+ int numOutputs, RROutputPtr * outputs) -+{ -+ struct xwl_output *xwl_output = crtc->devPrivate; -+ -+ if (!mode || (mode->mode.width == xwl_output->width && -+ mode->mode.height == xwl_output->height)) { -+ RRCrtcChanged(crtc, TRUE); -+ return TRUE; -+ } -+ -+ return FALSE; -+} -+ -+static Bool -+xwl_randr_crtc_set_gamma(ScreenPtr pScreen, RRCrtcPtr crtc) -+{ -+ return TRUE; -+} -+ -+static Bool -+xwl_randr_crtc_get_gamma(ScreenPtr pScreen, RRCrtcPtr crtc) -+{ -+ return TRUE; -+} -+ -+static Bool -+xwl_randr_output_set_property(ScreenPtr pScreen, -+ RROutputPtr output, -+ Atom property, -+ RRPropertyValuePtr value) -+{ -+ return TRUE; -+} -+ -+static Bool -+xwl_output_validate_mode(ScreenPtr pScreen, -+ RROutputPtr output, -+ RRModePtr mode) -+{ -+ return TRUE; -+} -+ -+static void -+xwl_randr_mode_destroy(ScreenPtr pScreen, RRModePtr mode) -+{ -+ return; -+} -+#endif - - Bool - xwl_screen_init_output(struct xwl_screen *xwl_screen) -@@ -543,7 +611,20 @@ xwl_screen_init_output(struct xwl_screen *xwl_screen) - - rp = rrGetScrPriv(xwl_screen->screen); - rp->rrGetInfo = xwl_randr_get_info; -+ -+#if RANDR_10_INTERFACE - rp->rrSetConfig = xwl_randr_set_config; -+#endif -+ -+#if RANDR_12_INTERFACE -+ rp->rrScreenSetSize = xwl_randr_screen_set_size; -+ rp->rrCrtcSet = xwl_randr_crtc_set; -+ rp->rrCrtcSetGamma = xwl_randr_crtc_set_gamma; -+ rp->rrCrtcGetGamma = xwl_randr_crtc_get_gamma; -+ rp->rrOutputSetProperty = xwl_randr_output_set_property; -+ rp->rrOutputValidateMode = xwl_output_validate_mode; -+ rp->rrModeDestroy = xwl_randr_mode_destroy; -+#endif - - return TRUE; - } --- -2.28.0 - diff --git a/0006-xwayland-Add-per-client-private-data.patch b/0006-xwayland-Add-per-client-private-data.patch deleted file mode 100644 index 5d64bd8..0000000 --- a/0006-xwayland-Add-per-client-private-data.patch +++ /dev/null @@ -1,80 +0,0 @@ -From ca0616ca4ca1badff2674fa5db8f290935b81e7f Mon Sep 17 00:00:00 2001 -From: Hans de Goede -Date: Thu, 29 Aug 2019 22:45:12 +0200 -Subject: [PATCH xserver 06/25] xwayland: Add per client private data -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Add per client private data, which for now is empty. - -This is a preparation patch for adding randr/vidmode resolution -change emulation. - -Reviewed-by: Olivier Fourdan -Acked-by: Michel Dänzer -Signed-off-by: Hans de Goede -(cherry picked from commit 905cb8b9e27add5f49a45fe167a0005bf05218bc) ---- - hw/xwayland/xwayland.c | 14 ++++++++++++++ - hw/xwayland/xwayland.h | 5 +++++ - 2 files changed, 19 insertions(+) - -diff --git a/hw/xwayland/xwayland.c b/hw/xwayland/xwayland.c -index e84515f94..f422cfc29 100644 ---- a/hw/xwayland/xwayland.c -+++ b/hw/xwayland/xwayland.c -@@ -137,11 +137,18 @@ ddxProcessArgument(int argc, char *argv[], int i) - return 0; - } - -+static DevPrivateKeyRec xwl_client_private_key; - static DevPrivateKeyRec xwl_window_private_key; - static DevPrivateKeyRec xwl_screen_private_key; - static DevPrivateKeyRec xwl_pixmap_private_key; - static DevPrivateKeyRec xwl_damage_private_key; - -+struct xwl_client * -+xwl_client_get(ClientPtr client) -+{ -+ return dixLookupPrivate(&client->devPrivates, &xwl_client_private_key); -+} -+ - static struct xwl_window * - xwl_window_get(WindowPtr window) - { -@@ -1145,6 +1152,13 @@ xwl_screen_init(ScreenPtr pScreen, int argc, char **argv) - return FALSE; - if (!dixRegisterPrivateKey(&xwl_damage_private_key, PRIVATE_WINDOW, 0)) - return FALSE; -+ /* There are no easy to use new / delete client hooks, we could use a -+ * ClientStateCallback, but it is easier to let the dix code manage the -+ * memory for us. This will zero fill the initial xwl_client data. -+ */ -+ if (!dixRegisterPrivateKey(&xwl_client_private_key, PRIVATE_CLIENT, -+ sizeof(struct xwl_client))) -+ return FALSE; - - dixSetPrivate(&pScreen->devPrivates, &xwl_screen_private_key, xwl_screen); - xwl_screen->screen = pScreen; -diff --git a/hw/xwayland/xwayland.h b/hw/xwayland/xwayland.h -index 200e18a8d..19626d394 100644 ---- a/hw/xwayland/xwayland.h -+++ b/hw/xwayland/xwayland.h -@@ -379,8 +379,13 @@ struct xwl_output { - Bool xdg_output_done; - }; - -+struct xwl_client { -+}; -+ - void xwl_window_create_frame_callback(struct xwl_window *xwl_window); - -+struct xwl_client *xwl_client_get(ClientPtr client); -+ - void xwl_sync_events (struct xwl_screen *xwl_screen); - void xwl_surface_damage(struct xwl_screen *xwl_screen, - struct wl_surface *surface, --- -2.28.0 - diff --git a/0007-xwayland-Add-support-for-storing-per-client-per-outp.patch b/0007-xwayland-Add-support-for-storing-per-client-per-outp.patch deleted file mode 100644 index 6673754..0000000 --- a/0007-xwayland-Add-support-for-storing-per-client-per-outp.patch +++ /dev/null @@ -1,149 +0,0 @@ -From 4bc5480d2e63cceecdc18b4bfda4fb4624f8fb43 Mon Sep 17 00:00:00 2001 -From: Hans de Goede -Date: Thu, 29 Aug 2019 23:04:36 +0200 -Subject: [PATCH xserver 07/25] xwayland: Add support for storing per client - per output emulated resolution -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Add support for storing per output randr/vidmode emulated resolution -into the per client data. - -Since we do not have a free/delete callback for the client this uses -a simple static array. The entries are tied to a specific output by the -server_output_id, with a server_output_id of 0 indicating a free slot -(0 is the "None" Wayland object id). - -Note that even if we were to store this in a linked list, we would still -need the server_output_id as this is *per client* *per output*. - -This is a preparation patch for adding randr/vidmode resolution -change emulation. - -Reviewed-by: Olivier Fourdan -Acked-by: Michel Dänzer -Signed-off-by: Hans de Goede -(cherry picked from commit aca0a588eb40a5e6669094a2ab7f71ca0ba06b16) ---- - hw/xwayland/xwayland-output.c | 67 +++++++++++++++++++++++++++++++++++ - hw/xwayland/xwayland.h | 17 +++++++++ - 2 files changed, 84 insertions(+) - -diff --git a/hw/xwayland/xwayland-output.c b/hw/xwayland/xwayland-output.c -index 633ebb89e..64794dee7 100644 ---- a/hw/xwayland/xwayland-output.c -+++ b/hw/xwayland/xwayland-output.c -@@ -208,6 +208,73 @@ update_screen_size(struct xwl_output *xwl_output, int width, int height) - update_desktop_dimensions(); - } - -+struct xwl_emulated_mode * -+xwl_output_get_emulated_mode_for_client(struct xwl_output *xwl_output, -+ ClientPtr client) -+{ -+ struct xwl_client *xwl_client = xwl_client_get(client); -+ int i; -+ -+ if (!xwl_output) -+ return NULL; -+ -+ for (i = 0; i < XWL_CLIENT_MAX_EMULATED_MODES; i++) { -+ if (xwl_client->emulated_modes[i].server_output_id == -+ xwl_output->server_output_id) -+ return &xwl_client->emulated_modes[i]; -+ } -+ -+ return NULL; -+} -+ -+static void -+xwl_output_add_emulated_mode_for_client(struct xwl_output *xwl_output, -+ ClientPtr client, -+ RRModePtr mode, -+ Bool from_vidmode) -+{ -+ struct xwl_client *xwl_client = xwl_client_get(client); -+ struct xwl_emulated_mode *emulated_mode; -+ int i; -+ -+ emulated_mode = xwl_output_get_emulated_mode_for_client(xwl_output, client); -+ if (!emulated_mode) { -+ /* Find a free spot in the emulated modes array */ -+ for (i = 0; i < XWL_CLIENT_MAX_EMULATED_MODES; i++) { -+ if (xwl_client->emulated_modes[i].server_output_id == 0) { -+ emulated_mode = &xwl_client->emulated_modes[i]; -+ break; -+ } -+ } -+ } -+ if (!emulated_mode) { -+ static Bool warned; -+ -+ if (!warned) { -+ ErrorF("Ran out of space for emulated-modes, not adding mode"); -+ warned = TRUE; -+ } -+ -+ return; -+ } -+ -+ emulated_mode->server_output_id = xwl_output->server_output_id; -+ emulated_mode->width = mode->mode.width; -+ emulated_mode->height = mode->mode.height; -+ emulated_mode->from_vidmode = from_vidmode; -+} -+ -+static void -+xwl_output_remove_emulated_mode_for_client(struct xwl_output *xwl_output, -+ ClientPtr client) -+{ -+ struct xwl_emulated_mode *emulated_mode; -+ -+ emulated_mode = xwl_output_get_emulated_mode_for_client(xwl_output, client); -+ if (emulated_mode) -+ memset(emulated_mode, 0, sizeof(*emulated_mode)); -+} -+ - /* From hw/xfree86/common/xf86DefModeSet.c with some obscure modes dropped */ - const int32_t xwl_output_fake_modes[][2] = { - /* 4:3 (1.33) */ -diff --git a/hw/xwayland/xwayland.h b/hw/xwayland/xwayland.h -index 19626d394..c886d77e9 100644 ---- a/hw/xwayland/xwayland.h -+++ b/hw/xwayland/xwayland.h -@@ -379,7 +379,21 @@ struct xwl_output { - Bool xdg_output_done; - }; - -+/* Per client per output emulated randr/vidmode resolution info. */ -+struct xwl_emulated_mode { -+ uint32_t server_output_id; -+ int32_t width; -+ int32_t height; -+ Bool from_vidmode; -+}; -+ -+/* Apps which use randr/vidmode to change the mode when going fullscreen, -+ * usually change the mode of only a single monitor, so this should be plenty. -+ */ -+#define XWL_CLIENT_MAX_EMULATED_MODES 16 -+ - struct xwl_client { -+ struct xwl_emulated_mode emulated_modes[XWL_CLIENT_MAX_EMULATED_MODES]; - }; - - void xwl_window_create_frame_callback(struct xwl_window *xwl_window); -@@ -427,6 +441,9 @@ void xwl_output_destroy(struct xwl_output *xwl_output); - - void xwl_output_remove(struct xwl_output *xwl_output); - -+struct xwl_emulated_mode *xwl_output_get_emulated_mode_for_client( -+ struct xwl_output *xwl_output, ClientPtr client); -+ - RRModePtr xwayland_cvt(int HDisplay, int VDisplay, - float VRefresh, Bool Reduced, Bool Interlaced); - --- -2.28.0 - diff --git a/0008-xwayland-Add-support-for-randr-resolution-change-emu.patch b/0008-xwayland-Add-support-for-randr-resolution-change-emu.patch deleted file mode 100644 index 75a2877..0000000 --- a/0008-xwayland-Add-support-for-randr-resolution-change-emu.patch +++ /dev/null @@ -1,462 +0,0 @@ -From 2f2a6b8556bd104740d76126640abcfe4705047c Mon Sep 17 00:00:00 2001 -From: Hans de Goede -Date: Tue, 2 Jul 2019 11:55:26 +0200 -Subject: [PATCH xserver 08/25] xwayland: Add support for randr-resolution - change emulation using viewport -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Add support for per client randr-resolution change emulation using viewport, -for apps which want to change the resolution when going fullscreen. - -Partly based on earlier work on this by Robert Mader - -Note SDL2 and SFML do not restore randr resolution when going from -fullscreen -> windowed, I believe this is caused by us still reporting the -desktop resolution when they query the resolution. This is not a problem -because when windowed the toplevel window size includes the window-decorations -so it never matches the emulated resolution. - -One exception would be the window being resizable in Windowed mode and the -user resizing the window so that including decorations it matches the -emulated resolution *and* the window being at pos 0x0. But this is an -extreme corner case. Still I will submit patches upstream to SDL2 -and SFML to always restore the desktop resolution under Xwayland, -disabling resolution emulation all together when going windowed. - -Reviewed-by: Olivier Fourdan -Acked-by: Michel Dänzer -Signed-off-by: Hans de Goede -(cherry picked from commit d99b9ff0f237d15e7eb507484493c73b393d5dba) ---- - hw/xwayland/xwayland-input.c | 5 + - hw/xwayland/xwayland-output.c | 63 ++++++++++- - hw/xwayland/xwayland.c | 199 ++++++++++++++++++++++++++++++++++ - hw/xwayland/xwayland.h | 15 +++ - 4 files changed, 276 insertions(+), 6 deletions(-) - -diff --git a/hw/xwayland/xwayland-input.c b/hw/xwayland/xwayland-input.c -index a05d178ff..7d75a8f54 100644 ---- a/hw/xwayland/xwayland-input.c -+++ b/hw/xwayland/xwayland-input.c -@@ -488,6 +488,11 @@ dispatch_pointer_motion_event(struct xwl_seat *xwl_seat) - int dx = xwl_seat->focus_window->window->drawable.x; - int dy = xwl_seat->focus_window->window->drawable.y; - -+ if (xwl_window_has_viewport_enabled(xwl_seat->focus_window)) { -+ sx *= xwl_seat->focus_window->scale_x; -+ sy *= xwl_seat->focus_window->scale_y; -+ } -+ - x = dx + sx; - y = dy + sy; - } else { -diff --git a/hw/xwayland/xwayland-output.c b/hw/xwayland/xwayland-output.c -index 64794dee7..e09d00108 100644 ---- a/hw/xwayland/xwayland-output.c -+++ b/hw/xwayland/xwayland-output.c -@@ -371,6 +371,42 @@ err: - FatalError("Failed to allocate memory for list of RR modes"); - } - -+RRModePtr -+xwl_output_find_mode(struct xwl_output *xwl_output, -+ int32_t width, int32_t height) -+{ -+ RROutputPtr output = xwl_output->randr_output; -+ int i; -+ -+ /* width & height -1 means we want the actual output mode, which is idx 0 */ -+ if (width == -1 && height == -1 && output->modes) -+ return output->modes[0]; -+ -+ for (i = 0; i < output->numModes; i++) { -+ if (output->modes[i]->mode.width == width && output->modes[i]->mode.height == height) -+ return output->modes[i]; -+ } -+ -+ ErrorF("XWAYLAND: mode %dx%d is not available\n", width, height); -+ return NULL; -+} -+ -+void -+xwl_output_set_emulated_mode(struct xwl_output *xwl_output, ClientPtr client, -+ RRModePtr mode, Bool from_vidmode) -+{ -+ DebugF("XWAYLAND: xwl_output_set_emulated_mode from %s: %dx%d\n", -+ from_vidmode ? "vidmode" : "randr", -+ mode->mode.width, mode->mode.height); -+ -+ if (mode->mode.width == xwl_output->width && mode->mode.height == xwl_output->height) -+ xwl_output_remove_emulated_mode_for_client(xwl_output, client); -+ else -+ xwl_output_add_emulated_mode_for_client(xwl_output, client, mode, from_vidmode); -+ -+ xwl_screen_check_resolution_change_emulation(xwl_output->xwl_screen); -+} -+ - static void - apply_output_change(struct xwl_output *xwl_output) - { -@@ -613,21 +649,36 @@ xwl_randr_screen_set_size(ScreenPtr pScreen, - static Bool - xwl_randr_crtc_set(ScreenPtr pScreen, - RRCrtcPtr crtc, -- RRModePtr mode, -+ RRModePtr new_mode, - int x, - int y, - Rotation rotation, - int numOutputs, RROutputPtr * outputs) - { - struct xwl_output *xwl_output = crtc->devPrivate; -+ RRModePtr mode; - -- if (!mode || (mode->mode.width == xwl_output->width && -- mode->mode.height == xwl_output->height)) { -- RRCrtcChanged(crtc, TRUE); -- return TRUE; -+ if (new_mode) { -+ mode = xwl_output_find_mode(xwl_output, -+ new_mode->mode.width, -+ new_mode->mode.height); -+ } else { -+ mode = xwl_output_find_mode(xwl_output, -1, -1); - } -+ if (!mode) -+ return FALSE; - -- return FALSE; -+ xwl_output_set_emulated_mode(xwl_output, GetCurrentClient(), mode, FALSE); -+ -+ /* A real randr implementation would call: -+ * RRCrtcNotify(xwl_output->randr_crtc, mode, xwl_output->x, xwl_output->y, -+ * xwl_output->rotation, NULL, 1, &xwl_output->randr_output); -+ * here to update the mode reported to clients querying the randr settings -+ * but that influences *all* clients and we do randr mode change emulation -+ * on a per client basis. So we just return success here. -+ */ -+ -+ return TRUE; - } - - static Bool -diff --git a/hw/xwayland/xwayland.c b/hw/xwayland/xwayland.c -index f422cfc29..87870a5f1 100644 ---- a/hw/xwayland/xwayland.c -+++ b/hw/xwayland/xwayland.c -@@ -178,6 +178,23 @@ xwl_screen_has_resolution_change_emulation(struct xwl_screen *xwl_screen) - return xwl_screen->rootless && xwl_screen_has_viewport_support(xwl_screen); - } - -+/* Return the output @ 0x0, falling back to the first output in the list */ -+struct xwl_output * -+xwl_screen_get_first_output(struct xwl_screen *xwl_screen) -+{ -+ struct xwl_output *xwl_output; -+ -+ xorg_list_for_each_entry(xwl_output, &xwl_screen->output_list, link) { -+ if (xwl_output->x == 0 && xwl_output->y == 0) -+ return xwl_output; -+ } -+ -+ if (xorg_list_is_empty(&xwl_screen->output_list)) -+ return NULL; -+ -+ return xorg_list_first_entry(&xwl_screen->output_list, struct xwl_output, link); -+} -+ - static void - xwl_window_set_allow_commits(struct xwl_window *xwl_window, Bool allow, - const char *debug_msg) -@@ -501,6 +518,150 @@ xwl_pixmap_get(PixmapPtr pixmap) - return dixLookupPrivate(&pixmap->devPrivates, &xwl_pixmap_private_key); - } - -+Bool -+xwl_window_has_viewport_enabled(struct xwl_window *xwl_window) -+{ -+ return (xwl_window->viewport != NULL); -+} -+ -+static void -+xwl_window_disable_viewport(struct xwl_window *xwl_window) -+{ -+ assert (xwl_window->viewport); -+ -+ DebugF("XWAYLAND: disabling viewport\n"); -+ wp_viewport_destroy(xwl_window->viewport); -+ xwl_window->viewport = NULL; -+} -+ -+static void -+xwl_window_enable_viewport(struct xwl_window *xwl_window, -+ struct xwl_output *xwl_output, -+ struct xwl_emulated_mode *emulated_mode) -+{ -+ /* If necessary disable old viewport to apply new settings */ -+ if (xwl_window_has_viewport_enabled(xwl_window)) -+ xwl_window_disable_viewport(xwl_window); -+ -+ DebugF("XWAYLAND: enabling viewport %dx%d -> %dx%d\n", -+ emulated_mode->width, emulated_mode->height, -+ xwl_output->width, xwl_output->height); -+ -+ xwl_window->viewport = -+ wp_viewporter_get_viewport(xwl_window->xwl_screen->viewporter, -+ xwl_window->surface); -+ -+ wp_viewport_set_source(xwl_window->viewport, -+ wl_fixed_from_int(0), -+ wl_fixed_from_int(0), -+ wl_fixed_from_int(emulated_mode->width), -+ wl_fixed_from_int(emulated_mode->height)); -+ wp_viewport_set_destination(xwl_window->viewport, -+ xwl_output->width, -+ xwl_output->height); -+ -+ xwl_window->scale_x = (float)emulated_mode->width / xwl_output->width; -+ xwl_window->scale_y = (float)emulated_mode->height / xwl_output->height; -+} -+ -+static Bool -+xwl_screen_client_is_window_manager(struct xwl_screen *xwl_screen, -+ ClientPtr client) -+{ -+ WindowPtr root = xwl_screen->screen->root; -+ OtherClients *others; -+ -+ for (others = wOtherClients(root); others; others = others->next) { -+ if (SameClient(others, client)) { -+ if (others->mask & (SubstructureRedirectMask | ResizeRedirectMask)) -+ return TRUE; -+ } -+ } -+ -+ return FALSE; -+} -+ -+static ClientPtr -+xwl_window_get_owner(struct xwl_window *xwl_window) -+{ -+ WindowPtr window = xwl_window->window; -+ ClientPtr client = wClient(window); -+ -+ /* If the toplevel window is owned by the window-manager, then the -+ * actual client toplevel window has been reparented to a window-manager -+ * decoration window. In that case return the client of the -+ * first *and only* child of the toplevel (decoration) window. -+ */ -+ if (xwl_screen_client_is_window_manager(xwl_window->xwl_screen, client)) { -+ if (window->firstChild && window->firstChild == window->lastChild) -+ return wClient(window->firstChild); -+ else -+ return NULL; /* Should never happen, skip resolution emulation */ -+ } -+ -+ return client; -+} -+ -+static Bool -+xwl_window_should_enable_viewport(struct xwl_window *xwl_window, -+ struct xwl_output **xwl_output_ret, -+ struct xwl_emulated_mode **emulated_mode_ret) -+{ -+ struct xwl_screen *xwl_screen = xwl_window->xwl_screen; -+ struct xwl_emulated_mode *emulated_mode; -+ struct xwl_output *xwl_output; -+ ClientPtr owner; -+ -+ if (!xwl_screen_has_resolution_change_emulation(xwl_screen)) -+ return FALSE; -+ -+ owner = xwl_window_get_owner(xwl_window); -+ if (!owner) -+ return FALSE; -+ -+ /* 1. Test if the window matches the emulated mode on one of the outputs -+ * This path gets hit by most games / libs (e.g. SDL, SFML, OGRE) -+ */ -+ xorg_list_for_each_entry(xwl_output, &xwl_screen->output_list, link) { -+ emulated_mode = xwl_output_get_emulated_mode_for_client(xwl_output, owner); -+ if (!emulated_mode) -+ continue; -+ -+ if (xwl_window->x == xwl_output->x && -+ xwl_window->y == xwl_output->y && -+ xwl_window->width == emulated_mode->width && -+ xwl_window->height == emulated_mode->height) { -+ -+ *emulated_mode_ret = emulated_mode; -+ *xwl_output_ret = xwl_output; -+ return TRUE; -+ } -+ } -+ -+ return FALSE; -+} -+ -+static void -+xwl_window_check_resolution_change_emulation(struct xwl_window *xwl_window) -+{ -+ struct xwl_emulated_mode *emulated_mode; -+ struct xwl_output *xwl_output; -+ -+ if (xwl_window_should_enable_viewport(xwl_window, &xwl_output, &emulated_mode)) -+ xwl_window_enable_viewport(xwl_window, xwl_output, emulated_mode); -+ else if (xwl_window_has_viewport_enabled(xwl_window)) -+ xwl_window_disable_viewport(xwl_window); -+} -+ -+void -+xwl_screen_check_resolution_change_emulation(struct xwl_screen *xwl_screen) -+{ -+ struct xwl_window *xwl_window; -+ -+ xorg_list_for_each_entry(xwl_window, &xwl_screen->window_list, link_window) -+ xwl_window_check_resolution_change_emulation(xwl_window); -+} -+ - static void - xwl_window_init_allow_commits(struct xwl_window *xwl_window) - { -@@ -571,6 +732,8 @@ ensure_surface_for_window(WindowPtr window) - - xwl_window->xwl_screen = xwl_screen; - xwl_window->window = window; -+ xwl_window->width = window->drawable.width; -+ xwl_window->height = window->drawable.height; - xwl_window->surface = wl_compositor_create_surface(xwl_screen->compositor); - if (xwl_window->surface == NULL) { - ErrorF("wl_display_create_surface failed\n"); -@@ -612,6 +775,7 @@ ensure_surface_for_window(WindowPtr window) - - dixSetPrivate(&window->devPrivates, &xwl_window_private_key, xwl_window); - xorg_list_init(&xwl_window->link_damage); -+ xorg_list_add(&xwl_window->link_window, &xwl_screen->window_list); - - #ifdef GLAMOR_HAS_GBM - xorg_list_init(&xwl_window->frame_callback_list); -@@ -705,8 +869,12 @@ xwl_unrealize_window(WindowPtr window) - if (!xwl_window) - return ret; - -+ if (xwl_window_has_viewport_enabled(xwl_window)) -+ xwl_window_disable_viewport(xwl_window); -+ - wl_surface_destroy(xwl_window->surface); - xorg_list_del(&xwl_window->link_damage); -+ xorg_list_del(&xwl_window->link_window); - unregister_damage(window); - - if (xwl_window->frame_callback) -@@ -756,6 +924,33 @@ xwl_set_window_pixmap(WindowPtr window, - ensure_surface_for_window(window); - } - -+static void -+xwl_resize_window(WindowPtr window, -+ int x, int y, -+ unsigned int width, unsigned int height, -+ WindowPtr sib) -+{ -+ ScreenPtr screen = window->drawable.pScreen; -+ struct xwl_screen *xwl_screen; -+ struct xwl_window *xwl_window; -+ -+ xwl_screen = xwl_screen_get(screen); -+ xwl_window = xwl_window_get(window); -+ -+ screen->ResizeWindow = xwl_screen->ResizeWindow; -+ (*screen->ResizeWindow) (window, x, y, width, height, sib); -+ xwl_screen->ResizeWindow = screen->ResizeWindow; -+ screen->ResizeWindow = xwl_resize_window; -+ -+ if (xwl_window) { -+ xwl_window->x = x; -+ xwl_window->y = y; -+ xwl_window->width = width; -+ xwl_window->height = height; -+ xwl_window_check_resolution_change_emulation(xwl_window); -+ } -+} -+ - static void - frame_callback(void *data, - struct wl_callback *callback, -@@ -1233,6 +1428,7 @@ xwl_screen_init(ScreenPtr pScreen, int argc, char **argv) - xorg_list_init(&xwl_screen->output_list); - xorg_list_init(&xwl_screen->seat_list); - xorg_list_init(&xwl_screen->damage_window_list); -+ xorg_list_init(&xwl_screen->window_list); - xwl_screen->depth = 24; - - if (!monitorResolution) -@@ -1332,6 +1528,9 @@ xwl_screen_init(ScreenPtr pScreen, int argc, char **argv) - xwl_screen->CloseScreen = pScreen->CloseScreen; - pScreen->CloseScreen = xwl_close_screen; - -+ xwl_screen->ResizeWindow = pScreen->ResizeWindow; -+ pScreen->ResizeWindow = xwl_resize_window; -+ - if (xwl_screen->rootless) { - xwl_screen->SetWindowPixmap = pScreen->SetWindowPixmap; - pScreen->SetWindowPixmap = xwl_set_window_pixmap; -diff --git a/hw/xwayland/xwayland.h b/hw/xwayland/xwayland.h -index c886d77e9..36c4c4c8b 100644 ---- a/hw/xwayland/xwayland.h -+++ b/hw/xwayland/xwayland.h -@@ -135,10 +135,12 @@ struct xwl_screen { - DestroyWindowProcPtr DestroyWindow; - XYToWindowProcPtr XYToWindow; - SetWindowPixmapProcPtr SetWindowPixmap; -+ ResizeWindowProcPtr ResizeWindow; - - struct xorg_list output_list; - struct xorg_list seat_list; - struct xorg_list damage_window_list; -+ struct xorg_list window_list; - - int wayland_fd; - struct wl_display *display; -@@ -179,9 +181,13 @@ struct xwl_screen { - struct xwl_window { - struct xwl_screen *xwl_screen; - struct wl_surface *surface; -+ struct wp_viewport *viewport; -+ int32_t x, y, width, height; -+ float scale_x, scale_y; - struct wl_shell_surface *shell_surface; - WindowPtr window; - struct xorg_list link_damage; -+ struct xorg_list link_window; - struct wl_callback *frame_callback; - Bool allow_commits; - #ifdef GLAMOR_HAS_GBM -@@ -411,6 +417,9 @@ Bool xwl_screen_init_cursor(struct xwl_screen *xwl_screen); - - struct xwl_screen *xwl_screen_get(ScreenPtr screen); - Bool xwl_screen_has_resolution_change_emulation(struct xwl_screen *xwl_screen); -+struct xwl_output *xwl_screen_get_first_output(struct xwl_screen *xwl_screen); -+void xwl_screen_check_resolution_change_emulation(struct xwl_screen *xwl_screen); -+Bool xwl_window_has_viewport_enabled(struct xwl_window *xwl_window); - - void xwl_tablet_tool_set_cursor(struct xwl_tablet_tool *tool); - void xwl_seat_set_cursor(struct xwl_seat *xwl_seat); -@@ -444,6 +453,12 @@ void xwl_output_remove(struct xwl_output *xwl_output); - struct xwl_emulated_mode *xwl_output_get_emulated_mode_for_client( - struct xwl_output *xwl_output, ClientPtr client); - -+RRModePtr xwl_output_find_mode(struct xwl_output *xwl_output, -+ int32_t width, int32_t height); -+void xwl_output_set_emulated_mode(struct xwl_output *xwl_output, -+ ClientPtr client, RRModePtr mode, -+ Bool from_vidmode); -+ - RRModePtr xwayland_cvt(int HDisplay, int VDisplay, - float VRefresh, Bool Reduced, Bool Interlaced); - --- -2.28.0 - diff --git a/0009-xwayland-Add-xwlRRModeToDisplayMode-helper-function.patch b/0009-xwayland-Add-xwlRRModeToDisplayMode-helper-function.patch deleted file mode 100644 index 1d29960..0000000 --- a/0009-xwayland-Add-xwlRRModeToDisplayMode-helper-function.patch +++ /dev/null @@ -1,101 +0,0 @@ -From aedd71a61ac2d78c347180e7d87e5918b795609e Mon Sep 17 00:00:00 2001 -From: Hans de Goede -Date: Mon, 8 Jul 2019 14:00:27 +0200 -Subject: [PATCH xserver 09/25] xwayland: Add xwlRRModeToDisplayMode() helper - function -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -This is a preparation patch for adding emulated mode/resolution change -support to Xwayland's XF86 vidmode extension emulation, using the -Wayland viewport extension. - -Reviewed-by: Olivier Fourdan -Acked-by: Michel Dänzer -Signed-off-by: Hans de Goede -(cherry picked from commit 43c80078126f6f33c6ab7d3cf4668733bde03366) ---- - hw/xwayland/xwayland-vidmode.c | 51 +++++++++++++++++++--------------- - 1 file changed, 28 insertions(+), 23 deletions(-) - -diff --git a/hw/xwayland/xwayland-vidmode.c b/hw/xwayland/xwayland-vidmode.c -index d25d1aca1..428af716d 100644 ---- a/hw/xwayland/xwayland-vidmode.c -+++ b/hw/xwayland/xwayland-vidmode.c -@@ -78,13 +78,37 @@ mode_refresh(const xRRModeInfo *mode_info) - return rate; - } - -+static void -+xwlRRModeToDisplayMode(RRModePtr rrmode, DisplayModePtr mode) -+{ -+ const xRRModeInfo *mode_info = &rrmode->mode; -+ -+ mode->next = mode; -+ mode->prev = mode; -+ mode->name = ""; -+ mode->VScan = 1; -+ mode->Private = NULL; -+ mode->HDisplay = mode_info->width; -+ mode->HSyncStart = mode_info->hSyncStart; -+ mode->HSyncEnd = mode_info->hSyncEnd; -+ mode->HTotal = mode_info->hTotal; -+ mode->HSkew = mode_info->hSkew; -+ mode->VDisplay = mode_info->height; -+ mode->VSyncStart = mode_info->vSyncStart; -+ mode->VSyncEnd = mode_info->vSyncEnd; -+ mode->VTotal = mode_info->vTotal; -+ mode->Flags = mode_info->modeFlags; -+ mode->Clock = mode_info->dotClock / 1000.0; -+ mode->VRefresh = mode_refresh(mode_info); /* Or RRVerticalRefresh() */ -+ mode->HSync = mode_hsync(mode_info); -+} -+ - static Bool - xwlVidModeGetCurrentModeline(ScreenPtr pScreen, DisplayModePtr *mode, int *dotClock) - { - DisplayModePtr pMod; - RROutputPtr output; - RRCrtcPtr crtc; -- xRRModeInfo rrmode; - - pMod = dixLookupPrivate(&pScreen->devPrivates, xwlVidModePrivateKey); - if (pMod == NULL) -@@ -98,30 +122,11 @@ xwlVidModeGetCurrentModeline(ScreenPtr pScreen, DisplayModePtr *mode, int *dotCl - if (crtc == NULL) - return FALSE; - -- rrmode = crtc->mode->mode; -- -- pMod->next = pMod; -- pMod->prev = pMod; -- pMod->name = ""; -- pMod->VScan = 1; -- pMod->Private = NULL; -- pMod->HDisplay = rrmode.width; -- pMod->HSyncStart = rrmode.hSyncStart; -- pMod->HSyncEnd = rrmode.hSyncEnd; -- pMod->HTotal = rrmode.hTotal; -- pMod->HSkew = rrmode.hSkew; -- pMod->VDisplay = rrmode.height; -- pMod->VSyncStart = rrmode.vSyncStart; -- pMod->VSyncEnd = rrmode.vSyncEnd; -- pMod->VTotal = rrmode.vTotal; -- pMod->Flags = rrmode.modeFlags; -- pMod->Clock = rrmode.dotClock / 1000.0; -- pMod->VRefresh = mode_refresh(&rrmode); /* Or RRVerticalRefresh() */ -- pMod->HSync = mode_hsync(&rrmode); -- *mode = pMod; -+ xwlRRModeToDisplayMode(crtc->mode, pMod); - -+ *mode = pMod; - if (dotClock != NULL) -- *dotClock = rrmode.dotClock / 1000.0; -+ *dotClock = pMod->Clock; - - return TRUE; - } --- -2.28.0 - diff --git a/0010-xwayland-Add-xwlVidModeGetCurrentRRMode-helper-to-th.patch b/0010-xwayland-Add-xwlVidModeGetCurrentRRMode-helper-to-th.patch deleted file mode 100644 index ea1f6c4..0000000 --- a/0010-xwayland-Add-xwlVidModeGetCurrentRRMode-helper-to-th.patch +++ /dev/null @@ -1,193 +0,0 @@ -From 719c1d2ef99784043883787d04afc0437f3a9b8f Mon Sep 17 00:00:00 2001 -From: Hans de Goede -Date: Mon, 8 Jul 2019 18:35:27 +0200 -Subject: [PATCH xserver 10/25] xwayland: Add xwlVidModeGetCurrentRRMode helper - to the vidmode code -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -crtc->mode reflects the mode set through the xrandr extension, once we -add support for also changing the mode through the vidmode extension this -will no longer correctly reflect the emulated resolution. - -Add a new xwlVidModeGetCurrentRRMode helper which determines the mode by -looking at the emulated_mode instead. - -Likewise add a xwlVidModeGetRRMode helper and use that in -xwlVidModeCheckModeForMonitor/xwlVidModeCheckModeForDriver to allow any -mode listed in the randr_output's mode list. - -This is a preparation patch for adding emulated mode/resolution change -support to Xwayland's XF86 vidmode extension emulation. - -Reviewed-by: Olivier Fourdan -Acked-by: Michel Dänzer -Signed-off-by: Hans de Goede -(cherry picked from commit bcad1b813a04b9f3ff225f57a4baad09bd6315b9) ---- - hw/xwayland/xwayland-vidmode.c | 90 +++++++++++++++++++++------------- - 1 file changed, 56 insertions(+), 34 deletions(-) - -diff --git a/hw/xwayland/xwayland-vidmode.c b/hw/xwayland/xwayland-vidmode.c -index 428af716d..7cf982fcc 100644 ---- a/hw/xwayland/xwayland-vidmode.c -+++ b/hw/xwayland/xwayland-vidmode.c -@@ -103,26 +103,56 @@ xwlRRModeToDisplayMode(RRModePtr rrmode, DisplayModePtr mode) - mode->HSync = mode_hsync(mode_info); - } - -+static RRModePtr -+xwlVidModeGetRRMode(ScreenPtr pScreen, int32_t width, int32_t height) -+{ -+ RROutputPtr output = RRFirstOutput(pScreen); -+ -+ if (output == NULL) -+ return NULL; -+ -+ return xwl_output_find_mode(output->devPrivate, width, height); -+} -+ -+static RRModePtr -+xwlVidModeGetCurrentRRMode(ScreenPtr pScreen) -+{ -+ struct xwl_emulated_mode *emulated_mode; -+ struct xwl_output *xwl_output; -+ RROutputPtr output; -+ -+ output = RRFirstOutput(pScreen); -+ if (output == NULL) -+ return NULL; -+ -+ xwl_output = output->devPrivate; -+ emulated_mode = -+ xwl_output_get_emulated_mode_for_client(xwl_output, GetCurrentClient()); -+ -+ if (emulated_mode) { -+ return xwl_output_find_mode(xwl_output, -+ emulated_mode->width, -+ emulated_mode->height); -+ } else { -+ return xwl_output_find_mode(xwl_output, -1, -1); -+ } -+} -+ - static Bool - xwlVidModeGetCurrentModeline(ScreenPtr pScreen, DisplayModePtr *mode, int *dotClock) - { - DisplayModePtr pMod; -- RROutputPtr output; -- RRCrtcPtr crtc; -+ RRModePtr rrmode; - - pMod = dixLookupPrivate(&pScreen->devPrivates, xwlVidModePrivateKey); - if (pMod == NULL) - return FALSE; - -- output = RRFirstOutput(pScreen); -- if (output == NULL) -- return FALSE; -- -- crtc = output->crtc; -- if (crtc == NULL) -+ rrmode = xwlVidModeGetCurrentRRMode(pScreen); -+ if (rrmode == NULL) - return FALSE; - -- xwlRRModeToDisplayMode(crtc->mode, pMod); -+ xwlRRModeToDisplayMode(rrmode, pMod); - - *mode = pMod; - if (dotClock != NULL) -@@ -135,9 +165,10 @@ static vidMonitorValue - xwlVidModeGetMonitorValue(ScreenPtr pScreen, int valtyp, int indx) - { - vidMonitorValue ret = { NULL, }; -- DisplayModePtr pMod; -+ RRModePtr rrmode; - -- if (!xwlVidModeGetCurrentModeline(pScreen, &pMod, NULL)) -+ rrmode = xwlVidModeGetCurrentRRMode(pScreen); -+ if (rrmode == NULL) - return ret; - - switch (valtyp) { -@@ -155,11 +186,11 @@ xwlVidModeGetMonitorValue(ScreenPtr pScreen, int valtyp, int indx) - break; - case VIDMODE_MON_HSYNC_LO: - case VIDMODE_MON_HSYNC_HI: -- ret.f = 100.0 * pMod->HSync; -+ ret.f = mode_hsync(&rrmode->mode) * 100.0; - break; - case VIDMODE_MON_VREFRESH_LO: - case VIDMODE_MON_VREFRESH_HI: -- ret.f = 100.0 * pMod->VRefresh; -+ ret.f = mode_refresh(&rrmode->mode) * 100.0; - break; - } - return ret; -@@ -168,13 +199,13 @@ xwlVidModeGetMonitorValue(ScreenPtr pScreen, int valtyp, int indx) - static int - xwlVidModeGetDotClock(ScreenPtr pScreen, int Clock) - { -- DisplayModePtr pMod; -+ RRModePtr rrmode; - -- if (!xwlVidModeGetCurrentModeline(pScreen, &pMod, NULL)) -+ rrmode = xwlVidModeGetCurrentRRMode(pScreen); -+ if (rrmode == NULL) - return 0; - -- return pMod->Clock; -- -+ return rrmode->mode.dotClock / 1000.0; - } - - static int -@@ -272,14 +303,15 @@ xwlVidModeLockZoom(ScreenPtr pScreen, Bool lock) - static ModeStatus - xwlVidModeCheckModeForMonitor(ScreenPtr pScreen, DisplayModePtr mode) - { -- DisplayModePtr pMod; -+ RRModePtr rrmode; - -- /* This should not happen */ -- if (!xwlVidModeGetCurrentModeline(pScreen, &pMod, NULL)) -+ rrmode = xwlVidModeGetRRMode(pScreen, mode->HDisplay, mode->VDisplay); -+ if (rrmode == NULL) - return MODE_ERROR; - - /* Only support mode with the same HSync/VRefresh as we advertise */ -- if (mode->HSync == pMod->HSync && mode->VRefresh == pMod->VRefresh) -+ if (mode->HSync == mode_hsync(&rrmode->mode) && -+ mode->VRefresh == mode_refresh(&rrmode->mode)) - return MODE_OK; - - /* All the rest is unsupported - If we want to succeed, return MODE_OK instead */ -@@ -289,20 +321,10 @@ xwlVidModeCheckModeForMonitor(ScreenPtr pScreen, DisplayModePtr mode) - static ModeStatus - xwlVidModeCheckModeForDriver(ScreenPtr pScreen, DisplayModePtr mode) - { -- DisplayModePtr pMod; -- -- /* This should not happen */ -- if (!xwlVidModeGetCurrentModeline(pScreen, &pMod, NULL)) -- return MODE_ERROR; -- -- if (mode->HTotal != pMod->HTotal) -- return MODE_BAD_HVALUE; -+ RRModePtr rrmode; - -- if (mode->VTotal != pMod->VTotal) -- return MODE_BAD_VVALUE; -- -- /* Unsupported for now, but pretend it works */ -- return MODE_OK; -+ rrmode = xwlVidModeGetRRMode(pScreen, mode->HDisplay, mode->VDisplay); -+ return rrmode ? MODE_OK : MODE_ERROR; - } - - static void --- -2.28.0 - diff --git a/0011-xwayland-Add-vidmode-mode-changing-emulation-support.patch b/0011-xwayland-Add-vidmode-mode-changing-emulation-support.patch deleted file mode 100644 index f3df892..0000000 --- a/0011-xwayland-Add-vidmode-mode-changing-emulation-support.patch +++ /dev/null @@ -1,236 +0,0 @@ -From 98e6cadf2ba8490c303cdc94106baf3f31006299 Mon Sep 17 00:00:00 2001 -From: Hans de Goede -Date: Tue, 9 Jul 2019 09:31:13 +0200 -Subject: [PATCH xserver 11/25] xwayland: Add vidmode mode changing emulation - support -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Add support for fake mode changes using viewport, for apps which want to -change the resolution when going fullscreen. - -Reviewed-by: Olivier Fourdan -Acked-by: Michel Dänzer -Signed-off-by: Hans de Goede -(cherry picked from commit 38de6260816674b5430144cc38a8a27d93d1bf19) ---- - hw/xwayland/xwayland-vidmode.c | 130 ++++++++++++++++++++++----------- - 1 file changed, 86 insertions(+), 44 deletions(-) - -diff --git a/hw/xwayland/xwayland-vidmode.c b/hw/xwayland/xwayland-vidmode.c -index 7cf982fcc..99a4d2c92 100644 ---- a/hw/xwayland/xwayland-vidmode.c -+++ b/hw/xwayland/xwayland-vidmode.c -@@ -106,26 +106,25 @@ xwlRRModeToDisplayMode(RRModePtr rrmode, DisplayModePtr mode) - static RRModePtr - xwlVidModeGetRRMode(ScreenPtr pScreen, int32_t width, int32_t height) - { -- RROutputPtr output = RRFirstOutput(pScreen); -+ struct xwl_screen *xwl_screen = xwl_screen_get(pScreen); -+ struct xwl_output *xwl_output = xwl_screen_get_first_output(xwl_screen); - -- if (output == NULL) -+ if (!xwl_output) - return NULL; - -- return xwl_output_find_mode(output->devPrivate, width, height); -+ return xwl_output_find_mode(xwl_output, width, height); - } - - static RRModePtr - xwlVidModeGetCurrentRRMode(ScreenPtr pScreen) - { -+ struct xwl_screen *xwl_screen = xwl_screen_get(pScreen); -+ struct xwl_output *xwl_output = xwl_screen_get_first_output(xwl_screen); - struct xwl_emulated_mode *emulated_mode; -- struct xwl_output *xwl_output; -- RROutputPtr output; - -- output = RRFirstOutput(pScreen); -- if (output == NULL) -+ if (!xwl_output) - return NULL; - -- xwl_output = output->devPrivate; - emulated_mode = - xwl_output_get_emulated_mode_for_client(xwl_output, GetCurrentClient()); - -@@ -199,39 +198,79 @@ xwlVidModeGetMonitorValue(ScreenPtr pScreen, int valtyp, int indx) - static int - xwlVidModeGetDotClock(ScreenPtr pScreen, int Clock) - { -- RRModePtr rrmode; -- -- rrmode = xwlVidModeGetCurrentRRMode(pScreen); -- if (rrmode == NULL) -- return 0; -- -- return rrmode->mode.dotClock / 1000.0; -+ return Clock; - } - - static int - xwlVidModeGetNumOfClocks(ScreenPtr pScreen, Bool *progClock) - { -- return 1; -+ /* We emulate a programmable clock, rather then a fixed set of clocks */ -+ *progClock = TRUE; -+ return 0; - } - - static Bool - xwlVidModeGetClocks(ScreenPtr pScreen, int *Clocks) - { -- *Clocks = xwlVidModeGetDotClock(pScreen, 0); -- -- return TRUE; -+ return FALSE; /* Programmable clock, no clock list */ - } - -+/* GetFirstModeline and GetNextModeline are used from Xext/vidmode.c like this: -+ * if (pVidMode->GetFirstModeline(pScreen, &mode, &dotClock)) { -+ * do { -+ * ... -+ * if (...) -+ * break; -+ * } while (pVidMode->GetNextModeline(pScreen, &mode, &dotClock)); -+ * } -+ * IOW our caller basically always loops over all the modes. There never is a -+ * return to the mainloop between GetFirstModeline and NextModeline calls where -+ * other parts of the server may change our state so we do not need to worry -+ * about xwl_output->randr_output->modes changing underneath us. -+ * Thus we can simply implement these two callbacks by storing the enumeration -+ * index in pVidMode->Next. -+ */ -+ - static Bool - xwlVidModeGetNextModeline(ScreenPtr pScreen, DisplayModePtr *mode, int *dotClock) - { -- return FALSE; -+ struct xwl_screen *xwl_screen = xwl_screen_get(pScreen); -+ struct xwl_output *xwl_output = xwl_screen_get_first_output(xwl_screen); -+ VidModePtr pVidMode; -+ DisplayModePtr pMod; -+ intptr_t index; -+ -+ pMod = dixLookupPrivate(&pScreen->devPrivates, xwlVidModePrivateKey); -+ pVidMode = VidModeGetPtr(pScreen); -+ if (xwl_output == NULL || pMod == NULL || pVidMode == NULL) -+ return FALSE; -+ -+ index = (intptr_t)pVidMode->Next; -+ if (index >= xwl_output->randr_output->numModes) -+ return FALSE; -+ xwlRRModeToDisplayMode(xwl_output->randr_output->modes[index], pMod); -+ index++; -+ pVidMode->Next = (void *)index; -+ -+ *mode = pMod; -+ if (dotClock != NULL) -+ *dotClock = pMod->Clock; -+ -+ return TRUE; - } - - static Bool - xwlVidModeGetFirstModeline(ScreenPtr pScreen, DisplayModePtr *mode, int *dotClock) - { -- return xwlVidModeGetCurrentModeline(pScreen, mode, dotClock); -+ VidModePtr pVidMode; -+ intptr_t index = 0; -+ -+ pVidMode = VidModeGetPtr(pScreen); -+ if (pVidMode == NULL) -+ return FALSE; -+ -+ pVidMode->Next = (void *)index; /* 0 */ -+ return xwlVidModeGetNextModeline(pScreen, mode, dotClock); - } - - static Bool -@@ -251,37 +290,27 @@ xwlVidModeZoomViewport(ScreenPtr pScreen, int zoom) - static Bool - xwlVidModeSetViewPort(ScreenPtr pScreen, int x, int y) - { -- RROutputPtr output; -- RRCrtcPtr crtc; -+ struct xwl_screen *xwl_screen = xwl_screen_get(pScreen); -+ struct xwl_output *xwl_output = xwl_screen_get_first_output(xwl_screen); - -- output = RRFirstOutput(pScreen); -- if (output == NULL) -- return FALSE; -- -- crtc = output->crtc; -- if (crtc == NULL) -+ if (!xwl_output) - return FALSE; - - /* Support only default viewport */ -- return (x == crtc->x && y == crtc->y); -+ return (x == xwl_output->x && y == xwl_output->y); - } - - static Bool - xwlVidModeGetViewPort(ScreenPtr pScreen, int *x, int *y) - { -- RROutputPtr output; -- RRCrtcPtr crtc; -+ struct xwl_screen *xwl_screen = xwl_screen_get(pScreen); -+ struct xwl_output *xwl_output = xwl_screen_get_first_output(xwl_screen); - -- output = RRFirstOutput(pScreen); -- if (output == NULL) -+ if (!xwl_output) - return FALSE; - -- crtc = output->crtc; -- if (crtc == NULL) -- return FALSE; -- -- *x = crtc->x; -- *y = crtc->y; -+ *x = xwl_output->x; -+ *y = xwl_output->y; - - return TRUE; - } -@@ -289,8 +318,19 @@ xwlVidModeGetViewPort(ScreenPtr pScreen, int *x, int *y) - static Bool - xwlVidModeSwitchMode(ScreenPtr pScreen, DisplayModePtr mode) - { -- /* Unsupported for now */ -- return FALSE; -+ struct xwl_screen *xwl_screen = xwl_screen_get(pScreen); -+ struct xwl_output *xwl_output = xwl_screen_get_first_output(xwl_screen); -+ RRModePtr rrmode; -+ -+ if (!xwl_output) -+ return FALSE; -+ -+ rrmode = xwl_output_find_mode(xwl_output, mode->HDisplay, mode->VDisplay); -+ if (rrmode == NULL) -+ return FALSE; -+ -+ xwl_output_set_emulated_mode(xwl_output, GetCurrentClient(), rrmode, TRUE); -+ return TRUE; - } - - static Bool -@@ -344,8 +384,10 @@ xwlVidModeAddModeline(ScreenPtr pScreen, DisplayModePtr mode) - static int - xwlVidModeGetNumOfModes(ScreenPtr pScreen) - { -- /* We have only one mode */ -- return 1; -+ struct xwl_screen *xwl_screen = xwl_screen_get(pScreen); -+ struct xwl_output *xwl_output = xwl_screen_get_first_output(xwl_screen); -+ -+ return xwl_output ? xwl_output->randr_output->numModes : 0; - } - - static Bool --- -2.28.0 - diff --git a/0012-xwayland-xwl_window_should_enable_viewport-Add-extra.patch b/0012-xwayland-xwl_window_should_enable_viewport-Add-extra.patch deleted file mode 100644 index 8b8ca1c..0000000 --- a/0012-xwayland-xwl_window_should_enable_viewport-Add-extra.patch +++ /dev/null @@ -1,57 +0,0 @@ -From 3d359d03573dee270b72f0cea1ea9061c2c886c3 Mon Sep 17 00:00:00 2001 -From: Hans de Goede -Date: Mon, 26 Aug 2019 12:26:34 +0200 -Subject: [PATCH xserver 12/25] xwayland: xwl_window_should_enable_viewport: - Add extra test -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Games based on the allegro gaming library or on ClanLib-1.0 do not size -their window to match the fullscreen resolution, instead they use a -window covering the entire screen, drawing only the fullscreen resolution -part of it. - -This commit adds a check for these games, so that we correctly apply a -viewport to them making fullscreen work properly for these games under -Xwayland. - -Reviewed-by: Olivier Fourdan -Acked-by: Michel Dänzer -Signed-off-by: Hans de Goede -(cherry picked from commit 0c305dbff8a44f3fa3d6aefd372a967029a7a527) ---- - hw/xwayland/xwayland.c | 17 +++++++++++++++++ - 1 file changed, 17 insertions(+) - -diff --git a/hw/xwayland/xwayland.c b/hw/xwayland/xwayland.c -index 87870a5f1..9175396f7 100644 ---- a/hw/xwayland/xwayland.c -+++ b/hw/xwayland/xwayland.c -@@ -638,6 +638,23 @@ xwl_window_should_enable_viewport(struct xwl_window *xwl_window, - } - } - -+ /* 2. Test if the window uses override-redirect + vidmode -+ * and matches (fully covers) the entire screen. -+ * This path gets hit by: allegro4, ClanLib-1.0. -+ */ -+ xwl_output = xwl_screen_get_first_output(xwl_screen); -+ emulated_mode = xwl_output_get_emulated_mode_for_client(xwl_output, owner); -+ if (xwl_output && xwl_window->window->overrideRedirect && -+ emulated_mode && emulated_mode->from_vidmode && -+ xwl_window->x == 0 && xwl_window->y == 0 && -+ xwl_window->width == xwl_screen->width && -+ xwl_window->height == xwl_screen->height) { -+ -+ *emulated_mode_ret = emulated_mode; -+ *xwl_output_ret = xwl_output; -+ return TRUE; -+ } -+ - return FALSE; - } - --- -2.28.0 - diff --git a/0013-xwayland-Set-_XWAYLAND_RANDR_EMU_MONITOR_RECTS-prope.patch b/0013-xwayland-Set-_XWAYLAND_RANDR_EMU_MONITOR_RECTS-prope.patch deleted file mode 100644 index 7aef593..0000000 --- a/0013-xwayland-Set-_XWAYLAND_RANDR_EMU_MONITOR_RECTS-prope.patch +++ /dev/null @@ -1,205 +0,0 @@ -From 48bc25613f91b69d9ee68e8211f8bf22317aa40a Mon Sep 17 00:00:00 2001 -From: Hans de Goede -Date: Mon, 2 Sep 2019 17:32:45 +0200 -Subject: [PATCH xserver 13/25] xwayland: Set _XWAYLAND_RANDR_EMU_MONITOR_RECTS - property for resolution emulation -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Apps using randr to change the resolution when going fullscreen, in -combination with _NET_WM_STATE_FULLSCREEN to tell the window-manager (WM) -to make their window fullscreen, expect the WM to give the fullscreen window -the size of the emulated resolution as would happen when run under Xorg (*). - -We need the WM to emulate this behavior for these apps to work correctly, -with Xwaylands resolution change emulation. For the WM to emulate this, -it needs to know about the emulated resolution for the Windows owning -client for each monitor. - -This commit adds a _XWAYLAND_RANDR_EMU_MONITOR_RECTS property, which -contains 4 Cardinals (32 bit integers) per monitor with resolution -emulation info. Window-managers can use this to get the emulated -resolution for the client and size the window correctly. - -*) Since under Xorg the resolution will actually be changed and after that -going fullscreen through NET_WM_STATE_FULLSCREEN will size the window to -be equal to the new resolution. - -Reviewed-by: Olivier Fourdan -Acked-by: Michel Dänzer -Signed-off-by: Hans de Goede -(cherry picked from commit 5315f988d9f175e4850f4259f691a68d95ce7ac2) ---- - hw/xwayland/xwayland-output.c | 77 +++++++++++++++++++++++++++++++++++ - hw/xwayland/xwayland.c | 23 +++++++++++ - hw/xwayland/xwayland.h | 3 ++ - 3 files changed, 103 insertions(+) - -diff --git a/hw/xwayland/xwayland-output.c b/hw/xwayland/xwayland-output.c -index e09d00108..0d6b9ac9f 100644 ---- a/hw/xwayland/xwayland-output.c -+++ b/hw/xwayland/xwayland-output.c -@@ -29,6 +29,7 @@ - - #include "xwayland.h" - #include -+#include - - #define ALL_ROTATIONS (RR_Rotate_0 | \ - RR_Rotate_90 | \ -@@ -391,6 +392,80 @@ xwl_output_find_mode(struct xwl_output *xwl_output, - return NULL; - } - -+struct xwl_output_randr_emu_prop { -+ Atom atom; -+ uint32_t rects[XWL_CLIENT_MAX_EMULATED_MODES][4]; -+ int rect_count; -+}; -+ -+static void -+xwl_output_randr_emu_prop(struct xwl_screen *xwl_screen, ClientPtr client, -+ struct xwl_output_randr_emu_prop *prop) -+{ -+ static const char atom_name[] = "_XWAYLAND_RANDR_EMU_MONITOR_RECTS"; -+ struct xwl_emulated_mode *emulated_mode; -+ struct xwl_output *xwl_output; -+ int index = 0; -+ -+ prop->atom = MakeAtom(atom_name, strlen(atom_name), TRUE); -+ -+ xorg_list_for_each_entry(xwl_output, &xwl_screen->output_list, link) { -+ emulated_mode = xwl_output_get_emulated_mode_for_client(xwl_output, client); -+ if (!emulated_mode) -+ continue; -+ -+ prop->rects[index][0] = xwl_output->x; -+ prop->rects[index][1] = xwl_output->y; -+ prop->rects[index][2] = emulated_mode->width; -+ prop->rects[index][3] = emulated_mode->height; -+ index++; -+ } -+ -+ prop->rect_count = index; -+} -+ -+static void -+xwl_output_set_randr_emu_prop(WindowPtr window, -+ struct xwl_output_randr_emu_prop *prop) -+{ -+ if (!xwl_window_is_toplevel(window)) -+ return; -+ -+ if (prop->rect_count) { -+ dixChangeWindowProperty(serverClient, window, prop->atom, -+ XA_CARDINAL, 32, PropModeReplace, -+ prop->rect_count * 4, prop->rects, TRUE); -+ } else { -+ DeleteProperty(serverClient, window, prop->atom); -+ } -+} -+ -+static void -+xwl_output_set_randr_emu_prop_callback(void *resource, XID id, void *user_data) -+{ -+ xwl_output_set_randr_emu_prop(resource, user_data); -+} -+ -+static void -+xwl_output_set_randr_emu_props(struct xwl_screen *xwl_screen, ClientPtr client) -+{ -+ struct xwl_output_randr_emu_prop prop = {}; -+ -+ xwl_output_randr_emu_prop(xwl_screen, client, &prop); -+ FindClientResourcesByType(client, RT_WINDOW, -+ xwl_output_set_randr_emu_prop_callback, &prop); -+} -+ -+void -+xwl_output_set_window_randr_emu_props(struct xwl_screen *xwl_screen, -+ WindowPtr window) -+{ -+ struct xwl_output_randr_emu_prop prop = {}; -+ -+ xwl_output_randr_emu_prop(xwl_screen, wClient(window), &prop); -+ xwl_output_set_randr_emu_prop(window, &prop); -+} -+ - void - xwl_output_set_emulated_mode(struct xwl_output *xwl_output, ClientPtr client, - RRModePtr mode, Bool from_vidmode) -@@ -405,6 +480,8 @@ xwl_output_set_emulated_mode(struct xwl_output *xwl_output, ClientPtr client, - xwl_output_add_emulated_mode_for_client(xwl_output, client, mode, from_vidmode); - - xwl_screen_check_resolution_change_emulation(xwl_output->xwl_screen); -+ -+ xwl_output_set_randr_emu_props(xwl_output->xwl_screen, client); - } - - static void -diff --git a/hw/xwayland/xwayland.c b/hw/xwayland/xwayland.c -index 9175396f7..32442d88e 100644 ---- a/hw/xwayland/xwayland.c -+++ b/hw/xwayland/xwayland.c -@@ -679,6 +679,27 @@ xwl_screen_check_resolution_change_emulation(struct xwl_screen *xwl_screen) - xwl_window_check_resolution_change_emulation(xwl_window); - } - -+/* This checks if the passed in Window is a toplevel client window, note this -+ * returns false for window-manager decoration windows and returns true for -+ * the actual client top-level window even if it has been reparented to -+ * a window-manager decoration window. -+ */ -+Bool -+xwl_window_is_toplevel(WindowPtr window) -+{ -+ struct xwl_screen *xwl_screen = xwl_screen_get(window->drawable.pScreen); -+ -+ if (xwl_screen_client_is_window_manager(xwl_screen, wClient(window))) -+ return FALSE; -+ -+ /* CSD and override-redirect toplevel windows */ -+ if (window_get_damage(window)) -+ return TRUE; -+ -+ /* Normal toplevel client windows, reparented to decoration window */ -+ return (window->parent && window_get_damage(window->parent)); -+} -+ - static void - xwl_window_init_allow_commits(struct xwl_window *xwl_window) - { -@@ -844,6 +865,8 @@ xwl_realize_window(WindowPtr window) - return FALSE; - } - -+ xwl_output_set_window_randr_emu_props(xwl_screen, window); -+ - return ensure_surface_for_window(window); - } - -diff --git a/hw/xwayland/xwayland.h b/hw/xwayland/xwayland.h -index 36c4c4c8b..1317ae5bb 100644 ---- a/hw/xwayland/xwayland.h -+++ b/hw/xwayland/xwayland.h -@@ -420,6 +420,7 @@ Bool xwl_screen_has_resolution_change_emulation(struct xwl_screen *xwl_screen); - struct xwl_output *xwl_screen_get_first_output(struct xwl_screen *xwl_screen); - void xwl_screen_check_resolution_change_emulation(struct xwl_screen *xwl_screen); - Bool xwl_window_has_viewport_enabled(struct xwl_window *xwl_window); -+Bool xwl_window_is_toplevel(WindowPtr window); - - void xwl_tablet_tool_set_cursor(struct xwl_tablet_tool *tool); - void xwl_seat_set_cursor(struct xwl_seat *xwl_seat); -@@ -458,6 +459,8 @@ RRModePtr xwl_output_find_mode(struct xwl_output *xwl_output, - void xwl_output_set_emulated_mode(struct xwl_output *xwl_output, - ClientPtr client, RRModePtr mode, - Bool from_vidmode); -+void xwl_output_set_window_randr_emu_props(struct xwl_screen *xwl_screen, -+ WindowPtr window); - - RRModePtr xwayland_cvt(int HDisplay, int VDisplay, - float VRefresh, Bool Reduced, Bool Interlaced); --- -2.28.0 - diff --git a/0014-xwayland-Cache-client-id-for-the-window-manager-clie.patch b/0014-xwayland-Cache-client-id-for-the-window-manager-clie.patch deleted file mode 100644 index 55f14d6..0000000 --- a/0014-xwayland-Cache-client-id-for-the-window-manager-clie.patch +++ /dev/null @@ -1,137 +0,0 @@ -From 12a0f852e3276cb5c60e44b8b0d6ddd97975fd42 Mon Sep 17 00:00:00 2001 -From: Hans de Goede -Date: Mon, 27 Jan 2020 11:08:00 +0100 -Subject: [PATCH xserver 14/25] xwayland: Cache client-id for the - window-manager client - -Instead of iterating over all clients which are listening for events on the -root window and checking if the client we are dealing with is the one -listening for SubstructureRedirectMask | ResizeRedirectMask events and thus -is the window-manager, cache the client-id of the window-manager in -xwl_screen and use that when checking if a client is the window-manager. - -Note that we cache and compare the client-id rather then the ClienPtr, -this saves reading the ClientPtr from the global clients array when doing -the comparison. - -Suggested-by: Olivier Fourdan -Acked-by: Olivier Fourdan -Signed-off-by: Hans de Goede -(cherry picked from commit ded89300c1dd541f59fe6e93c5c69d7fe7088244) ---- - hw/xwayland/xwayland.c | 48 ++++++++++++++++++++++++++++-------------- - hw/xwayland/xwayland.h | 2 ++ - 2 files changed, 34 insertions(+), 16 deletions(-) - -diff --git a/hw/xwayland/xwayland.c b/hw/xwayland/xwayland.c -index 32442d88e..f99cdf81f 100644 ---- a/hw/xwayland/xwayland.c -+++ b/hw/xwayland/xwayland.c -@@ -565,20 +565,11 @@ xwl_window_enable_viewport(struct xwl_window *xwl_window, - } - - static Bool --xwl_screen_client_is_window_manager(struct xwl_screen *xwl_screen, -- ClientPtr client) -+window_is_wm_window(WindowPtr window) - { -- WindowPtr root = xwl_screen->screen->root; -- OtherClients *others; -- -- for (others = wOtherClients(root); others; others = others->next) { -- if (SameClient(others, client)) { -- if (others->mask & (SubstructureRedirectMask | ResizeRedirectMask)) -- return TRUE; -- } -- } -+ struct xwl_screen *xwl_screen = xwl_screen_get(window->drawable.pScreen); - -- return FALSE; -+ return CLIENT_ID(window->drawable.id) == xwl_screen->wm_client_id; - } - - static ClientPtr -@@ -592,7 +583,7 @@ xwl_window_get_owner(struct xwl_window *xwl_window) - * decoration window. In that case return the client of the - * first *and only* child of the toplevel (decoration) window. - */ -- if (xwl_screen_client_is_window_manager(xwl_window->xwl_screen, client)) { -+ if (window_is_wm_window(window)) { - if (window->firstChild && window->firstChild == window->lastChild) - return wClient(window->firstChild); - else -@@ -687,9 +678,7 @@ xwl_screen_check_resolution_change_emulation(struct xwl_screen *xwl_screen) - Bool - xwl_window_is_toplevel(WindowPtr window) - { -- struct xwl_screen *xwl_screen = xwl_screen_get(window->drawable.pScreen); -- -- if (xwl_screen_client_is_window_manager(xwl_screen, wClient(window))) -+ if (window_is_wm_window(window)) - return FALSE; - - /* CSD and override-redirect toplevel windows */ -@@ -964,6 +953,30 @@ xwl_set_window_pixmap(WindowPtr window, - ensure_surface_for_window(window); - } - -+static Bool -+xwl_change_window_attributes(WindowPtr window, unsigned long mask) -+{ -+ ScreenPtr screen = window->drawable.pScreen; -+ struct xwl_screen *xwl_screen = xwl_screen_get(screen); -+ OtherClients *others; -+ Bool ret; -+ -+ screen->ChangeWindowAttributes = xwl_screen->ChangeWindowAttributes; -+ ret = (*screen->ChangeWindowAttributes) (window, mask); -+ xwl_screen->ChangeWindowAttributes = screen->ChangeWindowAttributes; -+ screen->ChangeWindowAttributes = xwl_change_window_attributes; -+ -+ if (window != screen->root || !(mask & CWEventMask)) -+ return ret; -+ -+ for (others = wOtherClients(window); others; others = others->next) { -+ if (others->mask & (SubstructureRedirectMask | ResizeRedirectMask)) -+ xwl_screen->wm_client_id = CLIENT_ID(others->resource); -+ } -+ -+ return ret; -+} -+ - static void - xwl_resize_window(WindowPtr window, - int x, int y, -@@ -1568,6 +1581,9 @@ xwl_screen_init(ScreenPtr pScreen, int argc, char **argv) - xwl_screen->CloseScreen = pScreen->CloseScreen; - pScreen->CloseScreen = xwl_close_screen; - -+ xwl_screen->ChangeWindowAttributes = pScreen->ChangeWindowAttributes; -+ pScreen->ChangeWindowAttributes = xwl_change_window_attributes; -+ - xwl_screen->ResizeWindow = pScreen->ResizeWindow; - pScreen->ResizeWindow = xwl_resize_window; - -diff --git a/hw/xwayland/xwayland.h b/hw/xwayland/xwayland.h -index 1317ae5bb..f5ffadfcc 100644 ---- a/hw/xwayland/xwayland.h -+++ b/hw/xwayland/xwayland.h -@@ -118,6 +118,7 @@ struct xwl_screen { - int height; - int depth; - ScreenPtr screen; -+ int wm_client_id; - int expecting_event; - enum RootClipMode root_clip_mode; - -@@ -135,6 +136,7 @@ struct xwl_screen { - DestroyWindowProcPtr DestroyWindow; - XYToWindowProcPtr XYToWindow; - SetWindowPixmapProcPtr SetWindowPixmap; -+ ChangeWindowAttributesProcPtr ChangeWindowAttributes; - ResizeWindowProcPtr ResizeWindow; - - struct xorg_list output_list; --- -2.28.0 - diff --git a/0015-xwayland-Reuse-viewport-instead-of-recreating.patch b/0015-xwayland-Reuse-viewport-instead-of-recreating.patch deleted file mode 100644 index c11d0c0..0000000 --- a/0015-xwayland-Reuse-viewport-instead-of-recreating.patch +++ /dev/null @@ -1,50 +0,0 @@ -From 5448ffeb9b06d20e821174c04d2280933e3ca993 Mon Sep 17 00:00:00 2001 -From: Roman Gilg -Date: Fri, 3 Jan 2020 17:12:14 +0100 -Subject: [PATCH xserver 15/25] xwayland: Reuse viewport instead of recreating - -When a viewport is already created we can reuse this object instead of -destroying it and getting a new one for updating the source rectangle and -destination size. - -Signed-off-by: Roman Gilg -Reviewed-by: Hans de Goede -Acked-by: Olivier Fourdan -Signed-off-by: Hans de Goede -(cherry picked from commit 948e02872feb641a176b3af82b6ef1201c97bb16) ---- - hw/xwayland/xwayland.c | 18 +++++++----------- - 1 file changed, 7 insertions(+), 11 deletions(-) - -diff --git a/hw/xwayland/xwayland.c b/hw/xwayland/xwayland.c -index f99cdf81f..8de3dd36b 100644 ---- a/hw/xwayland/xwayland.c -+++ b/hw/xwayland/xwayland.c -@@ -539,17 +539,13 @@ xwl_window_enable_viewport(struct xwl_window *xwl_window, - struct xwl_output *xwl_output, - struct xwl_emulated_mode *emulated_mode) - { -- /* If necessary disable old viewport to apply new settings */ -- if (xwl_window_has_viewport_enabled(xwl_window)) -- xwl_window_disable_viewport(xwl_window); -- -- DebugF("XWAYLAND: enabling viewport %dx%d -> %dx%d\n", -- emulated_mode->width, emulated_mode->height, -- xwl_output->width, xwl_output->height); -- -- xwl_window->viewport = -- wp_viewporter_get_viewport(xwl_window->xwl_screen->viewporter, -- xwl_window->surface); -+ if (!xwl_window_has_viewport_enabled(xwl_window)) { -+ DebugF("XWAYLAND: enabling viewport %dx%d -> %dx%d\n", -+ emulated_mode->width, emulated_mode->height, -+ xwl_output->width, xwl_output->height); -+ xwl_window->viewport = wp_viewporter_get_viewport(xwl_window->xwl_screen->viewporter, -+ xwl_window->surface); -+ } - - wp_viewport_set_source(xwl_window->viewport, - wl_fixed_from_int(0), --- -2.28.0 - diff --git a/0016-xwayland-Recurse-on-finding-the-none-wm-owner.patch b/0016-xwayland-Recurse-on-finding-the-none-wm-owner.patch deleted file mode 100644 index af33a86..0000000 --- a/0016-xwayland-Recurse-on-finding-the-none-wm-owner.patch +++ /dev/null @@ -1,81 +0,0 @@ -From 2896f732af4c74f124d767808a24005342d8f125 Mon Sep 17 00:00:00 2001 -From: Roman Gilg -Date: Fri, 3 Jan 2020 17:27:28 +0100 -Subject: [PATCH xserver 16/25] xwayland: Recurse on finding the none-wm owner - -An X11 window manager might add a chain of parent windows when reparenting to a -decoration window. - -That is for example the case for KWin, which reparents client windows to one -decoration and another wrapper parent window. - -Account for that by a recursion into the tree. For now assume as before that -all X11 window managers reparent with one child only for these parent windows. - -Changes by Hans de Goede: -- Move the xwl_window_is_toplevel() from a later patch in this series here - as it really belongs together with these changes -- Drop no longer necessary xwl_window argument from window_get_none_wm_owner - parameters - -Signed-off-by: Roman Gilg -Reviewed-by: Hans de Goede -Acked-by: Olivier Fourdan -Signed-off-by: Hans de Goede -(cherry picked from commit a69f7fbb54efc8ffad320c8afd23cb41fc9edc27) ---- - hw/xwayland/xwayland.c | 17 ++++++++--------- - 1 file changed, 8 insertions(+), 9 deletions(-) - -diff --git a/hw/xwayland/xwayland.c b/hw/xwayland/xwayland.c -index 8de3dd36b..c38c4180b 100644 ---- a/hw/xwayland/xwayland.c -+++ b/hw/xwayland/xwayland.c -@@ -569,19 +569,18 @@ window_is_wm_window(WindowPtr window) - } - - static ClientPtr --xwl_window_get_owner(struct xwl_window *xwl_window) -+window_get_none_wm_owner(WindowPtr window) - { -- WindowPtr window = xwl_window->window; - ClientPtr client = wClient(window); - - /* If the toplevel window is owned by the window-manager, then the -- * actual client toplevel window has been reparented to a window-manager -- * decoration window. In that case return the client of the -- * first *and only* child of the toplevel (decoration) window. -+ * actual client toplevel window has been reparented to some window-manager -+ * decoration/wrapper windows. In that case recurse by checking the client -+ * of the first *and only* child of the decoration/wrapper window. - */ - if (window_is_wm_window(window)) { - if (window->firstChild && window->firstChild == window->lastChild) -- return wClient(window->firstChild); -+ return window_get_none_wm_owner(window->firstChild); - else - return NULL; /* Should never happen, skip resolution emulation */ - } -@@ -602,7 +601,7 @@ xwl_window_should_enable_viewport(struct xwl_window *xwl_window, - if (!xwl_screen_has_resolution_change_emulation(xwl_screen)) - return FALSE; - -- owner = xwl_window_get_owner(xwl_window); -+ owner = window_get_none_wm_owner(xwl_window->window); - if (!owner) - return FALSE; - -@@ -681,8 +680,8 @@ xwl_window_is_toplevel(WindowPtr window) - if (window_get_damage(window)) - return TRUE; - -- /* Normal toplevel client windows, reparented to decoration window */ -- return (window->parent && window_get_damage(window->parent)); -+ /* Normal toplevel client windows, reparented to a window-manager window */ -+ return window->parent && window_is_wm_window(window->parent); - } - - static void --- -2.28.0 - diff --git a/0017-xwayland-Make-window_get_none_wm_owner-return-a-Wind.patch b/0017-xwayland-Make-window_get_none_wm_owner-return-a-Wind.patch deleted file mode 100644 index 58a9c4d..0000000 --- a/0017-xwayland-Make-window_get_none_wm_owner-return-a-Wind.patch +++ /dev/null @@ -1,82 +0,0 @@ -From dd83985179b4a3c2613c96922eafeea40e21b7d2 Mon Sep 17 00:00:00 2001 -From: Roman Gilg -Date: Wed, 15 Jan 2020 10:07:58 +0100 -Subject: [PATCH xserver 17/25] xwayland: Make window_get_none_wm_owner return - a Window instead of a Client - -Make window_get_none_wm_owner return the first non-wm-window instead of the -owner (client) of the first non-wm-window and rename it to -window_get_client_toplevel to match its new behavior. - -This is a preparation patch for switching to using the drawable coordinates -in xwl_window_should_enable_viewport() - -Changes by Hans de Goede: -- Split this change out into a separate patch for easier reviewing -- Rename window_get_none_wm_owner to window_get_client_toplevel to match - its new behavior - -Signed-off-by: Roman Gilg -Acked-by: Olivier Fourdan -Signed-off-by: Hans de Goede -(cherry picked from commit 060f10062eb1761515b762b46cba56c7a53db72c) ---- - hw/xwayland/xwayland.c | 17 ++++++++++------- - 1 file changed, 10 insertions(+), 7 deletions(-) - -diff --git a/hw/xwayland/xwayland.c b/hw/xwayland/xwayland.c -index c38c4180b..b3b80beae 100644 ---- a/hw/xwayland/xwayland.c -+++ b/hw/xwayland/xwayland.c -@@ -568,10 +568,10 @@ window_is_wm_window(WindowPtr window) - return CLIENT_ID(window->drawable.id) == xwl_screen->wm_client_id; - } - --static ClientPtr --window_get_none_wm_owner(WindowPtr window) -+static WindowPtr -+window_get_client_toplevel(WindowPtr window) - { -- ClientPtr client = wClient(window); -+ assert(window); - - /* If the toplevel window is owned by the window-manager, then the - * actual client toplevel window has been reparented to some window-manager -@@ -580,12 +580,12 @@ window_get_none_wm_owner(WindowPtr window) - */ - if (window_is_wm_window(window)) { - if (window->firstChild && window->firstChild == window->lastChild) -- return window_get_none_wm_owner(window->firstChild); -+ return window_get_client_toplevel(window->firstChild); - else - return NULL; /* Should never happen, skip resolution emulation */ - } - -- return client; -+ return window; - } - - static Bool -@@ -597,14 +597,17 @@ xwl_window_should_enable_viewport(struct xwl_window *xwl_window, - struct xwl_emulated_mode *emulated_mode; - struct xwl_output *xwl_output; - ClientPtr owner; -+ WindowPtr window; - - if (!xwl_screen_has_resolution_change_emulation(xwl_screen)) - return FALSE; - -- owner = window_get_none_wm_owner(xwl_window->window); -- if (!owner) -+ window = window_get_client_toplevel(xwl_window->window); -+ if (!window) - return FALSE; - -+ owner = wClient(window); -+ - /* 1. Test if the window matches the emulated mode on one of the outputs - * This path gets hit by most games / libs (e.g. SDL, SFML, OGRE) - */ --- -2.28.0 - diff --git a/0018-xwayland-Check-emulation-on-client-toplevel-resize.patch b/0018-xwayland-Check-emulation-on-client-toplevel-resize.patch deleted file mode 100644 index ea8a875..0000000 --- a/0018-xwayland-Check-emulation-on-client-toplevel-resize.patch +++ /dev/null @@ -1,121 +0,0 @@ -From be8c65e84dc4bee97bd0115a89c037fb47053d4c Mon Sep 17 00:00:00 2001 -From: Roman Gilg -Date: Fri, 3 Jan 2020 17:55:28 +0100 -Subject: [PATCH xserver 18/25] xwayland: Check emulation on client toplevel - resize - -When a reparented window is resized directly check the emulation instead of -doing this only when the window manager parent window is resized, what might -never happen. - -For that to work we need to make sure that we compare the current size of the -client toplevel when looking for an emulated mode. - -Changes by Hans de Goede: -- Remove xwl_window x, y, width and height members as those are no longer used. -- Add check for xwl_window_from_window() returning NULL. - -Signed-off-by: Roman Gilg -Acked-by: Olivier Fourdan -Signed-off-by: Hans de Goede -(cherry picked from commit 6d98f840da6dfcf2a69e03a1b3fa0bf602ba1f27) ---- - hw/xwayland/xwayland.c | 27 +++++++++++---------------- - hw/xwayland/xwayland.h | 1 - - 2 files changed, 11 insertions(+), 17 deletions(-) - -diff --git a/hw/xwayland/xwayland.c b/hw/xwayland/xwayland.c -index b3b80beae..b2e46336c 100644 ---- a/hw/xwayland/xwayland.c -+++ b/hw/xwayland/xwayland.c -@@ -598,6 +598,7 @@ xwl_window_should_enable_viewport(struct xwl_window *xwl_window, - struct xwl_output *xwl_output; - ClientPtr owner; - WindowPtr window; -+ DrawablePtr drawable; - - if (!xwl_screen_has_resolution_change_emulation(xwl_screen)) - return FALSE; -@@ -607,6 +608,7 @@ xwl_window_should_enable_viewport(struct xwl_window *xwl_window, - return FALSE; - - owner = wClient(window); -+ drawable = &window->drawable; - - /* 1. Test if the window matches the emulated mode on one of the outputs - * This path gets hit by most games / libs (e.g. SDL, SFML, OGRE) -@@ -616,10 +618,10 @@ xwl_window_should_enable_viewport(struct xwl_window *xwl_window, - if (!emulated_mode) - continue; - -- if (xwl_window->x == xwl_output->x && -- xwl_window->y == xwl_output->y && -- xwl_window->width == emulated_mode->width && -- xwl_window->height == emulated_mode->height) { -+ if (drawable->x == xwl_output->x && -+ drawable->y == xwl_output->y && -+ drawable->width == emulated_mode->width && -+ drawable->height == emulated_mode->height) { - - *emulated_mode_ret = emulated_mode; - *xwl_output_ret = xwl_output; -@@ -635,9 +637,9 @@ xwl_window_should_enable_viewport(struct xwl_window *xwl_window, - emulated_mode = xwl_output_get_emulated_mode_for_client(xwl_output, owner); - if (xwl_output && xwl_window->window->overrideRedirect && - emulated_mode && emulated_mode->from_vidmode && -- xwl_window->x == 0 && xwl_window->y == 0 && -- xwl_window->width == xwl_screen->width && -- xwl_window->height == xwl_screen->height) { -+ drawable->x == 0 && drawable->y == 0 && -+ drawable->width == xwl_screen->width && -+ drawable->height == xwl_screen->height) { - - *emulated_mode_ret = emulated_mode; - *xwl_output_ret = xwl_output; -@@ -757,8 +759,6 @@ ensure_surface_for_window(WindowPtr window) - - xwl_window->xwl_screen = xwl_screen; - xwl_window->window = window; -- xwl_window->width = window->drawable.width; -- xwl_window->height = window->drawable.height; - xwl_window->surface = wl_compositor_create_surface(xwl_screen->compositor); - if (xwl_window->surface == NULL) { - ErrorF("wl_display_create_surface failed\n"); -@@ -986,20 +986,15 @@ xwl_resize_window(WindowPtr window, - struct xwl_window *xwl_window; - - xwl_screen = xwl_screen_get(screen); -- xwl_window = xwl_window_get(window); -+ xwl_window = xwl_window_from_window(window); - - screen->ResizeWindow = xwl_screen->ResizeWindow; - (*screen->ResizeWindow) (window, x, y, width, height, sib); - xwl_screen->ResizeWindow = screen->ResizeWindow; - screen->ResizeWindow = xwl_resize_window; - -- if (xwl_window) { -- xwl_window->x = x; -- xwl_window->y = y; -- xwl_window->width = width; -- xwl_window->height = height; -+ if (xwl_window && xwl_window_is_toplevel(window)) - xwl_window_check_resolution_change_emulation(xwl_window); -- } - } - - static void -diff --git a/hw/xwayland/xwayland.h b/hw/xwayland/xwayland.h -index f5ffadfcc..0d0baac9b 100644 ---- a/hw/xwayland/xwayland.h -+++ b/hw/xwayland/xwayland.h -@@ -184,7 +184,6 @@ struct xwl_window { - struct xwl_screen *xwl_screen; - struct wl_surface *surface; - struct wp_viewport *viewport; -- int32_t x, y, width, height; - float scale_x, scale_y; - struct wl_shell_surface *shell_surface; - WindowPtr window; --- -2.28.0 - diff --git a/0019-xwayland-Also-check-resolution-change-emulation-when.patch b/0019-xwayland-Also-check-resolution-change-emulation-when.patch deleted file mode 100644 index a9c5e72..0000000 --- a/0019-xwayland-Also-check-resolution-change-emulation-when.patch +++ /dev/null @@ -1,45 +0,0 @@ -From 555e00dbf71d7c5b792bacd789cdde9c42203ff1 Mon Sep 17 00:00:00 2001 -From: Hans de Goede -Date: Wed, 15 Jan 2020 14:36:45 +0100 -Subject: [PATCH xserver 19/25] xwayland: Also check - resolution-change-emulation when the xwl_window itself moves - -The recent change to use the top-level non-window-manager Window drawable -coordinates from xwl_window_check_resolution_change_emulation() in -combination with only calling it on a resize when the top-level window -is moved breaks things with mutter/gnome-shell. - -When fullscreening a X11 window, mutter moves its window-decoration Window -wrapping the top-level Window to the monitor's origin coordinates (e.g. 0x0) -last. This updates the top-level's drawable coordinates, but as the -actual MoveWindow is called on the wrapper Window and not on the toplevel -we do not call xwl_window_check_resolution_change_emulation() and we never -enable the viewport. - -This commit fixes this by also calling -xwl_window_check_resolution_change_emulation() if the Window being moved -is an xwl_window itself. - -Acked-by: Olivier Fourdan -Signed-off-by: Hans de Goede -(cherry picked from commit 4fc107460a349a1a46f0e5251e6fd2a31f4c0428) ---- - hw/xwayland/xwayland.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/hw/xwayland/xwayland.c b/hw/xwayland/xwayland.c -index b2e46336c..e07dabcfa 100644 ---- a/hw/xwayland/xwayland.c -+++ b/hw/xwayland/xwayland.c -@@ -993,7 +993,7 @@ xwl_resize_window(WindowPtr window, - xwl_screen->ResizeWindow = screen->ResizeWindow; - screen->ResizeWindow = xwl_resize_window; - -- if (xwl_window && xwl_window_is_toplevel(window)) -+ if (xwl_window && (xwl_window_get(window) || xwl_window_is_toplevel(window))) - xwl_window_check_resolution_change_emulation(xwl_window); - } - --- -2.28.0 - diff --git a/0020-xwayland-Also-hook-screen-s-MoveWindow-method.patch b/0020-xwayland-Also-hook-screen-s-MoveWindow-method.patch deleted file mode 100644 index 4d66a7a..0000000 --- a/0020-xwayland-Also-hook-screen-s-MoveWindow-method.patch +++ /dev/null @@ -1,83 +0,0 @@ -From 46ccf740dc5e81d84b2e8c19f6211eaf1d8d06de Mon Sep 17 00:00:00 2001 -From: Hans de Goede -Date: Thu, 9 Jan 2020 11:00:36 +0100 -Subject: [PATCH xserver 20/25] xwayland: Also hook screen's MoveWindow method - -Not only hook the ResizeWindow method of the screen (which really is -MoveAndResize) but also hook the MoveWindow method for checking if we -need to setup a viewport for resolution change emulation. - -Our resolution change emulation check if the windows origin matches -the monitors origin and the windows origin can also be changed by just -a move without being resized. - -Also checking on a move becomes esp. important when we move to checking -on changes to the top-level non-window-manager client (X11)Window instead -of on changes to the xwl_window later on in this patch series. - -Acked-by: Olivier Fourdan -Signed-off-by: Hans de Goede -(cherry picked from commit 10df0437a2b142e61c4d84ffffa9592ac6846ef1) ---- - hw/xwayland/xwayland.c | 25 +++++++++++++++++++++++++ - hw/xwayland/xwayland.h | 1 + - 2 files changed, 26 insertions(+) - -diff --git a/hw/xwayland/xwayland.c b/hw/xwayland/xwayland.c -index e07dabcfa..4f19f3710 100644 ---- a/hw/xwayland/xwayland.c -+++ b/hw/xwayland/xwayland.c -@@ -997,6 +997,28 @@ xwl_resize_window(WindowPtr window, - xwl_window_check_resolution_change_emulation(xwl_window); - } - -+static void -+xwl_move_window(WindowPtr window, -+ int x, int y, -+ WindowPtr next_sib, -+ VTKind kind) -+{ -+ ScreenPtr screen = window->drawable.pScreen; -+ struct xwl_screen *xwl_screen; -+ struct xwl_window *xwl_window; -+ -+ xwl_screen = xwl_screen_get(screen); -+ xwl_window = xwl_window_from_window(window); -+ -+ screen->MoveWindow = xwl_screen->MoveWindow; -+ (*screen->MoveWindow) (window, x, y, next_sib, kind); -+ xwl_screen->MoveWindow = screen->MoveWindow; -+ screen->MoveWindow = xwl_move_window; -+ -+ if (xwl_window && (xwl_window_get(window) || xwl_window_is_toplevel(window))) -+ xwl_window_check_resolution_change_emulation(xwl_window); -+} -+ - static void - frame_callback(void *data, - struct wl_callback *callback, -@@ -1580,6 +1602,9 @@ xwl_screen_init(ScreenPtr pScreen, int argc, char **argv) - xwl_screen->ResizeWindow = pScreen->ResizeWindow; - pScreen->ResizeWindow = xwl_resize_window; - -+ xwl_screen->MoveWindow = pScreen->MoveWindow; -+ pScreen->MoveWindow = xwl_move_window; -+ - if (xwl_screen->rootless) { - xwl_screen->SetWindowPixmap = pScreen->SetWindowPixmap; - pScreen->SetWindowPixmap = xwl_set_window_pixmap; -diff --git a/hw/xwayland/xwayland.h b/hw/xwayland/xwayland.h -index 0d0baac9b..451c08e23 100644 ---- a/hw/xwayland/xwayland.h -+++ b/hw/xwayland/xwayland.h -@@ -138,6 +138,7 @@ struct xwl_screen { - SetWindowPixmapProcPtr SetWindowPixmap; - ChangeWindowAttributesProcPtr ChangeWindowAttributes; - ResizeWindowProcPtr ResizeWindow; -+ MoveWindowProcPtr MoveWindow; - - struct xorg_list output_list; - struct xorg_list seat_list; --- -2.28.0 - diff --git a/0021-xwayland-Fix-emulated-modes-not-being-removed-when-s.patch b/0021-xwayland-Fix-emulated-modes-not-being-removed-when-s.patch deleted file mode 100644 index b5f3dac..0000000 --- a/0021-xwayland-Fix-emulated-modes-not-being-removed-when-s.patch +++ /dev/null @@ -1,63 +0,0 @@ -From d64f12d119e4abe3ef337741bf7b38f8de2f9da9 Mon Sep 17 00:00:00 2001 -From: Hans de Goede -Date: Mon, 7 Oct 2019 14:27:49 +0200 -Subject: [PATCH xserver 21/25] xwayland: Fix emulated modes not being removed - when screen rotation is used - -The code building the mode-list does the following to deal with screen -rotation: - - if (need_rotate || xwl_output->rotation & (RR_Rotate_0 | RR_Rotate_180)) { - mode_width = xwl_output->width; - mode_height = xwl_output->height; - } else { - mode_width = xwl_output->height; - mode_height = xwl_output->width; - } - -This means we need to do something similar in xwl_output_set_emulated_mode() -to determine if the mode being set is the actual (not-emulated) output mode -and we this should remove any emulated modes set by the client. - -All callers of xwl_output_set_emulated_mode always pass a mode pointer -to a member of xwl_output->randr_output->modes, so we do not need to -duplicate this code, instead we can simply check that the passed in mode -is modes[0] which always is the actual output mode. - -Acked-by: Olivier Fourdan -Signed-off-by: Hans de Goede -(cherry picked from commit 88342353de45e64f408c38bb10cd1506ba0f159a) ---- - hw/xwayland/xwayland-output.c | 8 ++++++-- - 1 file changed, 6 insertions(+), 2 deletions(-) - -diff --git a/hw/xwayland/xwayland-output.c b/hw/xwayland/xwayland-output.c -index 0d6b9ac9f..4bc9cd6b8 100644 ---- a/hw/xwayland/xwayland-output.c -+++ b/hw/xwayland/xwayland-output.c -@@ -272,8 +272,11 @@ xwl_output_remove_emulated_mode_for_client(struct xwl_output *xwl_output, - struct xwl_emulated_mode *emulated_mode; - - emulated_mode = xwl_output_get_emulated_mode_for_client(xwl_output, client); -- if (emulated_mode) -+ if (emulated_mode) { -+ DebugF("XWAYLAND: xwl_output_remove_emulated_mode: %dx%d\n", -+ emulated_mode->width, emulated_mode->height); - memset(emulated_mode, 0, sizeof(*emulated_mode)); -+ } - } - - /* From hw/xfree86/common/xf86DefModeSet.c with some obscure modes dropped */ -@@ -474,7 +477,8 @@ xwl_output_set_emulated_mode(struct xwl_output *xwl_output, ClientPtr client, - from_vidmode ? "vidmode" : "randr", - mode->mode.width, mode->mode.height); - -- if (mode->mode.width == xwl_output->width && mode->mode.height == xwl_output->height) -+ /* modes[0] is the actual (not-emulated) output mode */ -+ if (mode == xwl_output->randr_output->modes[0]) - xwl_output_remove_emulated_mode_for_client(xwl_output, client); - else - xwl_output_add_emulated_mode_for_client(xwl_output, client, mode, from_vidmode); --- -2.28.0 - diff --git a/0022-xwayland-Call-xwl_window_check_resolution_change_emu.patch b/0022-xwayland-Call-xwl_window_check_resolution_change_emu.patch deleted file mode 100644 index 4f4c7f8..0000000 --- a/0022-xwayland-Call-xwl_window_check_resolution_change_emu.patch +++ /dev/null @@ -1,48 +0,0 @@ -From 677fd1ade4547008b0d67eec460770e002595c3c Mon Sep 17 00:00:00 2001 -From: Hans de Goede -Date: Mon, 4 Nov 2019 11:46:49 +0100 -Subject: [PATCH xserver 22/25] xwayland: Call - xwl_window_check_resolution_change_emulation() on newly created O-R windows - -Some clients, which use vidmode to change the resolution when going fullscreen, -create an override-redirect window and never trigger the screen->ResizeWindow -callback we rely on to do the xwl_window_check_resolution_change_emulation(). - -This causes us to not apply a viewport to them, causing the fullscreen window -to not fill the entire monitor. - -This commit adds a call to xwl_window_check_resolution_change_emulation() -at the end of ensure_surface_for_window() to fix this. Note that -ensure_surface_for_window() exits early without creating an xwl_window -for new windows which will not be backed by a wayland surface and which -thus will not have an xwl_window. - -This fixes ClanLib-0.6.x and alleggl-4.4.x using apps not properly -fullscreening. - -Acked-by: Olivier Fourdan -Signed-off-by: Hans de Goede -(cherry picked from commit 4cfc2677f5c82ca5db0919de549b9b077f1ba113) ---- - hw/xwayland/xwayland.c | 5 +++++ - 1 file changed, 5 insertions(+) - -diff --git a/hw/xwayland/xwayland.c b/hw/xwayland/xwayland.c -index 4f19f3710..5bb7a68e9 100644 ---- a/hw/xwayland/xwayland.c -+++ b/hw/xwayland/xwayland.c -@@ -808,6 +808,11 @@ ensure_surface_for_window(WindowPtr window) - - xwl_window_init_allow_commits(xwl_window); - -+ if (!window_is_wm_window(window)) { -+ /* CSD or O-R toplevel window, check viewport on creation */ -+ xwl_window_check_resolution_change_emulation(xwl_window); -+ } -+ - return TRUE; - - err_surf: --- -2.28.0 - diff --git a/0023-xwayland-Fix-setting-of-_XWAYLAND_RANDR_EMU_MONITOR_.patch b/0023-xwayland-Fix-setting-of-_XWAYLAND_RANDR_EMU_MONITOR_.patch deleted file mode 100644 index 4e15f4f..0000000 --- a/0023-xwayland-Fix-setting-of-_XWAYLAND_RANDR_EMU_MONITOR_.patch +++ /dev/null @@ -1,76 +0,0 @@ -From 049333a0ecf8574a0612bf27850f9682f0f70533 Mon Sep 17 00:00:00 2001 -From: Hans de Goede -Date: Mon, 4 Nov 2019 14:32:29 +0100 -Subject: [PATCH xserver 23/25] xwayland: Fix setting of - _XWAYLAND_RANDR_EMU_MONITOR_RECTS prop on new windows - -For window-manager managed windows, xwl_realize_window is only called for -the window-manager's decoration window and not for the actual client window -on which we should set the _XWAYLAND_RANDR_EMU_MONITOR_RECTS prop. - -Usualy this is not a problem since we walk all client windows to update -the property when the resolution is changed through a randr call. - -But for apps which first do the randr change and only then create their -window this does not work, and our xwl_output_set_window_randr_emu_props -call in xwl_realize_window is a no-op as that is only called for the wm -decoration window and not for the actual client's window. - -This commit fixes this by making ensure_surface_for_window() call -xwl_output_set_window_randr_emu_props on the first and only child of -window-manager managed windows. - -Note this also removes the non-functional xwl_output_set_window_randr_emu_props -call from xwl_realize_window, which was intended to do this, but does not -work. - -This fixes apps using the ogre3d library always running at the -monitors native resolution. - -Acked-by: Olivier Fourdan -Signed-off-by: Hans de Goede -(cherry picked from commit 148f428dfccf606b932a00d5a00af06e8dca8a7e) ---- - hw/xwayland/xwayland.c | 12 +++++++++--- - 1 file changed, 9 insertions(+), 3 deletions(-) - -diff --git a/hw/xwayland/xwayland.c b/hw/xwayland/xwayland.c -index 5bb7a68e9..1600c00cd 100644 ---- a/hw/xwayland/xwayland.c -+++ b/hw/xwayland/xwayland.c -@@ -738,6 +738,7 @@ ensure_surface_for_window(WindowPtr window) - struct xwl_screen *xwl_screen; - struct xwl_window *xwl_window; - struct wl_region *region; -+ WindowPtr toplevel; - - if (xwl_window_from_window(window)) - return TRUE; -@@ -808,7 +809,14 @@ ensure_surface_for_window(WindowPtr window) - - xwl_window_init_allow_commits(xwl_window); - -- if (!window_is_wm_window(window)) { -+ /* When a new window-manager window is realized, then the randr emulation -+ * props may have not been set on the managed client window yet. -+ */ -+ if (window_is_wm_window(window)) { -+ toplevel = window_get_client_toplevel(window); -+ if (toplevel) -+ xwl_output_set_window_randr_emu_props(xwl_screen, toplevel); -+ } else { - /* CSD or O-R toplevel window, check viewport on creation */ - xwl_window_check_resolution_change_emulation(xwl_window); - } -@@ -857,8 +865,6 @@ xwl_realize_window(WindowPtr window) - return FALSE; - } - -- xwl_output_set_window_randr_emu_props(xwl_screen, window); -- - return ensure_surface_for_window(window); - } - --- -2.28.0 - diff --git a/0024-xwayland-Remove-unnecessary-xwl_window_is_toplevel-c.patch b/0024-xwayland-Remove-unnecessary-xwl_window_is_toplevel-c.patch deleted file mode 100644 index ec778db..0000000 --- a/0024-xwayland-Remove-unnecessary-xwl_window_is_toplevel-c.patch +++ /dev/null @@ -1,49 +0,0 @@ -From f1d77ed7ac9ee9bc2f0cf60b0e4604bae092ebd0 Mon Sep 17 00:00:00 2001 -From: Hans de Goede -Date: Mon, 4 Nov 2019 15:01:18 +0100 -Subject: [PATCH xserver 24/25] xwayland: Remove unnecessary - xwl_window_is_toplevel() check from xwl_output_set_window_randr_emu_props() - -Since the recent fix to call xwl_output_set_window_randr_emu_props() from -ensure_surface_for_window(), it is now only called on a toplevel window, -so the is-toplevel check is not necessary for the -xwl_output_set_window_randr_emu_props() case. - -This commit moves the check to xwl_output_set_randr_emu_prop_callback() -so that we only do it when we are walking over all Windows of a client -to update the property on a change of the emulated resolution. - -Acked-by: Olivier Fourdan -Signed-off-by: Hans de Goede -(cherry picked from commit d4faab8708779df265239b203ed5f020bff681bf) ---- - hw/xwayland/xwayland-output.c | 6 ++---- - 1 file changed, 2 insertions(+), 4 deletions(-) - -diff --git a/hw/xwayland/xwayland-output.c b/hw/xwayland/xwayland-output.c -index 4bc9cd6b8..9d3372c8e 100644 ---- a/hw/xwayland/xwayland-output.c -+++ b/hw/xwayland/xwayland-output.c -@@ -431,9 +431,6 @@ static void - xwl_output_set_randr_emu_prop(WindowPtr window, - struct xwl_output_randr_emu_prop *prop) - { -- if (!xwl_window_is_toplevel(window)) -- return; -- - if (prop->rect_count) { - dixChangeWindowProperty(serverClient, window, prop->atom, - XA_CARDINAL, 32, PropModeReplace, -@@ -446,7 +443,8 @@ xwl_output_set_randr_emu_prop(WindowPtr window, - static void - xwl_output_set_randr_emu_prop_callback(void *resource, XID id, void *user_data) - { -- xwl_output_set_randr_emu_prop(resource, user_data); -+ if (xwl_window_is_toplevel(resource)) -+ xwl_output_set_randr_emu_prop(resource, user_data); - } - - static void --- -2.28.0 - diff --git a/0025-xwayland-Make-window_get_client_toplevel-non-recursi.patch b/0025-xwayland-Make-window_get_client_toplevel-non-recursi.patch deleted file mode 100644 index 4bf96dc..0000000 --- a/0025-xwayland-Make-window_get_client_toplevel-non-recursi.patch +++ /dev/null @@ -1,37 +0,0 @@ -From b5c62ae463101712a2ed91e976b28af5d1e73064 Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Michel=20D=C3=A4nzer?= -Date: Fri, 6 Nov 2020 10:14:19 +0100 -Subject: [PATCH xserver 25/25] xwayland: Make window_get_client_toplevel - non-recursive - -Noticed while reading the code. - -Reviewed-by: Olivier Fourdan -(cherry picked from commit df3aa4922fd7e256169e541188b724f67ca948e1) ---- - hw/xwayland/xwayland.c | 8 ++++---- - 1 file changed, 4 insertions(+), 4 deletions(-) - -diff --git a/hw/xwayland/xwayland.c b/hw/xwayland/xwayland.c -index 1600c00cd..a5756ea14 100644 ---- a/hw/xwayland/xwayland.c -+++ b/hw/xwayland/xwayland.c -@@ -578,11 +578,11 @@ window_get_client_toplevel(WindowPtr window) - * decoration/wrapper windows. In that case recurse by checking the client - * of the first *and only* child of the decoration/wrapper window. - */ -- if (window_is_wm_window(window)) { -- if (window->firstChild && window->firstChild == window->lastChild) -- return window_get_client_toplevel(window->firstChild); -- else -+ while (window_is_wm_window(window)) { -+ if (!window->firstChild || window->firstChild != window->lastChild) - return NULL; /* Should never happen, skip resolution emulation */ -+ -+ window = window->firstChild; - } - - return window; --- -2.28.0 - diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index fdf77f6..a858dbd 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.10 -Release: 3%{?gitdate:.%{gitdate}}%{?dist} +Release: 4%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -98,33 +98,6 @@ Patch6: 0001-Fedora-hack-Make-the-suid-root-wrapper-always-start-.patch # Backports from "master" upstream: # -# Backported Xwayland randr resolution change emulation support -Patch501: 0001-dix-Add-GetCurrentClient-helper.patch -Patch502: 0002-xwayland-Add-wp_viewport-wayland-extension-support.patch -Patch503: 0003-xwayland-Use-buffer_damage-instead-of-surface-damage.patch -Patch504: 0004-xwayland-Add-fake-output-modes-to-xrandr-output-mode.patch -Patch505: 0005-xwayland-Use-RandR-1.2-interface-rev-2.patch -Patch506: 0006-xwayland-Add-per-client-private-data.patch -Patch507: 0007-xwayland-Add-support-for-storing-per-client-per-outp.patch -Patch508: 0008-xwayland-Add-support-for-randr-resolution-change-emu.patch -Patch509: 0009-xwayland-Add-xwlRRModeToDisplayMode-helper-function.patch -Patch510: 0010-xwayland-Add-xwlVidModeGetCurrentRRMode-helper-to-th.patch -Patch511: 0011-xwayland-Add-vidmode-mode-changing-emulation-support.patch -Patch512: 0012-xwayland-xwl_window_should_enable_viewport-Add-extra.patch -Patch513: 0013-xwayland-Set-_XWAYLAND_RANDR_EMU_MONITOR_RECTS-prope.patch -Patch514: 0014-xwayland-Cache-client-id-for-the-window-manager-clie.patch -Patch515: 0015-xwayland-Reuse-viewport-instead-of-recreating.patch -Patch516: 0016-xwayland-Recurse-on-finding-the-none-wm-owner.patch -Patch517: 0017-xwayland-Make-window_get_none_wm_owner-return-a-Wind.patch -Patch518: 0018-xwayland-Check-emulation-on-client-toplevel-resize.patch -Patch519: 0019-xwayland-Also-check-resolution-change-emulation-when.patch -Patch520: 0020-xwayland-Also-hook-screen-s-MoveWindow-method.patch -Patch521: 0021-xwayland-Fix-emulated-modes-not-being-removed-when-s.patch -Patch522: 0022-xwayland-Call-xwl_window_check_resolution_change_emu.patch -Patch523: 0023-xwayland-Fix-setting-of-_XWAYLAND_RANDR_EMU_MONITOR_.patch -Patch524: 0024-xwayland-Remove-unnecessary-xwl_window_is_toplevel-c.patch -Patch525: 0025-xwayland-Make-window_get_client_toplevel-non-recursi.patch - BuildRequires: make BuildRequires: systemtap-sdt-devel BuildRequires: git-core @@ -145,10 +118,6 @@ BuildRequires: libXinerama-devel libXi-devel BuildRequires: libXt-devel libdmx-devel libXmu-devel libXrender-devel BuildRequires: libXi-devel libXpm-devel libXaw-devel libXfixes-devel -BuildRequires: wayland-devel -BuildRequires: wayland-protocols-devel -BuildRequires: pkgconfig(wayland-eglstream-protocols) -BuildRequires: pkgconfig(wayland-client) >= 1.3.0 BuildRequires: pkgconfig(epoxy) BuildRequires: pkgconfig(xshmfence) >= 1.1 BuildRequires: libXv-devel @@ -285,15 +254,6 @@ X protocol, and therefore supports the newer X extensions like Render and Composite. -%package Xwayland -Summary: Wayland X Server -Requires: xorg-x11-server-common >= %{version}-%{release} -Requires: libEGL - -%description Xwayland -Xwayland is an X server for running X clients under Wayland. - - %package devel Summary: SDK for X server driver module development Requires: xorg-x11-util-macros @@ -376,7 +336,6 @@ autoreconf -f -v --install || exit 1 %configure %{xservers} \ --enable-dependency-tracking \ - --enable-xwayland-eglstream \ --disable-static \ --with-pic \ %{?no_int10} \ @@ -392,7 +351,7 @@ autoreconf -f -v --install || exit 1 --enable-config-udev \ --disable-unit-tests \ --enable-dmx \ - --enable-xwayland \ + --disable-xwayland \ %{dri_flags} \ ${CONFIGURE} @@ -539,9 +498,6 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %{_bindir}/Xephyr %{_mandir}/man1/Xephyr.1* -%files Xwayland -%{_bindir}/Xwayland - %files devel %doc COPYING #{_docdir}/xorg-server @@ -556,6 +512,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Mon Feb 1 2021 Olivier Fourdan - 1.20.10-4 +- Remove Xwayland from the xserver builds + * Thu Jan 28 2021 Fedora Release Engineering - 1.20.10-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild From 5f0a71dde2357321cf582eff5ce70d4e371e2182 Mon Sep 17 00:00:00 2001 From: Peter Hutterer Date: Wed, 3 Feb 2021 15:21:19 +1000 Subject: [PATCH 05/74] Drop BuildRequires for flex-devel (#1871101) --- xorg-x11-server.spec | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index a858dbd..8a3da67 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.10 -Release: 4%{?gitdate:.%{gitdate}}%{?dist} +Release: 5%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -122,7 +122,7 @@ BuildRequires: pkgconfig(epoxy) BuildRequires: pkgconfig(xshmfence) >= 1.1 BuildRequires: libXv-devel BuildRequires: pixman-devel >= 0.30.0 -BuildRequires: libpciaccess-devel >= 0.13.1 openssl-devel bison flex flex-devel +BuildRequires: libpciaccess-devel >= 0.13.1 openssl-devel bison flex BuildRequires: mesa-libGL-devel >= 9.2 BuildRequires: mesa-libEGL-devel BuildRequires: mesa-libgbm-devel @@ -512,6 +512,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Wed Feb 03 2021 Peter Hutterer 1.20.10-5 +- Drop BuildRequires for flex-devel (#1871101) + * Mon Feb 1 2021 Olivier Fourdan - 1.20.10-4 - Remove Xwayland from the xserver builds From 03bc044aa3dd8ebb5b4492ed039e936957e223da Mon Sep 17 00:00:00 2001 From: Olivier Fourdan Date: Wed, 14 Apr 2021 10:55:42 +0200 Subject: [PATCH 06/74] xserver 1.20.11 Security fix for CVE-2021-3472 / ZDI-CAN-1259 --- sources | 2 +- xorg-x11-server.spec | 7 +++++-- 2 files changed, 6 insertions(+), 3 deletions(-) diff --git a/sources b/sources index 623b3d0..8b4e4a9 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (xorg-server-1.20.10.tar.bz2) = a07bee380bb72f2117fe6f831a6e4aded19bea1f2b36e42a019a30348e98d6fe65c0617cf819be9c6b405502f88cafb829df30aab32393774b71f1418a4cefae +SHA512 (xorg-server-1.20.11.tar.bz2) = 1017015b9fd5d53788abe3641d877e6df8609841fa5c1847c0a5e133ddcc1b758a5d695304ebd36828099ec201a85b6b70b46f5ea4f81c5bd3a16fa6e175e3c2 diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 8a3da67..1614370 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -45,8 +45,8 @@ Summary: X.Org X11 X server Name: xorg-x11-server -Version: 1.20.10 -Release: 5%{?gitdate:.%{gitdate}}%{?dist} +Version: 1.20.11 +Release: 1%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -512,6 +512,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Wed Apr 14 2021 Olivier Fourdan - 1.20.11-1 +- xserver 1.20.11 (CVE-2021-3472 / ZDI-CAN-1259) + * Wed Feb 03 2021 Peter Hutterer 1.20.10-5 - Drop BuildRequires for flex-devel (#1871101) From 4818e48baff962a94488a940e4cf777ebb8cc588 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 23 Jul 2021 21:51:14 +0000 Subject: [PATCH 07/74] - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- xorg-x11-server.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 1614370..0332529 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.11 -Release: 1%{?gitdate:.%{gitdate}}%{?dist} +Release: 2%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -512,6 +512,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Fri Jul 23 2021 Fedora Release Engineering - 1.20.11-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild + * Wed Apr 14 2021 Olivier Fourdan - 1.20.11-1 - xserver 1.20.11 (CVE-2021-3472 / ZDI-CAN-1259) From a6fbe2c194d3ef780f5991d62a59a0823ce72685 Mon Sep 17 00:00:00 2001 From: Sahana Prasad Date: Tue, 14 Sep 2021 19:18:17 +0200 Subject: [PATCH 08/74] Rebuilt with OpenSSL 3.0.0 --- xorg-x11-server.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 0332529..0781fe2 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.11 -Release: 2%{?gitdate:.%{gitdate}}%{?dist} +Release: 3%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -512,6 +512,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Tue Sep 14 2021 Sahana Prasad - 1.20.11-3 +- Rebuilt with OpenSSL 3.0.0 + * Fri Jul 23 2021 Fedora Release Engineering - 1.20.11-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild From f08aeec29a2912bcf17dfea173ce36122a614ad9 Mon Sep 17 00:00:00 2001 From: Olivier Fourdan Date: Fri, 17 Dec 2021 15:25:24 +0100 Subject: [PATCH 09/74] xserver 1.20.14 CVE-2021-4008/ZDI-CAN-14192 (#2026059, #2032941) CVE-2021-4009/ZDI-CAN-14950 (#2026072, #2032943) CVE-2021-4010/ZDI-CAN-14951 (#2026073, #2032944) CVE-2021-4011/ZDI-CAN-14952 (#2026074, #2032945) --- .gitignore | 1 + sources | 2 +- xorg-x11-server.spec | 13 ++++++++++--- 3 files changed, 12 insertions(+), 4 deletions(-) diff --git a/.gitignore b/.gitignore index ae892e8..89c66cc 100644 --- a/.gitignore +++ b/.gitignore @@ -34,3 +34,4 @@ xorg-server-1.9.1.tar.bz2 *.bz2 *.xz /xorg-x11-server-1.15.0-1.fc21.src.rpm +/xorg-server-1.20.14.tar.gz diff --git a/sources b/sources index 8b4e4a9..32cd6fa 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (xorg-server-1.20.11.tar.bz2) = 1017015b9fd5d53788abe3641d877e6df8609841fa5c1847c0a5e133ddcc1b758a5d695304ebd36828099ec201a85b6b70b46f5ea4f81c5bd3a16fa6e175e3c2 +SHA512 (xorg-server-1.20.14.tar.xz) = be3dc32cce7d55d7e38c5f6557027f13f39224c76cc83e5800555d5ce89dbdc3731773a2d186a5b97db9fc8731a2b2dd6e9829af2b01ee2559246d4aef7c4963 diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 0781fe2..f4cac33 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -45,8 +45,8 @@ Summary: X.Org X11 X server Name: xorg-x11-server -Version: 1.20.11 -Release: 3%{?gitdate:.%{gitdate}}%{?dist} +Version: 1.20.14 +Release: 1%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -59,7 +59,7 @@ Source0: xorg-server-%{gitdate}.tar.xz Source1: make-git-snapshot.sh Source2: commitid %else -Source0: https://www.x.org/pub/individual/xserver/%{pkgname}-%{version}.tar.bz2 +Source0: https://www.x.org/pub/individual/xserver/%{pkgname}-%{version}.tar.xz Source1: gitignore %endif @@ -512,6 +512,13 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Fri Dec 17 2021 Olivier - 1.20.14-1 +- xserver 1.20.14 + CVE-2021-4008/ZDI-CAN-14192 (#2026059, #2032941) + CVE-2021-4009/ZDI-CAN-14950 (#2026072, #2032943) + CVE-2021-4010/ZDI-CAN-14951 (#2026073, #2032944) + CVE-2021-4011/ZDI-CAN-14952 (#2026074, #2032945) + * Tue Sep 14 2021 Sahana Prasad - 1.20.11-3 - Rebuilt with OpenSSL 3.0.0 From 5125f505512ffb1b9695ebd1ca25d852b75094e1 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sat, 22 Jan 2022 05:24:18 +0000 Subject: [PATCH 10/74] - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- xorg-x11-server.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index f4cac33..66e63b6 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 1%{?gitdate:.%{gitdate}}%{?dist} +Release: 2%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -512,6 +512,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Sat Jan 22 2022 Fedora Release Engineering - 1.20.14-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild + * Fri Dec 17 2021 Olivier - 1.20.14-1 - xserver 1.20.14 CVE-2021-4008/ZDI-CAN-14192 (#2026059, #2032941) From befd31b80006001148e5722f6c3c0aa1240566df Mon Sep 17 00:00:00 2001 From: Olivier Fourdan Date: Fri, 28 Jan 2022 10:50:12 +0100 Subject: [PATCH 11/74] Fix crash with NVIDIA proprietary driver with Present Resolves: #2046147 --- ...sent-Check-for-NULL-to-prevent-crash.patch | 43 +++++++++++++++++++ xorg-x11-server.spec | 7 ++- 2 files changed, 48 insertions(+), 2 deletions(-) create mode 100644 0001-present-Check-for-NULL-to-prevent-crash.patch diff --git a/0001-present-Check-for-NULL-to-prevent-crash.patch b/0001-present-Check-for-NULL-to-prevent-crash.patch new file mode 100644 index 0000000..894ad0e --- /dev/null +++ b/0001-present-Check-for-NULL-to-prevent-crash.patch @@ -0,0 +1,43 @@ +From 94b4a3d45451d29e9539ea234ce8b5e9ed58546c Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?B=C5=82a=C5=BCej=20Szczygie=C5=82?= +Date: Thu, 13 Jan 2022 00:47:27 +0100 +Subject: [PATCH xserver] present: Check for NULL to prevent crash +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Closes: https://gitlab.freedesktop.org/xorg/xserver/-/issues/1275 +Signed-off-by: Błażej Szczygieł +Tested-by: Aaron Plattner +(cherry picked from commit 22d5818851967408bb7c903cb345b7ca8766094c) +--- + present/present_scmd.c | 6 ++++++ + 1 file changed, 6 insertions(+) + +diff --git a/present/present_scmd.c b/present/present_scmd.c +index 3c68e690b..11391adbb 100644 +--- a/present/present_scmd.c ++++ b/present/present_scmd.c +@@ -168,6 +168,9 @@ present_scmd_get_crtc(present_screen_priv_ptr screen_priv, WindowPtr window) + if (!screen_priv->info) + return NULL; + ++ if (!screen_priv->info->get_crtc) ++ return NULL; ++ + return (*screen_priv->info->get_crtc)(window); + } + +@@ -206,6 +209,9 @@ present_flush(WindowPtr window) + if (!screen_priv->info) + return; + ++ if (!screen_priv->info->flush) ++ return; ++ + (*screen_priv->info->flush) (window); + } + +-- +2.34.1 + diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 66e63b6..431a9c0 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 2%{?gitdate:.%{gitdate}}%{?dist} +Release: 3%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -96,7 +96,7 @@ Patch6: 0001-Fedora-hack-Make-the-suid-root-wrapper-always-start-.patch # # Backports from "master" upstream: -# +Patch100: 0001-present-Check-for-NULL-to-prevent-crash.patch BuildRequires: make BuildRequires: systemtap-sdt-devel @@ -512,6 +512,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Tue Jan 25 2022 Olivier Fourdan - 1.20.14-3 +- Fix crash with NVIDIA proprietary driver with Present (#2046147) + * Sat Jan 22 2022 Fedora Release Engineering - 1.20.14-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild From 4f6b52c6ec80890e454ac73059498d08d8d88859 Mon Sep 17 00:00:00 2001 From: Olivier Fourdan Date: Fri, 28 Jan 2022 10:54:50 +0100 Subject: [PATCH 12/74] Fix build with GCC 12 Resolves: #2047134 --- 0001-render-Fix-build-with-gcc-12.patch | 90 +++++++++++++++++++++++++ xorg-x11-server.spec | 6 +- 2 files changed, 95 insertions(+), 1 deletion(-) create mode 100644 0001-render-Fix-build-with-gcc-12.patch diff --git a/0001-render-Fix-build-with-gcc-12.patch b/0001-render-Fix-build-with-gcc-12.patch new file mode 100644 index 0000000..22f2e5a --- /dev/null +++ b/0001-render-Fix-build-with-gcc-12.patch @@ -0,0 +1,90 @@ +From 53173fdab492f0f638f6616fcf01af0b9ea6338d Mon Sep 17 00:00:00 2001 +From: Olivier Fourdan +Date: Thu, 20 Jan 2022 10:20:38 +0100 +Subject: [PATCH xserver] render: Fix build with gcc 12 +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +The xserver fails to compile with the latest gcc 12: + + render/picture.c: In function ‘CreateSolidPicture’: + render/picture.c:874:26: error: array subscript ‘union _SourcePict[0]’ is partly outside array bounds of ‘unsigned char[16]’ [-Werror=array-bounds] + 874 | pPicture->pSourcePict->type = SourcePictTypeSolidFill; + | ^~ + render/picture.c:868:45: note: object of size 16 allocated by ‘malloc’ + 868 | pPicture->pSourcePict = (SourcePictPtr) malloc(sizeof(PictSolidFill)); + | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + render/picture.c: In function ‘CreateLinearGradientPicture’: + render/picture.c:906:26: error: array subscript ‘union _SourcePict[0]’ is partly outside array bounds of ‘unsigned char[32]’ [-Werror=array-bounds] + 906 | pPicture->pSourcePict->linear.type = SourcePictTypeLinear; + | ^~ + render/picture.c:899:45: note: object of size 32 allocated by ‘malloc’ + 899 | pPicture->pSourcePict = (SourcePictPtr) malloc(sizeof(PictLinearGradient)); + | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + render/picture.c: In function ‘CreateConicalGradientPicture’: + render/picture.c:989:26: error: array subscript ‘union _SourcePict[0]’ is partly outside array bounds of ‘unsigned char[32]’ [-Werror=array-bounds] + 989 | pPicture->pSourcePict->conical.type = SourcePictTypeConical; + | ^~ + render/picture.c:982:45: note: object of size 32 allocated by ‘malloc’ + 982 | pPicture->pSourcePict = (SourcePictPtr) malloc(sizeof(PictConicalGradient)); + | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + cc1: some warnings being treated as errors + ninja: build stopped: subcommand failed. + +This is because gcc 12 has become stricter and raises a warning now. + +Fix the warning/error by allocating enough memory to store the union +struct. + +Signed-off-by: Olivier Fourdan +Acked-by: Michel Dänzer +Closes: https://gitlab.freedesktop.org/xorg/xserver/-/issues/1256 +(cherry picked from commit c6b0dcb82d4db07a2f32c09a8c09c85a5f57248e) +--- + render/picture.c | 8 ++++---- + 1 file changed, 4 insertions(+), 4 deletions(-) + +diff --git a/render/picture.c b/render/picture.c +index afa0d258f..2be4b1954 100644 +--- a/render/picture.c ++++ b/render/picture.c +@@ -865,7 +865,7 @@ CreateSolidPicture(Picture pid, xRenderColor * color, int *error) + } + + pPicture->id = pid; +- pPicture->pSourcePict = (SourcePictPtr) malloc(sizeof(PictSolidFill)); ++ pPicture->pSourcePict = (SourcePictPtr) malloc(sizeof(SourcePict)); + if (!pPicture->pSourcePict) { + *error = BadAlloc; + free(pPicture); +@@ -896,7 +896,7 @@ CreateLinearGradientPicture(Picture pid, xPointFixed * p1, xPointFixed * p2, + } + + pPicture->id = pid; +- pPicture->pSourcePict = (SourcePictPtr) malloc(sizeof(PictLinearGradient)); ++ pPicture->pSourcePict = (SourcePictPtr) malloc(sizeof(SourcePict)); + if (!pPicture->pSourcePict) { + *error = BadAlloc; + free(pPicture); +@@ -936,7 +936,7 @@ CreateRadialGradientPicture(Picture pid, xPointFixed * inner, + } + + pPicture->id = pid; +- pPicture->pSourcePict = (SourcePictPtr) malloc(sizeof(PictRadialGradient)); ++ pPicture->pSourcePict = (SourcePictPtr) malloc(sizeof(SourcePict)); + if (!pPicture->pSourcePict) { + *error = BadAlloc; + free(pPicture); +@@ -979,7 +979,7 @@ CreateConicalGradientPicture(Picture pid, xPointFixed * center, xFixed angle, + } + + pPicture->id = pid; +- pPicture->pSourcePict = (SourcePictPtr) malloc(sizeof(PictConicalGradient)); ++ pPicture->pSourcePict = (SourcePictPtr) malloc(sizeof(SourcePict)); + if (!pPicture->pSourcePict) { + *error = BadAlloc; + free(pPicture); +-- +2.34.1 + diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 431a9c0..e632148 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 3%{?gitdate:.%{gitdate}}%{?dist} +Release: 4%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -97,6 +97,7 @@ Patch6: 0001-Fedora-hack-Make-the-suid-root-wrapper-always-start-.patch # Backports from "master" upstream: Patch100: 0001-present-Check-for-NULL-to-prevent-crash.patch +Patch101: 0001-render-Fix-build-with-gcc-12.patch BuildRequires: make BuildRequires: systemtap-sdt-devel @@ -512,6 +513,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Fri Jan 28 2022 Olivier Fourdan - 1.20.14-4 +- Fix build with GCC 12 (#2047134) + * Tue Jan 25 2022 Olivier Fourdan - 1.20.14-3 - Fix crash with NVIDIA proprietary driver with Present (#2046147) From 672ae9a577e12acf35e6eab1eac5bc5e94c28320 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Franti=C5=A1ek=20Zatloukal?= Date: Mon, 11 Apr 2022 11:12:37 +0200 Subject: [PATCH 13/74] Fix basic graphic mode not working with simpledrm (#2067151) --- ...pt-devices-with-the-simpledrm-driver.patch | 34 +++++++++++++++++++ xorg-x11-server.spec | 6 +++- 2 files changed, 39 insertions(+), 1 deletion(-) create mode 100644 0001-xf86-Accept-devices-with-the-simpledrm-driver.patch diff --git a/0001-xf86-Accept-devices-with-the-simpledrm-driver.patch b/0001-xf86-Accept-devices-with-the-simpledrm-driver.patch new file mode 100644 index 0000000..3dc5796 --- /dev/null +++ b/0001-xf86-Accept-devices-with-the-simpledrm-driver.patch @@ -0,0 +1,34 @@ +From b9218fadf3c09d83566549279d68886d8258f79c Mon Sep 17 00:00:00 2001 +From: nerdopolis +Date: Thu, 30 Sep 2021 08:51:18 -0400 +Subject: [PATCH] xf86: Accept devices with the 'simpledrm' driver. + +SimpleDRM 'devices' are a fallback device, and do not have a busid +so they are getting skipped. This will allow simpledrm to work +with the modesetting driver +--- + hw/xfree86/common/xf86platformBus.c | 7 ++++++- + 1 file changed, 6 insertions(+), 1 deletion(-) + +diff --git a/hw/xfree86/common/xf86platformBus.c b/hw/xfree86/common/xf86platformBus.c +index 0e0a995ac..45028f7a6 100644 +--- a/hw/xfree86/common/xf86platformBus.c ++++ b/hw/xfree86/common/xf86platformBus.c +@@ -557,8 +557,13 @@ xf86platformProbeDev(DriverPtr drvp) + } + else { + /* for non-seat0 servers assume first device is the master */ +- if (ServerIsNotSeat0()) ++ if (ServerIsNotSeat0()) { + break; ++ } else { ++ /* Accept the device if the driver is simpledrm */ ++ if (strcmp(xf86_platform_devices[j].attribs->driver, "simpledrm") == 0) ++ break; ++ } + + if (xf86IsPrimaryPlatform(&xf86_platform_devices[j])) + break; +-- +2.35.1 + diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index e632148..63a51d6 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 4%{?gitdate:.%{gitdate}}%{?dist} +Release: 5%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -98,6 +98,7 @@ Patch6: 0001-Fedora-hack-Make-the-suid-root-wrapper-always-start-.patch # Backports from "master" upstream: Patch100: 0001-present-Check-for-NULL-to-prevent-crash.patch Patch101: 0001-render-Fix-build-with-gcc-12.patch +Patch102: 0001-xf86-Accept-devices-with-the-simpledrm-driver.patch BuildRequires: make BuildRequires: systemtap-sdt-devel @@ -513,6 +514,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Fri Apr 8 2022 Jocelyn Falempe - 1.20.14-5 +- Fix basic graphic mode not working with simpledrm (#2067151) + * Fri Jan 28 2022 Olivier Fourdan - 1.20.14-4 - Fix build with GCC 12 (#2047134) From ba5ead2efb47ba9f19f318ac3dc5c965174e461b Mon Sep 17 00:00:00 2001 From: Dominik 'Rathann' Mierzejewski Date: Wed, 13 Apr 2022 12:21:15 +0100 Subject: [PATCH 14/74] Don't hardcode fps for fake screen (#2054188) --- 0001-Don-t-hardcode-fps-for-fake-screen.patch | 135 ++++++++++++++++++ xorg-x11-server.spec | 6 +- 2 files changed, 140 insertions(+), 1 deletion(-) create mode 100644 0001-Don-t-hardcode-fps-for-fake-screen.patch diff --git a/0001-Don-t-hardcode-fps-for-fake-screen.patch b/0001-Don-t-hardcode-fps-for-fake-screen.patch new file mode 100644 index 0000000..465a92b --- /dev/null +++ b/0001-Don-t-hardcode-fps-for-fake-screen.patch @@ -0,0 +1,135 @@ +From 6497eeeb1a6552315132340565a3901d4db2144c Mon Sep 17 00:00:00 2001 +From: Boris-Barboris +Date: Tue, 22 Jun 2021 00:51:08 +0300 +Subject: [PATCH] Don't hardcode fps for fake screen + +Currently, when main hardware screen is powered-off, +X server initializes fake screen's timer with +1 second update interval. + +Streaming software like Nomachine or Vnc, as well as +desktop input automation suffers from it, since it +will forever be stuck on 1 fps until the display is +turned back on. + +This commit adds command line option -fakescreenfps +that allows the user to change the default fake screen +timer. + +Signed-off-by: Baranin Alexander +--- + man/Xserver.man | 3 +++ + os/utils.c | 12 ++++++++++++ + present/present.h | 2 ++ + present/present_fake.c | 28 ++++++++++++++++++---------- + 4 files changed, 35 insertions(+), 10 deletions(-) + +diff --git a/man/Xserver.man b/man/Xserver.man +index 31ffb8c..b1a3f40 100644 +--- a/man/Xserver.man ++++ b/man/Xserver.man +@@ -169,6 +169,9 @@ sets default cursor font. + .B \-fn \fIfont\fP + sets the default font. + .TP 8 ++.B \-fakescreenfps \fFps\fP ++sets fake presenter screen default fps (allowable range: 1-600). ++.TP 8 + .B \-fp \fIfontPath\fP + sets the search path for fonts. This path is a comma separated list + of directories which the X server searches for font databases. +diff --git a/os/utils.c b/os/utils.c +index 2ba1c80..721d4e9 100644 +--- a/os/utils.c ++++ b/os/utils.c +@@ -110,6 +110,8 @@ __stdcall unsigned long GetTickCount(void); + + #include "picture.h" + ++#include "present.h" ++ + Bool noTestExtensions; + + #ifdef COMPOSITE +@@ -526,6 +528,7 @@ UseMsg(void) + ErrorF + ("-deferglyphs [none|all|16] defer loading of [no|all|16-bit] glyphs\n"); + ErrorF("-f # bell base (0-100)\n"); ++ ErrorF("-fakescreenfps # fake screen default fps (1-600)\n"); + ErrorF("-fc string cursor font\n"); + ErrorF("-fn string default font name\n"); + ErrorF("-fp string default font path\n"); +@@ -776,6 +779,15 @@ ProcessCommandLine(int argc, char *argv[]) + else + UseMsg(); + } ++ else if (strcmp(argv[i], "-fakescreenfps") == 0) { ++ if (++i < argc) { ++ FakeScreenFps = (uint32_t) atoi(argv[i]); ++ if (FakeScreenFps < 1 || FakeScreenFps > 600) ++ FatalError("fakescreenfps must be an integer in [1;600] range\n"); ++ } ++ else ++ UseMsg(); ++ } + else if (strcmp(argv[i], "-fc") == 0) { + if (++i < argc) + defaultCursorFont = argv[i]; +diff --git a/present/present.h b/present/present.h +index 3d0b972..e7cc50d 100644 +--- a/present/present.h ++++ b/present/present.h +@@ -190,4 +190,6 @@ present_register_complete_notify(present_complete_notify_proc proc); + extern _X_EXPORT Bool + present_can_window_flip(WindowPtr window); + ++extern _X_EXPORT uint32_t FakeScreenFps; ++ + #endif /* _PRESENT_H_ */ +diff --git a/present/present_fake.c b/present/present_fake.c +index 2350638..d9ac598 100644 +--- a/present/present_fake.c ++++ b/present/present_fake.c +@@ -117,21 +117,29 @@ present_fake_queue_vblank(ScreenPtr screen, + return Success; + } + ++uint32_t FakeScreenFps = 0; ++ + void + present_fake_screen_init(ScreenPtr screen) + { ++ uint32_t fake_fps; + present_screen_priv_ptr screen_priv = present_screen_priv(screen); + +- /* For screens with hardware vblank support, the fake code +- * will be used for off-screen windows and while screens are blanked, +- * in which case we want a slow interval here +- * +- * Otherwise, pretend that the screen runs at 60Hz +- */ +- if (screen_priv->info && screen_priv->info->get_crtc) +- screen_priv->fake_interval = 1000000; +- else +- screen_priv->fake_interval = 16667; ++ if (FakeScreenFps) ++ fake_fps = FakeScreenFps; ++ else { ++ /* For screens with hardware vblank support, the fake code ++ * will be used for off-screen windows and while screens are blanked, ++ * in which case we want a large interval here: 1Hz ++ * ++ * Otherwise, pretend that the screen runs at 60Hz ++ */ ++ if (screen_priv->info && screen_priv->info->get_crtc) ++ fake_fps = 1; ++ else ++ fake_fps = 60; ++ } ++ screen_priv->fake_interval = 1000000 / fake_fps; + } + + void +-- +2.34.1 + diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 63a51d6..cc58003 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 5%{?gitdate:.%{gitdate}}%{?dist} +Release: 6%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -99,6 +99,7 @@ Patch6: 0001-Fedora-hack-Make-the-suid-root-wrapper-always-start-.patch Patch100: 0001-present-Check-for-NULL-to-prevent-crash.patch Patch101: 0001-render-Fix-build-with-gcc-12.patch Patch102: 0001-xf86-Accept-devices-with-the-simpledrm-driver.patch +Patch103: 0001-Don-t-hardcode-fps-for-fake-screen.patch BuildRequires: make BuildRequires: systemtap-sdt-devel @@ -514,6 +515,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Wed Apr 13 2022 Dominik Mierzejewski - 1.20.14-6 +- Don't hardcode fps for fake screen (#2054188) + * Fri Apr 8 2022 Jocelyn Falempe - 1.20.14-5 - Fix basic graphic mode not working with simpledrm (#2067151) From 98518b3d7ae429a5f3e11bd3453f8ab81bb27e8b Mon Sep 17 00:00:00 2001 From: Olivier Fourdan Date: Tue, 12 Jul 2022 17:26:05 +0200 Subject: [PATCH 15/74] Fix XKB vulnerabilities * CVE-2022-2319/ZDI-CAN-16062 * CVE-2022-2320/ZDI-CAN-16070 --- ...array-index-loops-to-moving-pointers.patch | 76 ++++++++ ...DeviceInfo-and-XkbSetDeviceInfoCheck.patch | 179 +++++++++++++++++ ...length-validation-for-XkbSetGeometry.patch | 182 ++++++++++++++++++ xorg-x11-server.spec | 10 +- 4 files changed, 446 insertions(+), 1 deletion(-) create mode 100644 0001-xkb-switch-to-array-index-loops-to-moving-pointers.patch create mode 100644 0002-xkb-swap-XkbSetDeviceInfo-and-XkbSetDeviceInfoCheck.patch create mode 100644 0003-xkb-add-request-length-validation-for-XkbSetGeometry.patch diff --git a/0001-xkb-switch-to-array-index-loops-to-moving-pointers.patch b/0001-xkb-switch-to-array-index-loops-to-moving-pointers.patch new file mode 100644 index 0000000..a4efb7a --- /dev/null +++ b/0001-xkb-switch-to-array-index-loops-to-moving-pointers.patch @@ -0,0 +1,76 @@ +From f1070c01d616c5f21f939d5ebc533738779451ac Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Tue, 5 Jul 2022 12:40:47 +1000 +Subject: [PATCH xserver 1/3] xkb: switch to array index loops to moving + pointers + +Most similar loops here use a pointer that advances with each loop +iteration, let's do the same here for consistency. + +No functional changes. + +Signed-off-by: Peter Hutterer +Reviewed-by: Olivier Fourdan +--- + xkb/xkb.c | 20 ++++++++++---------- + 1 file changed, 10 insertions(+), 10 deletions(-) + +diff --git a/xkb/xkb.c b/xkb/xkb.c +index a29262c24..64e52611e 100644 +--- a/xkb/xkb.c ++++ b/xkb/xkb.c +@@ -5368,16 +5368,16 @@ _CheckSetSections(XkbGeometryPtr geom, + row->left = rWire->left; + row->vertical = rWire->vertical; + kWire = (xkbKeyWireDesc *) &rWire[1]; +- for (k = 0; k < rWire->nKeys; k++) { ++ for (k = 0; k < rWire->nKeys; k++, kWire++) { + XkbKeyPtr key; + + key = XkbAddGeomKey(row); + if (!key) + return BadAlloc; +- memcpy(key->name.name, kWire[k].name, XkbKeyNameLength); +- key->gap = kWire[k].gap; +- key->shape_ndx = kWire[k].shapeNdx; +- key->color_ndx = kWire[k].colorNdx; ++ memcpy(key->name.name, kWire->name, XkbKeyNameLength); ++ key->gap = kWire->gap; ++ key->shape_ndx = kWire->shapeNdx; ++ key->color_ndx = kWire->colorNdx; + if (key->shape_ndx >= geom->num_shapes) { + client->errorValue = _XkbErrCode3(0x10, key->shape_ndx, + geom->num_shapes); +@@ -5389,7 +5389,7 @@ _CheckSetSections(XkbGeometryPtr geom, + return BadMatch; + } + } +- rWire = (xkbRowWireDesc *) &kWire[rWire->nKeys]; ++ rWire = (xkbRowWireDesc *)kWire; + } + wire = (char *) rWire; + if (sWire->nDoodads > 0) { +@@ -5454,16 +5454,16 @@ _CheckSetShapes(XkbGeometryPtr geom, + return BadAlloc; + ol->corner_radius = olWire->cornerRadius; + ptWire = (xkbPointWireDesc *) &olWire[1]; +- for (p = 0, pt = ol->points; p < olWire->nPoints; p++, pt++) { +- pt->x = ptWire[p].x; +- pt->y = ptWire[p].y; ++ for (p = 0, pt = ol->points; p < olWire->nPoints; p++, pt++, ptWire++) { ++ pt->x = ptWire->x; ++ pt->y = ptWire->y; + if (client->swapped) { + swaps(&pt->x); + swaps(&pt->y); + } + } + ol->num_points = olWire->nPoints; +- olWire = (xkbOutlineWireDesc *) (&ptWire[olWire->nPoints]); ++ olWire = (xkbOutlineWireDesc *)ptWire; + } + if (shapeWire->primaryNdx != XkbNoShape) + shape->primary = &shape->outlines[shapeWire->primaryNdx]; +-- +2.36.1 + diff --git a/0002-xkb-swap-XkbSetDeviceInfo-and-XkbSetDeviceInfoCheck.patch b/0002-xkb-swap-XkbSetDeviceInfo-and-XkbSetDeviceInfoCheck.patch new file mode 100644 index 0000000..8973a0e --- /dev/null +++ b/0002-xkb-swap-XkbSetDeviceInfo-and-XkbSetDeviceInfoCheck.patch @@ -0,0 +1,179 @@ +From dd8caf39e9e15d8f302e54045dd08d8ebf1025dc Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Tue, 5 Jul 2022 09:50:41 +1000 +Subject: [PATCH xserver 2/3] xkb: swap XkbSetDeviceInfo and + XkbSetDeviceInfoCheck + +XKB often uses a FooCheck and Foo function pair, the former is supposed +to check all values in the request and error out on BadLength, +BadValue, etc. The latter is then called once we're confident the values +are good (they may still fail on an individual device, but that's a +different topic). + +In the case of XkbSetDeviceInfo, those functions were incorrectly +named, with XkbSetDeviceInfo ending up as the checker function and +XkbSetDeviceInfoCheck as the setter function. As a result, the setter +function was called before the checker function, accessing request +data and modifying device state before we ensured that the data is +valid. + +In particular, the setter function relied on values being already +byte-swapped. This in turn could lead to potential OOB memory access. + +Fix this by correctly naming the functions and moving the length checks +over to the checker function. These were added in 87c64fc5b0 to the +wrong function, probably due to the incorrect naming. + +Fixes ZDI-CAN 16070, CVE-2022-2320. + +This vulnerability was discovered by: +Jan-Niklas Sohn working with Trend Micro Zero Day Initiative + +Introduced in c06e27b2f6fd9f7b9f827623a48876a225264132 + +Signed-off-by: Peter Hutterer +--- + xkb/xkb.c | 46 +++++++++++++++++++++++++--------------------- + 1 file changed, 25 insertions(+), 21 deletions(-) + +diff --git a/xkb/xkb.c b/xkb/xkb.c +index 64e52611e..34b2c290b 100644 +--- a/xkb/xkb.c ++++ b/xkb/xkb.c +@@ -6550,7 +6550,8 @@ ProcXkbGetDeviceInfo(ClientPtr client) + static char * + CheckSetDeviceIndicators(char *wire, + DeviceIntPtr dev, +- int num, int *status_rtrn, ClientPtr client) ++ int num, int *status_rtrn, ClientPtr client, ++ xkbSetDeviceInfoReq * stuff) + { + xkbDeviceLedsWireDesc *ledWire; + int i; +@@ -6558,6 +6559,11 @@ CheckSetDeviceIndicators(char *wire, + + ledWire = (xkbDeviceLedsWireDesc *) wire; + for (i = 0; i < num; i++) { ++ if (!_XkbCheckRequestBounds(client, stuff, ledWire, ledWire + 1)) { ++ *status_rtrn = BadLength; ++ return (char *) ledWire; ++ } ++ + if (client->swapped) { + swaps(&ledWire->ledClass); + swaps(&ledWire->ledID); +@@ -6585,6 +6591,11 @@ CheckSetDeviceIndicators(char *wire, + atomWire = (CARD32 *) &ledWire[1]; + if (nNames > 0) { + for (n = 0; n < nNames; n++) { ++ if (!_XkbCheckRequestBounds(client, stuff, atomWire, atomWire + 1)) { ++ *status_rtrn = BadLength; ++ return (char *) atomWire; ++ } ++ + if (client->swapped) { + swapl(atomWire); + } +@@ -6596,6 +6607,10 @@ CheckSetDeviceIndicators(char *wire, + mapWire = (xkbIndicatorMapWireDesc *) atomWire; + if (nMaps > 0) { + for (n = 0; n < nMaps; n++) { ++ if (!_XkbCheckRequestBounds(client, stuff, mapWire, mapWire + 1)) { ++ *status_rtrn = BadLength; ++ return (char *) mapWire; ++ } + if (client->swapped) { + swaps(&mapWire->virtualMods); + swapl(&mapWire->ctrls); +@@ -6647,11 +6662,6 @@ SetDeviceIndicators(char *wire, + xkbIndicatorMapWireDesc *mapWire; + XkbSrvLedInfoPtr sli; + +- if (!_XkbCheckRequestBounds(client, stuff, ledWire, ledWire + 1)) { +- *status_rtrn = BadLength; +- return (char *) ledWire; +- } +- + namec = mapc = statec = 0; + sli = XkbFindSrvLedInfo(dev, ledWire->ledClass, ledWire->ledID, + XkbXI_IndicatorMapsMask); +@@ -6670,10 +6680,6 @@ SetDeviceIndicators(char *wire, + memset((char *) sli->names, 0, XkbNumIndicators * sizeof(Atom)); + for (n = 0, bit = 1; n < XkbNumIndicators; n++, bit <<= 1) { + if (ledWire->namesPresent & bit) { +- if (!_XkbCheckRequestBounds(client, stuff, atomWire, atomWire + 1)) { +- *status_rtrn = BadLength; +- return (char *) atomWire; +- } + sli->names[n] = (Atom) *atomWire; + if (sli->names[n] == None) + ledWire->namesPresent &= ~bit; +@@ -6691,10 +6697,6 @@ SetDeviceIndicators(char *wire, + if (ledWire->mapsPresent) { + for (n = 0, bit = 1; n < XkbNumIndicators; n++, bit <<= 1) { + if (ledWire->mapsPresent & bit) { +- if (!_XkbCheckRequestBounds(client, stuff, mapWire, mapWire + 1)) { +- *status_rtrn = BadLength; +- return (char *) mapWire; +- } + sli->maps[n].flags = mapWire->flags; + sli->maps[n].which_groups = mapWire->whichGroups; + sli->maps[n].groups = mapWire->groups; +@@ -6730,13 +6732,17 @@ SetDeviceIndicators(char *wire, + } + + static int +-_XkbSetDeviceInfo(ClientPtr client, DeviceIntPtr dev, ++_XkbSetDeviceInfoCheck(ClientPtr client, DeviceIntPtr dev, + xkbSetDeviceInfoReq * stuff) + { + char *wire; + + wire = (char *) &stuff[1]; + if (stuff->change & XkbXI_ButtonActionsMask) { ++ int sz = stuff->nBtns * SIZEOF(xkbActionWireDesc); ++ if (!_XkbCheckRequestBounds(client, stuff, wire, (char *) wire + sz)) ++ return BadLength; ++ + if (!dev->button) { + client->errorValue = _XkbErrCode2(XkbErr_BadClass, ButtonClass); + return XkbKeyboardErrorCode; +@@ -6747,13 +6753,13 @@ _XkbSetDeviceInfo(ClientPtr client, DeviceIntPtr dev, + dev->button->numButtons); + return BadMatch; + } +- wire += (stuff->nBtns * SIZEOF(xkbActionWireDesc)); ++ wire += sz; + } + if (stuff->change & XkbXI_IndicatorsMask) { + int status = Success; + + wire = CheckSetDeviceIndicators(wire, dev, stuff->nDeviceLedFBs, +- &status, client); ++ &status, client, stuff); + if (status != Success) + return status; + } +@@ -6764,8 +6770,8 @@ _XkbSetDeviceInfo(ClientPtr client, DeviceIntPtr dev, + } + + static int +-_XkbSetDeviceInfoCheck(ClientPtr client, DeviceIntPtr dev, +- xkbSetDeviceInfoReq * stuff) ++_XkbSetDeviceInfo(ClientPtr client, DeviceIntPtr dev, ++ xkbSetDeviceInfoReq * stuff) + { + char *wire; + xkbExtensionDeviceNotify ed; +@@ -6789,8 +6795,6 @@ _XkbSetDeviceInfoCheck(ClientPtr client, DeviceIntPtr dev, + if (stuff->firstBtn + stuff->nBtns > nBtns) + return BadValue; + sz = stuff->nBtns * SIZEOF(xkbActionWireDesc); +- if (!_XkbCheckRequestBounds(client, stuff, wire, (char *) wire + sz)) +- return BadLength; + memcpy((char *) &acts[stuff->firstBtn], (char *) wire, sz); + wire += sz; + ed.reason |= XkbXI_ButtonActionsMask; +-- +2.36.1 + diff --git a/0003-xkb-add-request-length-validation-for-XkbSetGeometry.patch b/0003-xkb-add-request-length-validation-for-XkbSetGeometry.patch new file mode 100644 index 0000000..dca4d7c --- /dev/null +++ b/0003-xkb-add-request-length-validation-for-XkbSetGeometry.patch @@ -0,0 +1,182 @@ +From 6907b6ea2b4ce949cb07271f5b678d5966d9df42 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Tue, 5 Jul 2022 11:11:06 +1000 +Subject: [PATCH xserver 3/3] xkb: add request length validation for + XkbSetGeometry + +No validation of the various fields on that report were done, so a +malicious client could send a short request that claims it had N +sections, or rows, or keys, and the server would process the request for +N sections, running out of bounds of the actual request data. + +Fix this by adding size checks to ensure our data is valid. + +ZDI-CAN 16062, CVE-2022-2319. + +This vulnerability was discovered by: +Jan-Niklas Sohn working with Trend Micro Zero Day Initiative + +Signed-off-by: Peter Hutterer +--- + xkb/xkb.c | 43 ++++++++++++++++++++++++++++++++++++++----- + 1 file changed, 38 insertions(+), 5 deletions(-) + +diff --git a/xkb/xkb.c b/xkb/xkb.c +index 34b2c290b..4692895db 100644 +--- a/xkb/xkb.c ++++ b/xkb/xkb.c +@@ -5156,7 +5156,7 @@ _GetCountedString(char **wire_inout, ClientPtr client, char **str) + } + + static Status +-_CheckSetDoodad(char **wire_inout, ++_CheckSetDoodad(char **wire_inout, xkbSetGeometryReq *req, + XkbGeometryPtr geom, XkbSectionPtr section, ClientPtr client) + { + char *wire; +@@ -5167,6 +5167,9 @@ _CheckSetDoodad(char **wire_inout, + Status status; + + dWire = (xkbDoodadWireDesc *) (*wire_inout); ++ if (!_XkbCheckRequestBounds(client, req, dWire, dWire + 1)) ++ return BadLength; ++ + any = dWire->any; + wire = (char *) &dWire[1]; + if (client->swapped) { +@@ -5269,7 +5272,7 @@ _CheckSetDoodad(char **wire_inout, + } + + static Status +-_CheckSetOverlay(char **wire_inout, ++_CheckSetOverlay(char **wire_inout, xkbSetGeometryReq *req, + XkbGeometryPtr geom, XkbSectionPtr section, ClientPtr client) + { + register int r; +@@ -5280,6 +5283,9 @@ _CheckSetOverlay(char **wire_inout, + + wire = *wire_inout; + olWire = (xkbOverlayWireDesc *) wire; ++ if (!_XkbCheckRequestBounds(client, req, olWire, olWire + 1)) ++ return BadLength; ++ + if (client->swapped) { + swapl(&olWire->name); + } +@@ -5291,6 +5297,9 @@ _CheckSetOverlay(char **wire_inout, + xkbOverlayKeyWireDesc *kWire; + XkbOverlayRowPtr row; + ++ if (!_XkbCheckRequestBounds(client, req, rWire, rWire + 1)) ++ return BadLength; ++ + if (rWire->rowUnder > section->num_rows) { + client->errorValue = _XkbErrCode4(0x20, r, section->num_rows, + rWire->rowUnder); +@@ -5299,6 +5308,9 @@ _CheckSetOverlay(char **wire_inout, + row = XkbAddGeomOverlayRow(ol, rWire->rowUnder, rWire->nKeys); + kWire = (xkbOverlayKeyWireDesc *) &rWire[1]; + for (k = 0; k < rWire->nKeys; k++, kWire++) { ++ if (!_XkbCheckRequestBounds(client, req, kWire, kWire + 1)) ++ return BadLength; ++ + if (XkbAddGeomOverlayKey(ol, row, + (char *) kWire->over, + (char *) kWire->under) == NULL) { +@@ -5332,6 +5344,9 @@ _CheckSetSections(XkbGeometryPtr geom, + register int r; + xkbRowWireDesc *rWire; + ++ if (!_XkbCheckRequestBounds(client, req, sWire, sWire + 1)) ++ return BadLength; ++ + if (client->swapped) { + swapl(&sWire->name); + swaps(&sWire->top); +@@ -5357,6 +5372,9 @@ _CheckSetSections(XkbGeometryPtr geom, + XkbRowPtr row; + xkbKeyWireDesc *kWire; + ++ if (!_XkbCheckRequestBounds(client, req, rWire, rWire + 1)) ++ return BadLength; ++ + if (client->swapped) { + swaps(&rWire->top); + swaps(&rWire->left); +@@ -5371,6 +5389,9 @@ _CheckSetSections(XkbGeometryPtr geom, + for (k = 0; k < rWire->nKeys; k++, kWire++) { + XkbKeyPtr key; + ++ if (!_XkbCheckRequestBounds(client, req, kWire, kWire + 1)) ++ return BadLength; ++ + key = XkbAddGeomKey(row); + if (!key) + return BadAlloc; +@@ -5396,7 +5417,7 @@ _CheckSetSections(XkbGeometryPtr geom, + register int d; + + for (d = 0; d < sWire->nDoodads; d++) { +- status = _CheckSetDoodad(&wire, geom, section, client); ++ status = _CheckSetDoodad(&wire, req, geom, section, client); + if (status != Success) + return status; + } +@@ -5405,7 +5426,7 @@ _CheckSetSections(XkbGeometryPtr geom, + register int o; + + for (o = 0; o < sWire->nOverlays; o++) { +- status = _CheckSetOverlay(&wire, geom, section, client); ++ status = _CheckSetOverlay(&wire, req, geom, section, client); + if (status != Success) + return status; + } +@@ -5439,6 +5460,9 @@ _CheckSetShapes(XkbGeometryPtr geom, + xkbOutlineWireDesc *olWire; + XkbOutlinePtr ol; + ++ if (!_XkbCheckRequestBounds(client, req, shapeWire, shapeWire + 1)) ++ return BadLength; ++ + shape = + XkbAddGeomShape(geom, shapeWire->name, shapeWire->nOutlines); + if (!shape) +@@ -5449,12 +5473,18 @@ _CheckSetShapes(XkbGeometryPtr geom, + XkbPointPtr pt; + xkbPointWireDesc *ptWire; + ++ if (!_XkbCheckRequestBounds(client, req, olWire, olWire + 1)) ++ return BadLength; ++ + ol = XkbAddGeomOutline(shape, olWire->nPoints); + if (!ol) + return BadAlloc; + ol->corner_radius = olWire->cornerRadius; + ptWire = (xkbPointWireDesc *) &olWire[1]; + for (p = 0, pt = ol->points; p < olWire->nPoints; p++, pt++, ptWire++) { ++ if (!_XkbCheckRequestBounds(client, req, ptWire, ptWire + 1)) ++ return BadLength; ++ + pt->x = ptWire->x; + pt->y = ptWire->y; + if (client->swapped) { +@@ -5560,12 +5590,15 @@ _CheckSetGeom(XkbGeometryPtr geom, xkbSetGeometryReq * req, ClientPtr client) + return status; + + for (i = 0; i < req->nDoodads; i++) { +- status = _CheckSetDoodad(&wire, geom, NULL, client); ++ status = _CheckSetDoodad(&wire, req, geom, NULL, client); + if (status != Success) + return status; + } + + for (i = 0; i < req->nKeyAliases; i++) { ++ if (!_XkbCheckRequestBounds(client, req, wire, wire + XkbKeyNameLength)) ++ return BadLength; ++ + if (XkbAddGeomKeyAlias(geom, &wire[XkbKeyNameLength], wire) == NULL) + return BadAlloc; + wire += 2 * XkbKeyNameLength; +-- +2.36.1 + diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index cc58003..6712284 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 6%{?gitdate:.%{gitdate}}%{?dist} +Release: 7%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -101,6 +101,11 @@ Patch101: 0001-render-Fix-build-with-gcc-12.patch Patch102: 0001-xf86-Accept-devices-with-the-simpledrm-driver.patch Patch103: 0001-Don-t-hardcode-fps-for-fake-screen.patch +# CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070 +Patch110: 0001-xkb-switch-to-array-index-loops-to-moving-pointers.patch +Patch111: 0002-xkb-swap-XkbSetDeviceInfo-and-XkbSetDeviceInfoCheck.patch +Patch112: 0003-xkb-add-request-length-validation-for-XkbSetGeometry.patch + BuildRequires: make BuildRequires: systemtap-sdt-devel BuildRequires: git-core @@ -515,6 +520,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Tue Jul 12 2022 Olivier Fourdan - 1.20.14-7 +- Fix CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070 + * Wed Apr 13 2022 Dominik Mierzejewski - 1.20.14-6 - Don't hardcode fps for fake screen (#2054188) From 88dcddb59c19c2ebfd626b040b7e1075f732f9a3 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sat, 23 Jul 2022 13:25:55 +0000 Subject: [PATCH 16/74] Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- xorg-x11-server.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 6712284..c9f627e 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 7%{?gitdate:.%{gitdate}}%{?dist} +Release: 8%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -520,6 +520,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Sat Jul 23 2022 Fedora Release Engineering - 1.20.14-8 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild + * Tue Jul 12 2022 Olivier Fourdan - 1.20.14-7 - Fix CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070 From 9fc1d98575629b289a8bb0d9b66a3147677a8be3 Mon Sep 17 00:00:00 2001 From: Olivier Fourdan Date: Tue, 8 Nov 2022 12:03:21 +0100 Subject: [PATCH 17/74] Fix CVE-2022-3550, CVE-2022-3551 --- ...possible-memleaks-in-XkbGetKbdByName.patch | 59 +++++++++++++++++++ ...ntedString-against-request-length-at.patch | 35 +++++++++++ xorg-x11-server.spec | 10 +++- 3 files changed, 103 insertions(+), 1 deletion(-) create mode 100644 0001-xkb-fix-some-possible-memleaks-in-XkbGetKbdByName.patch create mode 100644 0001-xkb-proof-GetCountedString-against-request-length-at.patch diff --git a/0001-xkb-fix-some-possible-memleaks-in-XkbGetKbdByName.patch b/0001-xkb-fix-some-possible-memleaks-in-XkbGetKbdByName.patch new file mode 100644 index 0000000..6e5ebb5 --- /dev/null +++ b/0001-xkb-fix-some-possible-memleaks-in-XkbGetKbdByName.patch @@ -0,0 +1,59 @@ +From 18f91b950e22c2a342a4fbc55e9ddf7534a707d2 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Wed, 13 Jul 2022 11:23:09 +1000 +Subject: [PATCH xserver] xkb: fix some possible memleaks in XkbGetKbdByName + +GetComponentByName returns an allocated string, so let's free that if we +fail somewhere. + +Signed-off-by: Peter Hutterer +--- + xkb/xkb.c | 26 ++++++++++++++++++++------ + 1 file changed, 20 insertions(+), 6 deletions(-) + +diff --git a/xkb/xkb.c b/xkb/xkb.c +index 4692895db..b79a269e3 100644 +--- a/xkb/xkb.c ++++ b/xkb/xkb.c +@@ -5935,18 +5935,32 @@ ProcXkbGetKbdByName(ClientPtr client) + xkb = dev->key->xkbInfo->desc; + status = Success; + str = (unsigned char *) &stuff[1]; +- if (GetComponentSpec(&str, TRUE, &status)) /* keymap, unsupported */ +- return BadMatch; ++ { ++ char *keymap = GetComponentSpec(&str, TRUE, &status); /* keymap, unsupported */ ++ if (keymap) { ++ free(keymap); ++ return BadMatch; ++ } ++ } + names.keycodes = GetComponentSpec(&str, TRUE, &status); + names.types = GetComponentSpec(&str, TRUE, &status); + names.compat = GetComponentSpec(&str, TRUE, &status); + names.symbols = GetComponentSpec(&str, TRUE, &status); + names.geometry = GetComponentSpec(&str, TRUE, &status); +- if (status != Success) ++ if (status == Success) { ++ len = str - ((unsigned char *) stuff); ++ if ((XkbPaddedSize(len) / 4) != stuff->length) ++ status = BadLength; ++ } ++ ++ if (status != Success) { ++ free(names.keycodes); ++ free(names.types); ++ free(names.compat); ++ free(names.symbols); ++ free(names.geometry); + return status; +- len = str - ((unsigned char *) stuff); +- if ((XkbPaddedSize(len) / 4) != stuff->length) +- return BadLength; ++ } + + CHK_MASK_LEGAL(0x01, stuff->want, XkbGBN_AllComponentsMask); + CHK_MASK_LEGAL(0x02, stuff->need, XkbGBN_AllComponentsMask); +-- +2.38.1 + diff --git a/0001-xkb-proof-GetCountedString-against-request-length-at.patch b/0001-xkb-proof-GetCountedString-against-request-length-at.patch new file mode 100644 index 0000000..d358a32 --- /dev/null +++ b/0001-xkb-proof-GetCountedString-against-request-length-at.patch @@ -0,0 +1,35 @@ +From 11beef0b7f1ed290348e45618e5fa0d2bffcb72e Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Tue, 5 Jul 2022 12:06:20 +1000 +Subject: [PATCH xserver] xkb: proof GetCountedString against request length + attacks + +GetCountedString did a check for the whole string to be within the +request buffer but not for the initial 2 bytes that contain the length +field. A swapped client could send a malformed request to trigger a +swaps() on those bytes, writing into random memory. + +Signed-off-by: Peter Hutterer +--- + xkb/xkb.c | 5 +++++ + 1 file changed, 5 insertions(+) + +diff --git a/xkb/xkb.c b/xkb/xkb.c +index f42f59ef3..1841cff26 100644 +--- a/xkb/xkb.c ++++ b/xkb/xkb.c +@@ -5137,6 +5137,11 @@ _GetCountedString(char **wire_inout, ClientPtr client, char **str) + CARD16 len; + + wire = *wire_inout; ++ ++ if (client->req_len < ++ bytes_to_int32(wire + 2 - (char *) client->requestBuffer)) ++ return BadValue; ++ + len = *(CARD16 *) wire; + if (client->swapped) { + swaps(&len); +-- +2.38.1 + diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index c9f627e..f676f0c 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 8%{?gitdate:.%{gitdate}}%{?dist} +Release: 9%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -106,6 +106,11 @@ Patch110: 0001-xkb-switch-to-array-index-loops-to-moving-pointers.patch Patch111: 0002-xkb-swap-XkbSetDeviceInfo-and-XkbSetDeviceInfoCheck.patch Patch112: 0003-xkb-add-request-length-validation-for-XkbSetGeometry.patch +# CVE-2022-3550 +Patch113: 0001-xkb-proof-GetCountedString-against-request-length-at.patch +# CVE-2022-3551 +Patch114: 0001-xkb-fix-some-possible-memleaks-in-XkbGetKbdByName.patch + BuildRequires: make BuildRequires: systemtap-sdt-devel BuildRequires: git-core @@ -520,6 +525,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Tue Nov 8 2022 Olivier Fourdan - 1.20.14-9 +- Fix CVE-2022-3550, CVE-2022-3551 + * Sat Jul 23 2022 Fedora Release Engineering - 1.20.14-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild From 4e595ce4fd362911c230e5538b96d9ac4e9da381 Mon Sep 17 00:00:00 2001 From: Peter Hutterer Date: Wed, 23 Nov 2022 14:57:50 +1000 Subject: [PATCH 18/74] Drop dependency on xorg-x11-font-utils, it was only there for one build-time variable that's always the same value anyway (#2145088) --- ...search-for-the-fontrootdir-ourselves.patch | 72 +++++++++++++++++++ xorg-x11-server.spec | 13 +++- 2 files changed, 83 insertions(+), 2 deletions(-) create mode 100644 0001-configure.ac-search-for-the-fontrootdir-ourselves.patch diff --git a/0001-configure.ac-search-for-the-fontrootdir-ourselves.patch b/0001-configure.ac-search-for-the-fontrootdir-ourselves.patch new file mode 100644 index 0000000..3e29358 --- /dev/null +++ b/0001-configure.ac-search-for-the-fontrootdir-ourselves.patch @@ -0,0 +1,72 @@ +From e67e988730346c63d2f0cdf2531ed36b0c7ad5a6 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Wed, 23 Nov 2022 14:50:29 +1000 +Subject: [PATCH xserver] configure.ac: search for the fontrootdir ourselves + +This replaces the use of font-utils' .m4 macro set with a copy of the +only one we actually want: the bit for the fontrootpath. + +We don't need configure options for every single subfont directory, so +let's hardcode those in the default font path. Like meson does upstream +too. + +With this patch we no longer require the font-utils dependency. + +Signed-off-by: Peter Hutterer +--- + configure.ac | 28 +++++++++++++++++----------- + 1 file changed, 17 insertions(+), 11 deletions(-) + +diff --git a/configure.ac b/configure.ac +index 0909cc5b4d..2349320888 100644 +--- a/configure.ac ++++ b/configure.ac +@@ -49,9 +49,6 @@ XORG_WITH_XSLTPROC + XORG_ENABLE_UNIT_TESTS + XORG_LD_WRAP([optional]) + +-m4_ifndef([XORG_FONT_MACROS_VERSION], [m4_fatal([must install font-util 1.1 or later before running autoconf/autogen])]) +-XORG_FONT_MACROS_VERSION(1.1) +- + dnl this gets generated by autoheader, and thus contains all the defines. we + dnl don't ever actually use it, internally. + AC_CONFIG_HEADERS(include/do-not-use-config.h) +@@ -450,18 +447,27 @@ AC_MSG_RESULT([$FALLBACK_INPUT_DRIVER]) + AC_DEFINE_UNQUOTED(FALLBACK_INPUT_DRIVER, ["$FALLBACK_INPUT_DRIVER"], [ Fallback input driver ]) + + dnl Determine font path +-XORG_FONTROOTDIR +-XORG_FONTSUBDIR(FONTMISCDIR, fontmiscdir, misc) +-XORG_FONTSUBDIR(FONTOTFDIR, fontotfdir, OTF) +-XORG_FONTSUBDIR(FONTTTFDIR, fontttfdir, TTF) +-XORG_FONTSUBDIR(FONTTYPE1DIR, fonttype1dir, Type1) +-XORG_FONTSUBDIR(FONT75DPIDIR, font75dpidir, 75dpi) +-XORG_FONTSUBDIR(FONT100DPIDIR, font100dpidir, 100dpi) ++dnl This is a copy of XORG_FONTROOTDIR from font-utils so we can drop the dependency ++AC_MSG_CHECKING([for root directory for font files]) ++AC_ARG_WITH(fontrootdir, ++ AS_HELP_STRING([--with-fontrootdir=DIR], ++ [Path to root directory for font files]), ++ [FONTROOTDIR="$withval"]) ++# if --with-fontrootdir not specified... ++if test "x${FONTROOTDIR}" = "x"; then ++ FONTROOTDIR=`$PKG_CONFIG --variable=fontrootdir fontutil` ++fi ++# ...and if pkg-config didn't find fontdir in fontutil.pc... ++if test "x${FONTROOTDIR}" = "x"; then ++ FONTROOTDIR="${datadir}/fonts/X11" ++fi ++AC_SUBST(FONTROOTDIR) ++AC_MSG_RESULT([${FONTROOTDIR}]) + + dnl Uses --with-default-font-path if set, otherwise uses standard + dnl subdirectories of FONTROOTDIR. Some distros set the default font path to + dnl "catalogue:/etc/X11/fontpath.d,built-ins" +-DEFAULT_FONT_PATH="${FONTMISCDIR}/,${FONTTTFDIR}/,${FONTOTFDIR}/,${FONTTYPE1DIR}/,${FONT100DPIDIR}/,${FONT75DPIDIR}/" ++DEFAULT_FONT_PATH="${FONTROOTDIR}/misc,${FONTROOTDIR}/OTF,${FONTROOTDIR}/TTF,${FONTROOTDIR}/Type1,${FONTROOTDIR}/75dpi,${FONTROOTDIR}/100dpi" + case $host_os in + darwin*) DEFAULT_FONT_PATH="${DEFAULT_FONT_PATH},/Library/Fonts,/System/Library/Fonts" ;; + esac +-- +2.38.1 + diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index f676f0c..1b98ee3 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 9%{?gitdate:.%{gitdate}}%{?dist} +Release: 10%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -92,6 +92,12 @@ Patch5: 0001-autobind-GPUs-to-the-screen.patch # because the display-managers are not ready yet, do not upstream Patch6: 0001-Fedora-hack-Make-the-suid-root-wrapper-always-start-.patch +# Not sure anyone else cares about this so let's keep this Fedora-only for now +# Upstream PR for the meson.build equivalent is here, so we can drop this patch +# when we start building with meson. +# https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/1001` +Patch7: 0001-configure.ac-search-for-the-fontrootdir-ourselves.patch + # Backports from current stable "server-1.20-branch": # @@ -118,7 +124,6 @@ BuildRequires: automake autoconf libtool pkgconfig BuildRequires: xorg-x11-util-macros >= 1.17 BuildRequires: xorg-x11-proto-devel >= 7.7-10 -BuildRequires: xorg-x11-font-utils >= 7.2-11 BuildRequires: dbus-devel libepoxy-devel systemd-devel BuildRequires: xorg-x11-xtrans-devel >= 1.3.2 @@ -525,6 +530,10 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Wed Nov 23 2022 Peter Hutterer - 1.20.14-10 +- Drop dependency on xorg-x11-font-utils, it was only there for on + build-time variable that's always the same value anyway (#2145088) + * Tue Nov 8 2022 Olivier Fourdan - 1.20.14-9 - Fix CVE-2022-3550, CVE-2022-3551 From 75e6f92d0f54c035cfc105c43aeae53233f09c88 Mon Sep 17 00:00:00 2001 From: Peter Hutterer Date: Wed, 14 Dec 2022 11:53:02 +1000 Subject: [PATCH 19/74] CVE fix for: CVE-2022-4283, CVE-2022-46340, CVE-2022-46341, CVE-2022-46342, CVE-2022-46343, CVE-2022-46344 --- ...-GenericEvents-in-XTestSwapFakeInput.patch | 52 ++++++++++++ ...or-from-XI-property-changes-if-verif.patch | 41 ++++++++++ ...-truncation-in-length-check-of-ProcX.patch | 71 ++++++++++++++++ ...llow-passive-grabs-with-a-detail-255.patch | 82 +++++++++++++++++++ ...reen-saver-resource-when-replacing-i.patch | 48 +++++++++++ ...RTVideoNotify-when-turning-off-from-.patch | 74 +++++++++++++++++ ...dio_groups-pointer-to-NULL-after-fre.patch | 36 ++++++++ xorg-x11-server.spec | 21 ++++- 8 files changed, 424 insertions(+), 1 deletion(-) create mode 100644 0001-Xtest-disallow-GenericEvents-in-XTestSwapFakeInput.patch create mode 100644 0002-Xi-return-an-error-from-XI-property-changes-if-verif.patch create mode 100644 0003-Xi-avoid-integer-truncation-in-length-check-of-ProcX.patch create mode 100644 0004-Xi-disallow-passive-grabs-with-a-detail-255.patch create mode 100644 0005-Xext-free-the-screen-saver-resource-when-replacing-i.patch create mode 100644 0006-Xext-free-the-XvRTVideoNotify-when-turning-off-from-.patch create mode 100644 0007-xkb-reset-the-radio_groups-pointer-to-NULL-after-fre.patch diff --git a/0001-Xtest-disallow-GenericEvents-in-XTestSwapFakeInput.patch b/0001-Xtest-disallow-GenericEvents-in-XTestSwapFakeInput.patch new file mode 100644 index 0000000..017f247 --- /dev/null +++ b/0001-Xtest-disallow-GenericEvents-in-XTestSwapFakeInput.patch @@ -0,0 +1,52 @@ +From 8dba686dc277d6d262ad0c77b4632a5b276697ba Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Tue, 29 Nov 2022 12:55:45 +1000 +Subject: [PATCH xserver 1/7] Xtest: disallow GenericEvents in + XTestSwapFakeInput + +XTestSwapFakeInput assumes all events in this request are +sizeof(xEvent) and iterates through these in 32-byte increments. +However, a GenericEvent may be of arbitrary length longer than 32 bytes, +so any GenericEvent in this list would result in subsequent events to be +misparsed. + +Additional, the swapped event is written into a stack-allocated struct +xEvent (size 32 bytes). For any GenericEvent longer than 32 bytes, +swapping the event may thus smash the stack like an avocado on toast. + +Catch this case early and return BadValue for any GenericEvent. +Which is what would happen in unswapped setups anyway since XTest +doesn't support GenericEvent. + +CVE-2022-46340, ZDI-CAN 19265 + +This vulnerability was discovered by: +Jan-Niklas Sohn working with Trend Micro Zero Day Initiative + +Signed-off-by: Peter Hutterer +Acked-by: Olivier Fourdan +--- + Xext/xtest.c | 5 +++-- + 1 file changed, 3 insertions(+), 2 deletions(-) + +diff --git a/Xext/xtest.c b/Xext/xtest.c +index bf27eb590b..2985a4ce6e 100644 +--- a/Xext/xtest.c ++++ b/Xext/xtest.c +@@ -502,10 +502,11 @@ XTestSwapFakeInput(ClientPtr client, xReq * req) + + nev = ((req->length << 2) - sizeof(xReq)) / sizeof(xEvent); + for (ev = (xEvent *) &req[1]; --nev >= 0; ev++) { ++ int evtype = ev->u.u.type & 0x177; + /* Swap event */ +- proc = EventSwapVector[ev->u.u.type & 0177]; ++ proc = EventSwapVector[evtype]; + /* no swapping proc; invalid event type? */ +- if (!proc || proc == NotImplemented) { ++ if (!proc || proc == NotImplemented || evtype == GenericEvent) { + client->errorValue = ev->u.u.type; + return BadValue; + } +-- +2.38.1 + diff --git a/0002-Xi-return-an-error-from-XI-property-changes-if-verif.patch b/0002-Xi-return-an-error-from-XI-property-changes-if-verif.patch new file mode 100644 index 0000000..72bcadb --- /dev/null +++ b/0002-Xi-return-an-error-from-XI-property-changes-if-verif.patch @@ -0,0 +1,41 @@ +From c5ff57676698f19ed3a1402aef58a15552e32d27 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Tue, 29 Nov 2022 13:24:00 +1000 +Subject: [PATCH xserver 2/7] Xi: return an error from XI property changes if + verification failed + +Both ProcXChangeDeviceProperty and ProcXIChangeProperty checked the +property for validity but didn't actually return the potential error. + +Signed-off-by: Peter Hutterer +Acked-by: Olivier Fourdan +--- + Xi/xiproperty.c | 5 +++++ + 1 file changed, 5 insertions(+) + +diff --git a/Xi/xiproperty.c b/Xi/xiproperty.c +index a36f7d61df..68c362c628 100644 +--- a/Xi/xiproperty.c ++++ b/Xi/xiproperty.c +@@ -902,6 +902,8 @@ ProcXChangeDeviceProperty(ClientPtr client) + + rc = check_change_property(client, stuff->property, stuff->type, + stuff->format, stuff->mode, stuff->nUnits); ++ if (rc != Success) ++ return rc; + + len = stuff->nUnits; + if (len > (bytes_to_int32(0xffffffff - sizeof(xChangeDevicePropertyReq)))) +@@ -1141,6 +1143,9 @@ ProcXIChangeProperty(ClientPtr client) + + rc = check_change_property(client, stuff->property, stuff->type, + stuff->format, stuff->mode, stuff->num_items); ++ if (rc != Success) ++ return rc; ++ + len = stuff->num_items; + if (len > bytes_to_int32(0xffffffff - sizeof(xXIChangePropertyReq))) + return BadLength; +-- +2.38.1 + diff --git a/0003-Xi-avoid-integer-truncation-in-length-check-of-ProcX.patch b/0003-Xi-avoid-integer-truncation-in-length-check-of-ProcX.patch new file mode 100644 index 0000000..d3c6541 --- /dev/null +++ b/0003-Xi-avoid-integer-truncation-in-length-check-of-ProcX.patch @@ -0,0 +1,71 @@ +From f9c435822c852659e3926502829f1b13ce6efc37 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Tue, 29 Nov 2022 13:26:57 +1000 +Subject: [PATCH xserver 3/7] Xi: avoid integer truncation in length check of + ProcXIChangeProperty + +This fixes an OOB read and the resulting information disclosure. + +Length calculation for the request was clipped to a 32-bit integer. With +the correct stuff->num_items value the expected request size was +truncated, passing the REQUEST_FIXED_SIZE check. + +The server then proceeded with reading at least stuff->num_items bytes +(depending on stuff->format) from the request and stuffing whatever it +finds into the property. In the process it would also allocate at least +stuff->num_items bytes, i.e. 4GB. + +The same bug exists in ProcChangeProperty and ProcXChangeDeviceProperty, +so let's fix that too. + +CVE-2022-46344, ZDI-CAN 19405 + +This vulnerability was discovered by: +Jan-Niklas Sohn working with Trend Micro Zero Day Initiative + +Signed-off-by: Peter Hutterer +Acked-by: Olivier Fourdan +--- + Xi/xiproperty.c | 4 ++-- + dix/property.c | 3 ++- + 2 files changed, 4 insertions(+), 3 deletions(-) + +diff --git a/Xi/xiproperty.c b/Xi/xiproperty.c +index 68c362c628..066ba21fba 100644 +--- a/Xi/xiproperty.c ++++ b/Xi/xiproperty.c +@@ -890,7 +890,7 @@ ProcXChangeDeviceProperty(ClientPtr client) + REQUEST(xChangeDevicePropertyReq); + DeviceIntPtr dev; + unsigned long len; +- int totalSize; ++ uint64_t totalSize; + int rc; + + REQUEST_AT_LEAST_SIZE(xChangeDevicePropertyReq); +@@ -1130,7 +1130,7 @@ ProcXIChangeProperty(ClientPtr client) + { + int rc; + DeviceIntPtr dev; +- int totalSize; ++ uint64_t totalSize; + unsigned long len; + + REQUEST(xXIChangePropertyReq); +diff --git a/dix/property.c b/dix/property.c +index 94ef5a0ec0..acce94b2c6 100644 +--- a/dix/property.c ++++ b/dix/property.c +@@ -205,7 +205,8 @@ ProcChangeProperty(ClientPtr client) + WindowPtr pWin; + char format, mode; + unsigned long len; +- int sizeInBytes, totalSize, err; ++ int sizeInBytes, err; ++ uint64_t totalSize; + + REQUEST(xChangePropertyReq); + +-- +2.38.1 + diff --git a/0004-Xi-disallow-passive-grabs-with-a-detail-255.patch b/0004-Xi-disallow-passive-grabs-with-a-detail-255.patch new file mode 100644 index 0000000..5b189ea --- /dev/null +++ b/0004-Xi-disallow-passive-grabs-with-a-detail-255.patch @@ -0,0 +1,82 @@ +From 0dab0b527ac5c4fe0272ea679522bd87238a733b Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Tue, 29 Nov 2022 13:55:32 +1000 +Subject: [PATCH xserver 4/7] Xi: disallow passive grabs with a detail > 255 + +The XKB protocol effectively prevents us from ever using keycodes above +255. For buttons it's theoretically possible but realistically too niche +to worry about. For all other passive grabs, the detail must be zero +anyway. + +This fixes an OOB write: + +ProcXIPassiveUngrabDevice() calls DeletePassiveGrabFromList with a +temporary grab struct which contains tempGrab->detail.exact = stuff->detail. +For matching existing grabs, DeleteDetailFromMask is called with the +stuff->detail value. This function creates a new mask with the one bit +representing stuff->detail cleared. + +However, the array size for the new mask is 8 * sizeof(CARD32) bits, +thus any detail above 255 results in an OOB array write. + +CVE-2022-46341, ZDI-CAN 19381 + +This vulnerability was discovered by: +Jan-Niklas Sohn working with Trend Micro Zero Day Initiative + +Signed-off-by: Peter Hutterer +Acked-by: Olivier Fourdan +--- + Xi/xipassivegrab.c | 22 ++++++++++++++-------- + 1 file changed, 14 insertions(+), 8 deletions(-) + +diff --git a/Xi/xipassivegrab.c b/Xi/xipassivegrab.c +index 2769fb7c94..c9ac2f8553 100644 +--- a/Xi/xipassivegrab.c ++++ b/Xi/xipassivegrab.c +@@ -137,6 +137,12 @@ ProcXIPassiveGrabDevice(ClientPtr client) + return BadValue; + } + ++ /* XI2 allows 32-bit keycodes but thanks to XKB we can never ++ * implement this. Just return an error for all keycodes that ++ * cannot work anyway, same for buttons > 255. */ ++ if (stuff->detail > 255) ++ return XIAlreadyGrabbed; ++ + if (XICheckInvalidMaskBits(client, (unsigned char *) &stuff[1], + stuff->mask_len * 4) != Success) + return BadValue; +@@ -207,14 +213,8 @@ ProcXIPassiveGrabDevice(ClientPtr client) + ¶m, XI2, &mask); + break; + case XIGrabtypeKeycode: +- /* XI2 allows 32-bit keycodes but thanks to XKB we can never +- * implement this. Just return an error for all keycodes that +- * cannot work anyway */ +- if (stuff->detail > 255) +- status = XIAlreadyGrabbed; +- else +- status = GrabKey(client, dev, mod_dev, stuff->detail, +- ¶m, XI2, &mask); ++ status = GrabKey(client, dev, mod_dev, stuff->detail, ++ ¶m, XI2, &mask); + break; + case XIGrabtypeEnter: + case XIGrabtypeFocusIn: +@@ -334,6 +334,12 @@ ProcXIPassiveUngrabDevice(ClientPtr client) + return BadValue; + } + ++ /* We don't allow passive grabs for details > 255 anyway */ ++ if (stuff->detail > 255) { ++ client->errorValue = stuff->detail; ++ return BadValue; ++ } ++ + rc = dixLookupWindow(&win, stuff->grab_window, client, DixSetAttrAccess); + if (rc != Success) + return rc; +-- +2.38.1 + diff --git a/0005-Xext-free-the-screen-saver-resource-when-replacing-i.patch b/0005-Xext-free-the-screen-saver-resource-when-replacing-i.patch new file mode 100644 index 0000000..dc2a9d9 --- /dev/null +++ b/0005-Xext-free-the-screen-saver-resource-when-replacing-i.patch @@ -0,0 +1,48 @@ +From 94f6fe99d87cf6ba0adadd95c595158c345b7d29 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Tue, 29 Nov 2022 14:53:07 +1000 +Subject: [PATCH xserver 5/7] Xext: free the screen saver resource when + replacing it + +This fixes a use-after-free bug: + +When a client first calls ScreenSaverSetAttributes(), a struct +ScreenSaverAttrRec is allocated and added to the client's +resources. + +When the same client calls ScreenSaverSetAttributes() again, a new +struct ScreenSaverAttrRec is allocated, replacing the old struct. The +old struct was freed but not removed from the clients resources. + +Later, when the client is destroyed the resource system invokes +ScreenSaverFreeAttr and attempts to clean up the already freed struct. + +Fix this by letting the resource system free the old attrs instead. + +CVE-2022-46343, ZDI-CAN 19404 + +This vulnerability was discovered by: +Jan-Niklas Sohn working with Trend Micro Zero Day Initiative + +Signed-off-by: Peter Hutterer +Acked-by: Olivier Fourdan +--- + Xext/saver.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/Xext/saver.c b/Xext/saver.c +index f813ba08d1..fd6153c313 100644 +--- a/Xext/saver.c ++++ b/Xext/saver.c +@@ -1051,7 +1051,7 @@ ScreenSaverSetAttributes(ClientPtr client) + pVlist++; + } + if (pPriv->attr) +- FreeScreenAttr(pPriv->attr); ++ FreeResource(pPriv->attr->resource, AttrType); + pPriv->attr = pAttr; + pAttr->resource = FakeClientID(client->index); + if (!AddResource(pAttr->resource, AttrType, (void *) pAttr)) +-- +2.38.1 + diff --git a/0006-Xext-free-the-XvRTVideoNotify-when-turning-off-from-.patch b/0006-Xext-free-the-XvRTVideoNotify-when-turning-off-from-.patch new file mode 100644 index 0000000..ba8b8fa --- /dev/null +++ b/0006-Xext-free-the-XvRTVideoNotify-when-turning-off-from-.patch @@ -0,0 +1,74 @@ +From a42635ee3c01f71a49052d83a372933504c9db04 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Wed, 30 Nov 2022 11:20:40 +1000 +Subject: [PATCH xserver 6/7] Xext: free the XvRTVideoNotify when turning off + from the same client + +This fixes a use-after-free bug: + +When a client first calls XvdiSelectVideoNotify() on a drawable with a +TRUE onoff argument, a struct XvVideoNotifyRec is allocated. This struct +is added twice to the resources: + - as the drawable's XvRTVideoNotifyList. This happens only once per + drawable, subsequent calls append to this list. + - as the client's XvRTVideoNotify. This happens for every client. + +The struct keeps the ClientPtr around once it has been added for a +client. The idea, presumably, is that if the client disconnects we can remove +all structs from the drawable's list that match the client (by resetting +the ClientPtr to NULL), but if the drawable is destroyed we can remove +and free the whole list. + +However, if the same client then calls XvdiSelectVideoNotify() on the +same drawable with a FALSE onoff argument, only the ClientPtr on the +existing struct was set to NULL. The struct itself remained in the +client's resources. + +If the drawable is now destroyed, the resource system invokes +XvdiDestroyVideoNotifyList which frees the whole list for this drawable +- including our struct. This function however does not free the resource +for the client since our ClientPtr is NULL. + +Later, when the client is destroyed and the resource system invokes +XvdiDestroyVideoNotify, we unconditionally set the ClientPtr to NULL. On +a struct that has been freed previously. This is generally frowned upon. + +Fix this by calling FreeResource() on the second call instead of merely +setting the ClientPtr to NULL. This removes the struct from the client +resources (but not from the list), ensuring that it won't be accessed +again when the client quits. + +Note that the assignment tpn->client = NULL; is superfluous since the +XvdiDestroyVideoNotify function will do this anyway. But it's left for +clarity and to match a similar invocation in XvdiSelectPortNotify. + +CVE-2022-46342, ZDI-CAN 19400 + +This vulnerability was discovered by: +Jan-Niklas Sohn working with Trend Micro Zero Day Initiative + +Signed-off-by: Peter Hutterer +Acked-by: Olivier Fourdan +--- + Xext/xvmain.c | 4 +++- + 1 file changed, 3 insertions(+), 1 deletion(-) + +diff --git a/Xext/xvmain.c b/Xext/xvmain.c +index f627471938..2a08f8744a 100644 +--- a/Xext/xvmain.c ++++ b/Xext/xvmain.c +@@ -811,8 +811,10 @@ XvdiSelectVideoNotify(ClientPtr client, DrawablePtr pDraw, BOOL onoff) + tpn = pn; + while (tpn) { + if (tpn->client == client) { +- if (!onoff) ++ if (!onoff) { + tpn->client = NULL; ++ FreeResource(tpn->id, XvRTVideoNotify); ++ } + return Success; + } + if (!tpn->client) +-- +2.38.1 + diff --git a/0007-xkb-reset-the-radio_groups-pointer-to-NULL-after-fre.patch b/0007-xkb-reset-the-radio_groups-pointer-to-NULL-after-fre.patch new file mode 100644 index 0000000..c6b2352 --- /dev/null +++ b/0007-xkb-reset-the-radio_groups-pointer-to-NULL-after-fre.patch @@ -0,0 +1,36 @@ +From 774260dbae1fa505cd2848c786baed9a8db5179d Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Mon, 5 Dec 2022 15:55:54 +1000 +Subject: [PATCH xserver 7/7] xkb: reset the radio_groups pointer to NULL after + freeing it + +Unlike other elements of the keymap, this pointer was freed but not +reset. On a subsequent XkbGetKbdByName request, the server may access +already freed memory. + +CVE-2022-46283, ZDI-CAN-19530 + +This vulnerability was discovered by: +Jan-Niklas Sohn working with Trend Micro Zero Day Initiative + +Signed-off-by: Peter Hutterer +Acked-by: Olivier Fourdan +--- + xkb/xkbUtils.c | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/xkb/xkbUtils.c b/xkb/xkbUtils.c +index dd089c2046..3f5791a183 100644 +--- a/xkb/xkbUtils.c ++++ b/xkb/xkbUtils.c +@@ -1326,6 +1326,7 @@ _XkbCopyNames(XkbDescPtr src, XkbDescPtr dst) + } + else { + free(dst->names->radio_groups); ++ dst->names->radio_groups = NULL; + } + dst->names->num_rg = src->names->num_rg; + +-- +2.38.1 + diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 1b98ee3..5285f9d 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 10%{?gitdate:.%{gitdate}}%{?dist} +Release: 11%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -117,6 +117,21 @@ Patch113: 0001-xkb-proof-GetCountedString-against-request-length-at.patch # CVE-2022-3551 Patch114: 0001-xkb-fix-some-possible-memleaks-in-XkbGetKbdByName.patch +# CVE-2022-46340 +Patch115: 0001-Xtest-disallow-GenericEvents-in-XTestSwapFakeInput.patch +# related to CVE-2022-46344 +Patch116: 0002-Xi-return-an-error-from-XI-property-changes-if-verif.patch +# CVE-2022-46344 +Patch117: 0003-Xi-avoid-integer-truncation-in-length-check-of-ProcX.patch +# CVE-2022-46341 +Patch118: 0004-Xi-disallow-passive-grabs-with-a-detail-255.patch +# CVE-2022-46343 +Patch119: 0005-Xext-free-the-screen-saver-resource-when-replacing-i.patch +# CVE-2022-46342 +Patch120: 0006-Xext-free-the-XvRTVideoNotify-when-turning-off-from-.patch +# CVE-2022-46283 +Patch121: 0007-xkb-reset-the-radio_groups-pointer-to-NULL-after-fre.patch + BuildRequires: make BuildRequires: systemtap-sdt-devel BuildRequires: git-core @@ -530,6 +545,10 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Wed Dec 14 2022 Peter Hutterer 1.20.14-11 +- CVE fix for: CVE-2022-4283, CVE-2022-46340, CVE-2022-46341, + CVE-2022-46342, CVE-2022-46343, CVE-2022-46344 + * Wed Nov 23 2022 Peter Hutterer - 1.20.14-10 - Drop dependency on xorg-x11-font-utils, it was only there for on build-time variable that's always the same value anyway (#2145088) From fc0c7be4e314918120e199284ed0305862761cab Mon Sep 17 00:00:00 2001 From: Peter Hutterer Date: Mon, 19 Dec 2022 10:18:48 +1000 Subject: [PATCH 20/74] Fix buggy patch to CVE-2022-46340 --- ...-event-type-mask-in-XTestSwapFakeInp.patch | 35 +++++++++++++++++++ xorg-x11-server.spec | 7 +++- 2 files changed, 41 insertions(+), 1 deletion(-) create mode 100644 0008-Xext-fix-invalid-event-type-mask-in-XTestSwapFakeInp.patch diff --git a/0008-Xext-fix-invalid-event-type-mask-in-XTestSwapFakeInp.patch b/0008-Xext-fix-invalid-event-type-mask-in-XTestSwapFakeInp.patch new file mode 100644 index 0000000..c84d387 --- /dev/null +++ b/0008-Xext-fix-invalid-event-type-mask-in-XTestSwapFakeInp.patch @@ -0,0 +1,35 @@ +From bb1711b7fba42f2a0c7d1c09beee241a1b2bcc30 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Mon, 19 Dec 2022 10:06:45 +1000 +Subject: [PATCH xserver] Xext: fix invalid event type mask in + XTestSwapFakeInput + +In commit b320ca0 the mask was inadvertently changed from octal 0177 to +hexadecimal 0x177. + +Fixes commit b320ca0ffe4c0c872eeb3a93d9bde21f765c7c63 + Xtest: disallow GenericEvents in XTestSwapFakeInput + +Found by Stuart Cassoff + +Signed-off-by: Peter Hutterer +--- + Xext/xtest.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/Xext/xtest.c b/Xext/xtest.c +index 2985a4ce6e..dde5c4cf9d 100644 +--- a/Xext/xtest.c ++++ b/Xext/xtest.c +@@ -502,7 +502,7 @@ XTestSwapFakeInput(ClientPtr client, xReq * req) + + nev = ((req->length << 2) - sizeof(xReq)) / sizeof(xEvent); + for (ev = (xEvent *) &req[1]; --nev >= 0; ev++) { +- int evtype = ev->u.u.type & 0x177; ++ int evtype = ev->u.u.type & 0177; + /* Swap event */ + proc = EventSwapVector[evtype]; + /* no swapping proc; invalid event type? */ +-- +2.38.1 + diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 5285f9d..2184f31 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 11%{?gitdate:.%{gitdate}}%{?dist} +Release: 12%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -131,6 +131,8 @@ Patch119: 0005-Xext-free-the-screen-saver-resource-when-replacing-i.patch Patch120: 0006-Xext-free-the-XvRTVideoNotify-when-turning-off-from-.patch # CVE-2022-46283 Patch121: 0007-xkb-reset-the-radio_groups-pointer-to-NULL-after-fre.patch +# Fix for buggy patch to CVE-2022-46340 +Patch122: 0008-Xext-fix-invalid-event-type-mask-in-XTestSwapFakeInp.patch BuildRequires: make BuildRequires: systemtap-sdt-devel @@ -545,6 +547,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Mon Dec 19 2022 Peter Hutterer - 1.20.14-12 +- Fix buggy patch to CVE-2022-46340 + * Wed Dec 14 2022 Peter Hutterer 1.20.14-11 - CVE fix for: CVE-2022-4283, CVE-2022-46340, CVE-2022-46341, CVE-2022-46342, CVE-2022-46343, CVE-2022-46344 From 140953a817b9139307553a921b9f9a7f35c8dd1b Mon Sep 17 00:00:00 2001 From: Olivier Fourdan Date: Wed, 11 Jan 2023 16:41:24 +0100 Subject: [PATCH 21/74] Rename value field from bool to boolean Rename boolean config value field from bool to boolean to fix drivers build failures due to a conflict with C++ and stdbool.h --- ...n-config-value-field-from-bool-to-bo.patch | 154 ++++++++++++++++++ xorg-x11-server.spec | 7 +- 2 files changed, 160 insertions(+), 1 deletion(-) create mode 100644 0001-hw-Rename-boolean-config-value-field-from-bool-to-bo.patch diff --git a/0001-hw-Rename-boolean-config-value-field-from-bool-to-bo.patch b/0001-hw-Rename-boolean-config-value-field-from-bool-to-bo.patch new file mode 100644 index 0000000..52ea4d0 --- /dev/null +++ b/0001-hw-Rename-boolean-config-value-field-from-bool-to-bo.patch @@ -0,0 +1,154 @@ +From 454b3a826edb5fc6d0fea3a9cfd1a5e8fc568747 Mon Sep 17 00:00:00 2001 +From: Adam Jackson +Date: Mon, 22 Jul 2019 13:51:06 -0400 +Subject: [PATCH xserver] hw: Rename boolean config value field from bool to + boolean + +"bool" conflicts with C++ (meh) and stdbool.h (ngh alright fine). This +is a driver-visible change and will likely break the build for mach64, +but it can be fixed by simply using xf86ReturnOptValBool like every +other driver. + +Signed-off-by: Adam Jackson +--- + hw/xfree86/common/xf86Opt.h | 2 +- + hw/xfree86/common/xf86Option.c | 10 +++++----- + hw/xwin/winconfig.c | 22 +++++++++++----------- + hw/xwin/winconfig.h | 2 +- + 4 files changed, 18 insertions(+), 18 deletions(-) + +diff --git a/hw/xfree86/common/xf86Opt.h b/hw/xfree86/common/xf86Opt.h +index 3be2a0fc7..3046fbd41 100644 +--- a/hw/xfree86/common/xf86Opt.h ++++ b/hw/xfree86/common/xf86Opt.h +@@ -41,7 +41,7 @@ typedef union { + unsigned long num; + const char *str; + double realnum; +- Bool bool; ++ Bool boolean; + OptFrequency freq; + } ValueUnion; + +diff --git a/hw/xfree86/common/xf86Option.c b/hw/xfree86/common/xf86Option.c +index 06973bca3..ca538cc57 100644 +--- a/hw/xfree86/common/xf86Option.c ++++ b/hw/xfree86/common/xf86Option.c +@@ -213,7 +213,7 @@ LookupBoolOption(XF86OptionPtr optlist, const char *name, int deflt, + o.name = name; + o.type = OPTV_BOOLEAN; + if (ParseOptionValue(-1, optlist, &o, markUsed)) +- deflt = o.value.bool; ++ deflt = o.value.boolean; + return deflt; + } + +@@ -474,7 +474,7 @@ xf86ShowUnusedOptions(int scrnIndex, XF86OptionPtr opt) + static Bool + GetBoolValue(OptionInfoPtr p, const char *s) + { +- return xf86getBoolValue(&p->value.bool, s); ++ return xf86getBoolValue(&p->value.boolean, s); + } + + static Bool +@@ -678,7 +678,7 @@ ParseOptionValue(int scrnIndex, XF86OptionPtr options, OptionInfoPtr p, + if (markUsed) + xf86MarkOptionUsedByName(options, newn); + if (GetBoolValue(&opt, s)) { +- p->value.bool = !opt.value.bool; ++ p->value.boolean = !opt.value.boolean; + p->found = TRUE; + } + else { +@@ -869,7 +869,7 @@ xf86GetOptValBool(const OptionInfoRec * table, int token, Bool *value) + + p = xf86TokenToOptinfo(table, token); + if (p && p->found) { +- *value = p->value.bool; ++ *value = p->value.boolean; + return TRUE; + } + else +@@ -883,7 +883,7 @@ xf86ReturnOptValBool(const OptionInfoRec * table, int token, Bool def) + + p = xf86TokenToOptinfo(table, token); + if (p && p->found) { +- return p->value.bool; ++ return p->value.boolean; + } + else + return def; +diff --git a/hw/xwin/winconfig.c b/hw/xwin/winconfig.c +index 31894d2fb..646d69006 100644 +--- a/hw/xwin/winconfig.c ++++ b/hw/xwin/winconfig.c +@@ -623,7 +623,7 @@ winSetBoolOption(void *optlist, const char *name, int deflt) + o.name = name; + o.type = OPTV_BOOLEAN; + if (ParseOptionValue(-1, optlist, &o)) +- deflt = o.value.bool; ++ deflt = o.value.boolean; + return deflt; + } + +@@ -918,7 +918,7 @@ ParseOptionValue(int scrnIndex, void *options, OptionInfoPtr p) + } + if ((s = winFindOptionValue(options, newn)) != NULL) { + if (GetBoolValue(&opt, s)) { +- p->value.bool = !opt.value.bool; ++ p->value.boolean = !opt.value.boolean; + p->found = TRUE; + } + else { +@@ -968,25 +968,25 @@ static Bool + GetBoolValue(OptionInfoPtr p, const char *s) + { + if (*s == 0) { +- p->value.bool = TRUE; ++ p->value.boolean = TRUE; + } + else { + if (winNameCompare(s, "1") == 0) +- p->value.bool = TRUE; ++ p->value.boolean = TRUE; + else if (winNameCompare(s, "on") == 0) +- p->value.bool = TRUE; ++ p->value.boolean = TRUE; + else if (winNameCompare(s, "true") == 0) +- p->value.bool = TRUE; ++ p->value.boolean = TRUE; + else if (winNameCompare(s, "yes") == 0) +- p->value.bool = TRUE; ++ p->value.boolean = TRUE; + else if (winNameCompare(s, "0") == 0) +- p->value.bool = FALSE; ++ p->value.boolean = FALSE; + else if (winNameCompare(s, "off") == 0) +- p->value.bool = FALSE; ++ p->value.boolean = FALSE; + else if (winNameCompare(s, "false") == 0) +- p->value.bool = FALSE; ++ p->value.boolean = FALSE; + else if (winNameCompare(s, "no") == 0) +- p->value.bool = FALSE; ++ p->value.boolean = FALSE; + } + return TRUE; + } +diff --git a/hw/xwin/winconfig.h b/hw/xwin/winconfig.h +index f079368c7..bd1f59650 100644 +--- a/hw/xwin/winconfig.h ++++ b/hw/xwin/winconfig.h +@@ -199,7 +199,7 @@ typedef union { + unsigned long num; + char *str; + double realnum; +- Bool bool; ++ Bool boolean; + OptFrequency freq; + } ValueUnion; + +-- +2.39.0 + diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 2184f31..a79dac2 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 12%{?gitdate:.%{gitdate}}%{?dist} +Release: 13%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -106,6 +106,7 @@ Patch100: 0001-present-Check-for-NULL-to-prevent-crash.patch Patch101: 0001-render-Fix-build-with-gcc-12.patch Patch102: 0001-xf86-Accept-devices-with-the-simpledrm-driver.patch Patch103: 0001-Don-t-hardcode-fps-for-fake-screen.patch +Patch104: 0001-hw-Rename-boolean-config-value-field-from-bool-to-bo.patch # CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070 Patch110: 0001-xkb-switch-to-array-index-loops-to-moving-pointers.patch @@ -547,6 +548,10 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Wed Jan 11 2023 Olivier Fourdan - 1.20.14-13 +- Rename boolean config value field from bool to boolean to fix drivers + build failures due to a conflict with C++ and stdbool.h + * Mon Dec 19 2022 Peter Hutterer - 1.20.14-12 - Fix buggy patch to CVE-2022-46340 From e6bf129b81251bcd2a6e2f8e5c77a8d238a043bf Mon Sep 17 00:00:00 2001 From: Peter Hutterer Date: Fri, 13 Jan 2023 15:23:38 +1000 Subject: [PATCH 22/74] Disallow byte-swapped clients (#2159489) --- ...llow-byte-swapped-clients-by-default.patch | 272 ++++++++++++++++++ xorg-x11-server.spec | 11 +- 2 files changed, 282 insertions(+), 1 deletion(-) create mode 100644 0001-Disallow-byte-swapped-clients-by-default.patch diff --git a/0001-Disallow-byte-swapped-clients-by-default.patch b/0001-Disallow-byte-swapped-clients-by-default.patch new file mode 100644 index 0000000..2cbf798 --- /dev/null +++ b/0001-Disallow-byte-swapped-clients-by-default.patch @@ -0,0 +1,272 @@ +From 73d6e888c6058b28a0e87ab65aa4172b17d8327d Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Mon, 19 Dec 2022 10:34:29 +1000 +Subject: [PATCH xserver] Fix some indentation issues + +Signed-off-by: Peter Hutterer +--- + dix/dispatch.c | 22 +++++++++++----------- + 1 file changed, 11 insertions(+), 11 deletions(-) + +diff --git a/dix/dispatch.c b/dix/dispatch.c +index 210df75c63..e38a8fecaa 100644 +--- a/dix/dispatch.c ++++ b/dix/dispatch.c +@@ -492,10 +492,10 @@ Dispatch(void) + if (!WaitForSomething(clients_are_ready())) + continue; + +- /***************** +- * Handle events in round robin fashion, doing input between +- * each round +- *****************/ ++ /***************** ++ * Handle events in round robin fashion, doing input between ++ * each round ++ *****************/ + + if (!dispatchException && clients_are_ready()) { + client = SmartScheduleClient(); +@@ -3657,11 +3657,11 @@ ProcInitialConnection(ClientPtr client) + prefix = (xConnClientPrefix *) ((char *)stuff + sz_xReq); + order = prefix->byteOrder; + if (order != 'l' && order != 'B' && order != 'r' && order != 'R') +- return client->noClientException = -1; ++ return client->noClientException = -1; + if (((*(char *) &whichbyte) && (order == 'B' || order == 'R')) || +- (!(*(char *) &whichbyte) && (order == 'l' || order == 'r'))) { +- client->swapped = TRUE; +- SwapConnClientPrefix(prefix); ++ (!(*(char *) &whichbyte) && (order == 'l' || order == 'r'))) { ++ client->swapped = TRUE; ++ SwapConnClientPrefix(prefix); + } + stuff->reqType = 2; + stuff->length += bytes_to_int32(prefix->nbytesAuthProto) + +@@ -3670,7 +3670,7 @@ ProcInitialConnection(ClientPtr client) + swaps(&stuff->length); + } + if (order == 'r' || order == 'R') { +- client->local = FALSE; ++ client->local = FALSE; + } + ResetCurrentRequest(client); + return Success; +@@ -3781,8 +3781,8 @@ ProcEstablishConnection(ClientPtr client) + auth_string = auth_proto + pad_to_int32(prefix->nbytesAuthProto); + + if ((client->req_len << 2) != sz_xReq + sz_xConnClientPrefix + +- pad_to_int32(prefix->nbytesAuthProto) + +- pad_to_int32(prefix->nbytesAuthString)) ++ pad_to_int32(prefix->nbytesAuthProto) + ++ pad_to_int32(prefix->nbytesAuthString)) + reason = "Bad length"; + else if ((prefix->majorVersion != X_PROTOCOL) || + (prefix->minorVersion != X_PROTOCOL_REVISION)) +-- +2.39.0 + +From f69280ddcdd3115ee4717f22e85e0f43569b60dd Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Tue, 20 Dec 2022 11:40:16 +1000 +Subject: [PATCH xserver] dix: localize two variables + +Signed-off-by: Peter Hutterer +--- + dix/dispatch.c | 8 ++++---- + 1 file changed, 4 insertions(+), 4 deletions(-) + +diff --git a/dix/dispatch.c b/dix/dispatch.c +index c651c3d887..92be773e6c 100644 +--- a/dix/dispatch.c ++++ b/dix/dispatch.c +@@ -3766,14 +3766,11 @@ int + ProcEstablishConnection(ClientPtr client) + { + const char *reason; +- char *auth_proto, *auth_string; + xConnClientPrefix *prefix; + + REQUEST(xReq); + + prefix = (xConnClientPrefix *) ((char *) stuff + sz_xReq); +- auth_proto = (char *) prefix + sz_xConnClientPrefix; +- auth_string = auth_proto + pad_to_int32(prefix->nbytesAuthProto); + + if ((client->req_len << 2) != sz_xReq + sz_xConnClientPrefix + + pad_to_int32(prefix->nbytesAuthProto) + +@@ -3782,12 +3779,15 @@ ProcEstablishConnection(ClientPtr client) + else if ((prefix->majorVersion != X_PROTOCOL) || + (prefix->minorVersion != X_PROTOCOL_REVISION)) + reason = "Protocol version mismatch"; +- else ++ else { ++ char *auth_proto = (char *) prefix + sz_xConnClientPrefix; ++ char *auth_string = auth_proto + pad_to_int32(prefix->nbytesAuthProto); + reason = ClientAuthorized(client, + (unsigned short) prefix->nbytesAuthProto, + auth_proto, + (unsigned short) prefix->nbytesAuthString, + auth_string); ++ } + + return (SendConnSetup(client, reason)); + } +-- +2.39.0 + +From 412777664a20dd3561b936c02c96571a756fe9b2 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Tue, 20 Dec 2022 10:42:03 +1000 +Subject: [PATCH xserver] Disallow byte-swapped clients by default + +The X server swapping code is a huge attack surface, much of this code +is untested and prone to security issues. The use-case of byte-swapped +clients is very niche, so let's disable this by default and allow it +only when the respective config option or commandline flag is given. + +For Xorg, this adds the ServerFlag "AllowByteSwappedClients" "on". +For all DDX, this adds the commandline options +byteswappedclients and +-byteswappedclients to enable or disable, respectively. + +Fixes #1201 + +https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/1029 + +Signed-off-by: Peter Hutterer +--- + dix/dispatch.c | 4 +++- + hw/xfree86/common/xf86Config.c | 8 ++++++++ + hw/xfree86/man/xorg.conf.man | 2 ++ + hw/xwayland/xwayland.pc.in | 1 + + include/opaque.h | 2 ++ + man/Xserver.man | 6 ++++++ + os/utils.c | 9 +++++++++ + 7 files changed, 31 insertions(+), 1 deletion(-) + +diff --git a/dix/dispatch.c b/dix/dispatch.c +index 92be773e6c..9c26753a96 100644 +--- a/dix/dispatch.c ++++ b/dix/dispatch.c +@@ -3772,7 +3772,9 @@ ProcEstablishConnection(ClientPtr client) + + prefix = (xConnClientPrefix *) ((char *) stuff + sz_xReq); + +- if ((client->req_len << 2) != sz_xReq + sz_xConnClientPrefix + ++ if (client->swapped && !AllowByteSwappedClients) { ++ reason = "Prohibited client endianess, see the Xserver man page "; ++ } else if ((client->req_len << 2) != sz_xReq + sz_xConnClientPrefix + + pad_to_int32(prefix->nbytesAuthProto) + + pad_to_int32(prefix->nbytesAuthString)) + reason = "Bad length"; +diff --git a/hw/xfree86/common/xf86Config.c b/hw/xfree86/common/xf86Config.c +index 5d814c1485..41acb25aa2 100644 +--- a/hw/xfree86/common/xf86Config.c ++++ b/hw/xfree86/common/xf86Config.c +@@ -646,6 +646,7 @@ typedef enum { + FLAG_MAX_CLIENTS, + FLAG_IGLX, + FLAG_DEBUG, ++ FLAG_ALLOW_BYTE_SWAPPED_CLIENTS, + } FlagValues; + + /** +@@ -705,6 +706,8 @@ static OptionInfoRec FlagOptions[] = { + {0}, FALSE}, + {FLAG_DEBUG, "Debug", OPTV_STRING, + {0}, FALSE}, ++ {FLAG_ALLOW_BYTE_SWAPPED_CLIENTS, "AllowByteSwappedClients", OPTV_BOOLEAN, ++ {0}, FALSE}, + {-1, NULL, OPTV_NONE, + {0}, FALSE}, + }; +@@ -746,6 +749,11 @@ configServerFlags(XF86ConfFlagsPtr flagsconf, XF86OptionPtr layoutopts) + xf86Msg(X_CONFIG, "Ignoring ABI Version\n"); + } + ++ xf86GetOptValBool(FlagOptions, FLAG_ALLOW_BYTE_SWAPPED_CLIENTS, &AllowByteSwappedClients); ++ if (AllowByteSwappedClients) { ++ xf86Msg(X_CONFIG, "Allowing byte-swapped clients\n"); ++ } ++ + if (xf86IsOptionSet(FlagOptions, FLAG_AUTO_ADD_DEVICES)) { + xf86GetOptValBool(FlagOptions, FLAG_AUTO_ADD_DEVICES, + &xf86Info.autoAddDevices); +diff --git a/hw/xfree86/man/xorg.conf.man b/hw/xfree86/man/xorg.conf.man +index 01b47247ee..d057f26ecd 100644 +--- a/hw/xfree86/man/xorg.conf.man ++++ b/hw/xfree86/man/xorg.conf.man +@@ -677,6 +677,8 @@ Possible values are + or + .BR sync . + Unset by default. ++.BI "Option \*qAllowByteSwappedClients\*q \*q" boolean \*q ++Allow clients with a different byte-order than the server. Disabled by default. + .SH "MODULE SECTION" + The + .B Module +diff --git a/include/opaque.h b/include/opaque.h +index 256261c2ad..398d4b4e51 100644 +--- a/include/opaque.h ++++ b/include/opaque.h +@@ -74,4 +74,6 @@ extern _X_EXPORT Bool bgNoneRoot; + extern _X_EXPORT Bool CoreDump; + extern _X_EXPORT Bool NoListenAll; + ++extern _X_EXPORT Bool AllowByteSwappedClients; ++ + #endif /* OPAQUE_H */ +diff --git a/man/Xserver.man b/man/Xserver.man +index 764bd1d907..e7adf9eb35 100644 +--- a/man/Xserver.man ++++ b/man/Xserver.man +@@ -114,6 +114,12 @@ pattern. This is the default unless -retro or -wr is specified. + .B \-bs + disables backing store support on all screens. + .TP 8 ++.B \+byteswappedclients ++Allow connections from clients with an endianess different to that of the server. ++.TP 8 ++.B \-byteswappedclients ++Prohibit connections from clients with an endianess different to that of the server. ++.TP 8 + .B \-c + turns off key-click. + .TP 8 +diff --git a/os/utils.c b/os/utils.c +index fe94912f34..405bf7d8b4 100644 +--- a/os/utils.c ++++ b/os/utils.c +@@ -189,6 +189,8 @@ Bool CoreDump; + + Bool enableIndirectGLX = FALSE; + ++Bool AllowByteSwappedClients = FALSE; ++ + #ifdef PANORAMIX + Bool PanoramiXExtensionDisabledHack = FALSE; + #endif +@@ -523,6 +525,8 @@ UseMsg(void) + ErrorF("-br create root window with black background\n"); + ErrorF("+bs enable any backing store support\n"); + ErrorF("-bs disable any backing store support\n"); ++ ErrorF("+byteswappedclients Allow clients with endianess different to that of the server\n"); ++ ErrorF("-byteswappedclients Prohibit clients with endianess different to that of the server\n"); + ErrorF("-c turns off key-click\n"); + ErrorF("c # key-click volume (0-100)\n"); + ErrorF("-cc int default color visual class\n"); +@@ -720,6 +724,11 @@ ProcessCommandLine(int argc, char *argv[]) + else + UseMsg(); + } ++ else if (strcmp(argv[i], "-byteswappedclients") == 0) { ++ AllowByteSwappedClients = FALSE; ++ } else if (strcmp(argv[i], "+byteswappedclients") == 0) { ++ AllowByteSwappedClients = TRUE; ++ } + else if (strcmp(argv[i], "-br") == 0); /* default */ + else if (strcmp(argv[i], "+bs") == 0) + enableBackingStore = TRUE; +-- +2.39.0 + diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index a79dac2..3fd8caf 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 13%{?gitdate:.%{gitdate}}%{?dist} +Release: 14%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -135,6 +135,12 @@ Patch121: 0007-xkb-reset-the-radio_groups-pointer-to-NULL-after-fre.patch # Fix for buggy patch to CVE-2022-46340 Patch122: 0008-Xext-fix-invalid-event-type-mask-in-XTestSwapFakeInp.patch +# Only on F38 and later +%if 0%{fedora} >= 38 +# Upstream commits 73d6e88, f69280dd and 4127776, minus the xwayland.pc.in change +Patch200: 0001-Disallow-byte-swapped-clients-by-default.patch +%endif + BuildRequires: make BuildRequires: systemtap-sdt-devel BuildRequires: git-core @@ -548,6 +554,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Fri Jan 13 2023 Peter Hutterer - 1.20.14-14 +- Disallow byte-swapped clients (#2159489) + * Wed Jan 11 2023 Olivier Fourdan - 1.20.14-13 - Rename boolean config value field from bool to boolean to fix drivers build failures due to a conflict with C++ and stdbool.h From 6c12217df8fda831add4b16f1b1a203973c71bf8 Mon Sep 17 00:00:00 2001 From: Leif Liddy Date: Thu, 12 Jan 2023 11:57:17 +0100 Subject: [PATCH 23/74] resolve Xorg server DCP display issue (#2152414) Xorg server does not correctly select the DCP for the display without a quirk --- 0001-add-a-quirk-for-apple-silicon.patch | 30 +++++++++++++++++++ 10-quirks.conf | 38 ------------------------ xorg-x11-server.spec | 12 ++++---- 3 files changed, 36 insertions(+), 44 deletions(-) create mode 100644 0001-add-a-quirk-for-apple-silicon.patch delete mode 100644 10-quirks.conf diff --git a/0001-add-a-quirk-for-apple-silicon.patch b/0001-add-a-quirk-for-apple-silicon.patch new file mode 100644 index 0000000..17c40e5 --- /dev/null +++ b/0001-add-a-quirk-for-apple-silicon.patch @@ -0,0 +1,30 @@ +commit 39934a656a44722d16a80bf4db411c53e2d67b38 (HEAD -> master, origin/master, origin/HEAD) +Author: Eric Curtin +Date: Fri Dec 16 11:10:12 2022 +0000 + + config: add a quirk for Apple Silicon appledrm + + Xorg server does not correctly select the DCP for the display without a + quirk on Apple Silicon. + + Signed-off-by: Eric Curtin + Suggested-by: Hector Martin + +diff --git a/config/10-quirks.conf b/config/10-quirks.conf +index 47907d82d..54dd908a7 100644 +--- a/config/10-quirks.conf ++++ b/config/10-quirks.conf +@@ -36,3 +36,13 @@ Section "InputClass" + MatchDriver "evdev" + Option "TypeName" "MOUSE" + EndSection ++ ++# https://bugzilla.redhat.com/show_bug.cgi?id=2152414 ++# Xorg server does not correctly select the DCP for the display without ++# a quirk on Apple Silicon ++Section "OutputClass" ++ Identifier "appledrm" ++ MatchDriver "apple" ++ Driver "modesetting" ++ Option "PrimaryGPU" "true" ++EndSection diff --git a/10-quirks.conf b/10-quirks.conf deleted file mode 100644 index 47907d8..0000000 --- a/10-quirks.conf +++ /dev/null @@ -1,38 +0,0 @@ -# Collection of quirks and blacklist/whitelists for specific devices. - - -# Accelerometer device, posts data through ABS_X/ABS_Y, making X unusable -# http://bugs.freedesktop.org/show_bug.cgi?id=22442 -Section "InputClass" - Identifier "ThinkPad HDAPS accelerometer blacklist" - MatchProduct "ThinkPad HDAPS accelerometer data" - Option "Ignore" "on" -EndSection - -# https://bugzilla.redhat.com/show_bug.cgi?id=523914 -# Mouse does not move in PV Xen guest -# Explicitly tell evdev to not ignore the absolute axes. -Section "InputClass" - Identifier "Xen Virtual Pointer axis blacklist" - MatchProduct "Xen Virtual Pointer" - Option "IgnoreAbsoluteAxes" "off" - Option "IgnoreRelativeAxes" "off" -EndSection - -# https://bugs.freedesktop.org/show_bug.cgi?id=55867 -# Bug 55867 - Doesn't know how to tag XI_TRACKBALL -Section "InputClass" - Identifier "Tag trackballs as XI_TRACKBALL" - MatchProduct "trackball" - MatchDriver "evdev" - Option "TypeName" "TRACKBALL" -EndSection - -# https://bugs.freedesktop.org/show_bug.cgi?id=62831 -# Bug 62831 - Mionix Naos 5000 mouse detected incorrectly -Section "InputClass" - Identifier "Tag Mionix Naos 5000 mouse XI_MOUSE" - MatchProduct "La-VIEW Technology Naos 5000 Mouse" - MatchDriver "evdev" - Option "TypeName" "MOUSE" -EndSection diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 3fd8caf..2cfb3ec 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 14%{?gitdate:.%{gitdate}}%{?dist} +Release: 15%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -63,8 +63,6 @@ Source0: https://www.x.org/pub/individual/xserver/%{pkgname}-%{version}.tar.xz Source1: gitignore %endif -Source4: 10-quirks.conf - Source10: xserver.pamd # "useful" xvfb-run script @@ -107,6 +105,7 @@ Patch101: 0001-render-Fix-build-with-gcc-12.patch Patch102: 0001-xf86-Accept-devices-with-the-simpledrm-driver.patch Patch103: 0001-Don-t-hardcode-fps-for-fake-screen.patch Patch104: 0001-hw-Rename-boolean-config-value-field-from-bool-to-bo.patch +Patch105: 0001-add-a-quirk-for-apple-silicon.patch # CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070 Patch110: 0001-xkb-switch-to-array-index-loops-to-moving-pointers.patch @@ -408,9 +407,6 @@ mkdir -p $RPM_BUILD_ROOT%{_libdir}/xorg/modules/{drivers,input} mkdir -p $RPM_BUILD_ROOT%{_sysconfdir}/pam.d install -m 644 %{SOURCE10} $RPM_BUILD_ROOT%{_sysconfdir}/pam.d/xserver -mkdir -p $RPM_BUILD_ROOT%{_datadir}/X11/xorg.conf.d -install -m 644 %{SOURCE4} $RPM_BUILD_ROOT%{_datadir}/X11/xorg.conf.d - # make sure the (empty) /etc/X11/xorg.conf.d is there, system-setup-keyboard # relies on it more or less. mkdir -p $RPM_BUILD_ROOT%{_sysconfdir}/X11/xorg.conf.d @@ -554,6 +550,10 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Fri Jan 13 2023 Leif Liddy 1.20.14-15 +- Xorg server does not correctly select the DCP for the display + without a quirk on Apple silicon machines (#2152414) + * Fri Jan 13 2023 Peter Hutterer - 1.20.14-14 - Disallow byte-swapped clients (#2159489) From 743d53fc693d797a9aabefe0bb9aba63cbe6d05e Mon Sep 17 00:00:00 2001 From: Olivier Fourdan Date: Tue, 17 Jan 2023 17:12:15 +0100 Subject: [PATCH 24/74] Use the recommended way to apply conditional patches https://docs.fedoraproject.org/en-US/packaging-guidelines/SourceURL/#_do_not_conditionalize_sources --- xorg-x11-server.spec | 16 +++++++++++----- 1 file changed, 11 insertions(+), 5 deletions(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 2cfb3ec..be5d1f1 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 15%{?gitdate:.%{gitdate}}%{?dist} +Release: 16%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -134,11 +134,9 @@ Patch121: 0007-xkb-reset-the-radio_groups-pointer-to-NULL-after-fre.patch # Fix for buggy patch to CVE-2022-46340 Patch122: 0008-Xext-fix-invalid-event-type-mask-in-XTestSwapFakeInp.patch -# Only on F38 and later -%if 0%{fedora} >= 38 +# Only on F38 and later (patch number starts at 3801, see autopatch below) # Upstream commits 73d6e88, f69280dd and 4127776, minus the xwayland.pc.in change -Patch200: 0001-Disallow-byte-swapped-clients-by-default.patch -%endif +Patch3801: 0001-Disallow-byte-swapped-clients-by-default.patch BuildRequires: make BuildRequires: systemtap-sdt-devel @@ -327,7 +325,11 @@ cp %{SOURCE1} .gitignore # ick %global __scm git %{expand:%__scm_setup_git -q} +%if 0%{fedora} >= 38 %autopatch +%else +%autopatch -M 3800 +%endif %if 0%{?stable_abi} # check the ABI in the source against what we expect. @@ -550,6 +552,10 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Tue Jan 17 2023 Olivier Fourdan - 1.20.14-16 +- Use the recommended way to apply conditional patches without + conditionalizing the sources (for byte-swapped clients). + * Fri Jan 13 2023 Leif Liddy 1.20.14-15 - Xorg server does not correctly select the DCP for the display without a quirk on Apple silicon machines (#2152414) From 50af4f1fc6d205eb636df1459c071467ef161e14 Mon Sep 17 00:00:00 2001 From: Peter Hutterer Date: Wed, 1 Feb 2023 14:27:20 +1000 Subject: [PATCH 25/74] Updated conditional fedora statement --- xorg-x11-server.spec | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index be5d1f1..c689d4e 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 16%{?gitdate:.%{gitdate}}%{?dist} +Release: 17%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -325,7 +325,7 @@ cp %{SOURCE1} .gitignore # ick %global __scm git %{expand:%__scm_setup_git -q} -%if 0%{fedora} >= 38 +%if 0%{?fedora} >= 38 %autopatch %else %autopatch -M 3800 @@ -552,6 +552,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Wed Feb 01 2023 Peter Hutterer - 1.20.14-17 +- Updated conditional fedora statement + * Tue Jan 17 2023 Olivier Fourdan - 1.20.14-16 - Use the recommended way to apply conditional patches without conditionalizing the sources (for byte-swapped clients). From 996eaa843f218b2e237334460c31ac4c2d221f53 Mon Sep 17 00:00:00 2001 From: Peter Hutterer Date: Thu, 2 Feb 2023 15:32:24 +1000 Subject: [PATCH 26/74] CVE-2023-0494: potential use-after-free --- ...-use-after-free-in-DeepCopyPointerCl.patch | 35 +++++++++++++++++++ xorg-x11-server.spec | 7 +++- 2 files changed, 41 insertions(+), 1 deletion(-) create mode 100644 0001-Xi-fix-potential-use-after-free-in-DeepCopyPointerCl.patch diff --git a/0001-Xi-fix-potential-use-after-free-in-DeepCopyPointerCl.patch b/0001-Xi-fix-potential-use-after-free-in-DeepCopyPointerCl.patch new file mode 100644 index 0000000..2389895 --- /dev/null +++ b/0001-Xi-fix-potential-use-after-free-in-DeepCopyPointerCl.patch @@ -0,0 +1,35 @@ +From 7150ba655c0cc08fa6ded309b81265bb672f2869 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Wed, 25 Jan 2023 11:41:40 +1000 +Subject: [PATCH xserver] Xi: fix potential use-after-free in + DeepCopyPointerClasses + +CVE-2023-0494, ZDI-CAN 19596 + +This vulnerability was discovered by: +Jan-Niklas Sohn working with Trend Micro Zero Day Initiative + +Signed-off-by: Peter Hutterer +--- + Xi/exevents.c | 4 +++- + 1 file changed, 3 insertions(+), 1 deletion(-) + +diff --git a/Xi/exevents.c b/Xi/exevents.c +index 217baa9561..dcd4efb3bc 100644 +--- a/Xi/exevents.c ++++ b/Xi/exevents.c +@@ -619,8 +619,10 @@ DeepCopyPointerClasses(DeviceIntPtr from, DeviceIntPtr to) + memcpy(to->button->xkb_acts, from->button->xkb_acts, + sizeof(XkbAction)); + } +- else ++ else { + free(to->button->xkb_acts); ++ to->button->xkb_acts = NULL; ++ } + + memcpy(to->button->labels, from->button->labels, + from->button->numButtons * sizeof(Atom)); +-- +2.39.0 + diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index c689d4e..0c2a07e 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 17%{?gitdate:.%{gitdate}}%{?dist} +Release: 18%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -133,6 +133,8 @@ Patch120: 0006-Xext-free-the-XvRTVideoNotify-when-turning-off-from-.patch Patch121: 0007-xkb-reset-the-radio_groups-pointer-to-NULL-after-fre.patch # Fix for buggy patch to CVE-2022-46340 Patch122: 0008-Xext-fix-invalid-event-type-mask-in-XTestSwapFakeInp.patch +# CVE-2023-0494 +Patch123: 0001-Xi-fix-potential-use-after-free-in-DeepCopyPointerCl.patch # Only on F38 and later (patch number starts at 3801, see autopatch below) # Upstream commits 73d6e88, f69280dd and 4127776, minus the xwayland.pc.in change @@ -552,6 +554,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Thu Feb 02 2023 Peter Hutterer - 1.20.14-18 +- CVE-2023-0494: potential use-after-free + * Wed Feb 01 2023 Peter Hutterer - 1.20.14-17 - Updated conditional fedora statement From 7c9187a0934bb176ae8f46c0a11fc6dee3488c35 Mon Sep 17 00:00:00 2001 From: Iker Pedrosa Date: Mon, 6 Feb 2023 12:09:39 +0100 Subject: [PATCH 27/74] Remove pam_console from service file pam_console is being removed as it was replaced by ConsoleKit, and later by systemd-logind. Most probably the migration was already done years ago as I don't see any specific configuration file for pam_console. This change only removes pam_console from the service file. If you are curious about the removal check the Fedora System-Wide Change proposal linked below. Resolves: https://bugzilla.redhat.com/show_bug.cgi?id=1822209 Relates: https://fedoraproject.org/wiki/Changes/RemovePamConsole Relates: https://bugzilla.redhat.com/show_bug.cgi?id=2166692 Signed-off-by: Iker Pedrosa --- xorg-x11-server.spec | 5 ++++- xserver.pamd | 1 - 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 0c2a07e..5c4ddfd 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 18%{?gitdate:.%{gitdate}}%{?dist} +Release: 19%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -554,6 +554,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Thu Feb 09 2023 Iker Pedrosa - 1.20.14-19 +- Remove pam_console from service file (#1822209) + * Thu Feb 02 2023 Peter Hutterer - 1.20.14-18 - CVE-2023-0494: potential use-after-free diff --git a/xserver.pamd b/xserver.pamd index bf79930..9374ff6 100644 --- a/xserver.pamd +++ b/xserver.pamd @@ -1,5 +1,4 @@ #%PAM-1.0 auth sufficient pam_rootok.so -auth required pam_console.so account required pam_permit.so session optional pam_keyinit.so force revoke From 31ea8b9649d0ba2dca56c218edcfd39530181c3e Mon Sep 17 00:00:00 2001 From: Olivier Fourdan Date: Thu, 23 Feb 2023 09:09:36 +0100 Subject: [PATCH 28/74] Fix xvfb-run script with --listen-tcp --- xorg-x11-server.spec | 5 ++++- xvfb-run.sh | 2 +- 2 files changed, 5 insertions(+), 2 deletions(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 5c4ddfd..cfd9c76 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 19%{?gitdate:.%{gitdate}}%{?dist} +Release: 20%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -554,6 +554,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Thu Feb 23 2023 Olivier Fourdan - 1.20.14-20 +- Fix xvfb-run script with --listen-tcp + * Thu Feb 09 2023 Iker Pedrosa - 1.20.14-19 - Remove pam_console from service file (#1822209) diff --git a/xvfb-run.sh b/xvfb-run.sh index 9d088c1..5d4447b 100644 --- a/xvfb-run.sh +++ b/xvfb-run.sh @@ -120,7 +120,7 @@ while :; do -f|--auth-file) AUTHFILE="$2"; shift ;; -h|--help) SHOWHELP="yes" ;; -n|--server-num) SERVERNUM="$2"; shift ;; - -l|--listen-tcp) LISTENTCP="" ;; + -l|--listen-tcp) LISTENTCP="-listen tcp" ;; -p|--xauth-protocol) XAUTHPROTO="$2"; shift ;; -s|--server-args) XVFBARGS="$2"; shift ;; -w|--wait) STARTWAIT="$2"; shift ;; From 21269fd4b752289d8f45277ac9a92bb6bb72dcc1 Mon Sep 17 00:00:00 2001 From: Olivier Fourdan Date: Wed, 29 Mar 2023 15:36:30 +0200 Subject: [PATCH 29/74] Fix for CVE-2023-1393 --- ...posite-Fix-use-after-free-of-the-COW.patch | 42 +++++++++++++++++++ xorg-x11-server.spec | 7 +++- 2 files changed, 48 insertions(+), 1 deletion(-) create mode 100644 0001-composite-Fix-use-after-free-of-the-COW.patch diff --git a/0001-composite-Fix-use-after-free-of-the-COW.patch b/0001-composite-Fix-use-after-free-of-the-COW.patch new file mode 100644 index 0000000..bb21d7e --- /dev/null +++ b/0001-composite-Fix-use-after-free-of-the-COW.patch @@ -0,0 +1,42 @@ +From 26ef545b3502f61ca722a7a3373507e88ef64110 Mon Sep 17 00:00:00 2001 +From: Olivier Fourdan +Date: Mon, 13 Mar 2023 11:08:47 +0100 +Subject: [PATCH xserver] composite: Fix use-after-free of the COW + +ZDI-CAN-19866/CVE-2023-1393 + +If a client explicitly destroys the compositor overlay window (aka COW), +we would leave a dangling pointer to that window in the CompScreen +structure, which will trigger a use-after-free later. + +Make sure to clear the CompScreen pointer to the COW when the latter gets +destroyed explicitly by the client. + +This vulnerability was discovered by: +Jan-Niklas Sohn working with Trend Micro Zero Day Initiative + +Signed-off-by: Olivier Fourdan +Reviewed-by: Adam Jackson +--- + composite/compwindow.c | 5 +++++ + 1 file changed, 5 insertions(+) + +diff --git a/composite/compwindow.c b/composite/compwindow.c +index 4e2494b86..b30da589e 100644 +--- a/composite/compwindow.c ++++ b/composite/compwindow.c +@@ -620,6 +620,11 @@ compDestroyWindow(WindowPtr pWin) + ret = (*pScreen->DestroyWindow) (pWin); + cs->DestroyWindow = pScreen->DestroyWindow; + pScreen->DestroyWindow = compDestroyWindow; ++ ++ /* Did we just destroy the overlay window? */ ++ if (pWin == cs->pOverlayWin) ++ cs->pOverlayWin = NULL; ++ + /* compCheckTree (pWin->drawable.pScreen); can't check -- tree isn't good*/ + return ret; + } +-- +2.40.0 + diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index cfd9c76..53f1d75 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 20%{?gitdate:.%{gitdate}}%{?dist} +Release: 21%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -135,6 +135,8 @@ Patch121: 0007-xkb-reset-the-radio_groups-pointer-to-NULL-after-fre.patch Patch122: 0008-Xext-fix-invalid-event-type-mask-in-XTestSwapFakeInp.patch # CVE-2023-0494 Patch123: 0001-Xi-fix-potential-use-after-free-in-DeepCopyPointerCl.patch +# CVE-2023-1393 +Patch124: 0001-composite-Fix-use-after-free-of-the-COW.patch # Only on F38 and later (patch number starts at 3801, see autopatch below) # Upstream commits 73d6e88, f69280dd and 4127776, minus the xwayland.pc.in change @@ -554,6 +556,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Wed Mar 29 2023 Olivier Fourdan - 1.20.14-21 +- CVE fix for: CVE-2023-1393 + * Thu Feb 23 2023 Olivier Fourdan - 1.20.14-20 - Fix xvfb-run script with --listen-tcp From c2b6cc043d2760f168e97ce7860c344357645e25 Mon Sep 17 00:00:00 2001 From: Florian Weimer Date: Thu, 13 Apr 2023 15:48:20 +0200 Subject: [PATCH 30/74] Make more functions available in fb.h with !FB_ACCESS_WRAPPER Related to: --- xorg-x11-server-fb-access-wrapper.patch | 31 +++++++++++++++++++++++++ xorg-x11-server.spec | 7 +++++- 2 files changed, 37 insertions(+), 1 deletion(-) create mode 100644 xorg-x11-server-fb-access-wrapper.patch diff --git a/xorg-x11-server-fb-access-wrapper.patch b/xorg-x11-server-fb-access-wrapper.patch new file mode 100644 index 0000000..7bb0e23 --- /dev/null +++ b/xorg-x11-server-fb-access-wrapper.patch @@ -0,0 +1,31 @@ +fb: Declare wfbFinishScreenInit, wfbScreenInit for !FB_ACCESS_WRAPPER + +xorg-x11-drv-nouveau wfbScreenInit without defining FB_ACCESS_WRAPPER +(which has other unintended side effects). Presently, this compiles +and links because compilers still support implicit function +declarations, but this is going to change fairly soon. This seems to +be the most straightforward change to keep the driver building. + +Submitted upstream: + + + +diff -ur xorg-server-1.20.14.orig/fb/fb.h xorg-server-1.20.14/fb/fb.h +--- xorg-server-1.20.14.orig/fb/fb.h 2021-12-15 20:01:24.000000000 +0100 ++++ xorg-server-1.20.14/fb/fb.h 2023-04-13 13:59:47.325341537 +0200 +@@ -1027,7 +1027,6 @@ + int dpiy, int width, /* pixel width of frame buffer */ + int bpp); /* bits per pixel of frame buffer */ + +-#ifdef FB_ACCESS_WRAPPER + extern _X_EXPORT Bool + wfbFinishScreenInit(ScreenPtr pScreen, + void *pbits, +@@ -1049,7 +1048,6 @@ + int width, + int bpp, + SetupWrapProcPtr setupWrap, FinishWrapProcPtr finishWrap); +-#endif + + extern _X_EXPORT Bool + fbFinishScreenInit(ScreenPtr pScreen, diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 53f1d75..2086fcd 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 21%{?gitdate:.%{gitdate}}%{?dist} +Release: 22%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -138,6 +138,8 @@ Patch123: 0001-Xi-fix-potential-use-after-free-in-DeepCopyPointerCl.patch # CVE-2023-1393 Patch124: 0001-composite-Fix-use-after-free-of-the-COW.patch +Patch125: xorg-x11-server-fb-access-wrapper.patch + # Only on F38 and later (patch number starts at 3801, see autopatch below) # Upstream commits 73d6e88, f69280dd and 4127776, minus the xwayland.pc.in change Patch3801: 0001-Disallow-byte-swapped-clients-by-default.patch @@ -556,6 +558,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Thu Apr 13 2023 Florian Weimer - 1.20.14-22 +- Make more functions available in fb.h with !FB_ACCESS_WRAPPER + * Wed Mar 29 2023 Olivier Fourdan - 1.20.14-21 - CVE fix for: CVE-2023-1393 From a3932dc93a2738b8ce64b45b18107c12588c4ffc Mon Sep 17 00:00:00 2001 From: Olivier Fourdan Date: Tue, 25 Apr 2023 10:49:16 +0200 Subject: [PATCH 31/74] Backport fix for a deadlock with DRI3 See https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/1057 and https://gitlab.freedesktop.org/mesa/mesa/-/merge_requests/21339 Resolves: #2189434 --- ...resentConfigureNotify-event-for-dest.patch | 105 ++++++++++++++++++ xorg-x11-server.spec | 9 +- 2 files changed, 112 insertions(+), 2 deletions(-) create mode 100644 0001-present-Send-a-PresentConfigureNotify-event-for-dest.patch diff --git a/0001-present-Send-a-PresentConfigureNotify-event-for-dest.patch b/0001-present-Send-a-PresentConfigureNotify-event-for-dest.patch new file mode 100644 index 0000000..d9eea48 --- /dev/null +++ b/0001-present-Send-a-PresentConfigureNotify-event-for-dest.patch @@ -0,0 +1,105 @@ +From b98fc07d3442a289c6bef82df50dd0a2d01de71a Mon Sep 17 00:00:00 2001 +From: Adam Jackson +Date: Thu, 2 Feb 2023 12:26:27 -0500 +Subject: [PATCH xserver] present: Send a PresentConfigureNotify event for + destroyed windows +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +This enables fixing a deadlock case on the client side, where the client +ends up blocked waiting for a Present event that will never come because +the window was destroyed. The new PresentWindowDestroyed flag allows the +client to avoid blocking indefinitely. + +Signed-off-by: Adam Jackson +See-also: https://gitlab.freedesktop.org/mesa/mesa/-/issues/116 +See-also: https://gitlab.freedesktop.org/mesa/mesa/-/issues/6685 +Reviewed-by: Michel Dänzer +(cherry picked from commit 462b06033e66a32308d940eb5fc47f5e4c914dc0) +--- + present/present_event.c | 5 +++-- + present/present_priv.h | 7 ++++++- + present/present_screen.c | 11 ++++++++++- + 3 files changed, 19 insertions(+), 4 deletions(-) + +diff --git a/present/present_event.c b/present/present_event.c +index 435b26b70..849732dc8 100644 +--- a/present/present_event.c ++++ b/present/present_event.c +@@ -102,7 +102,8 @@ present_event_swap(xGenericEvent *from, xGenericEvent *to) + } + + void +-present_send_config_notify(WindowPtr window, int x, int y, int w, int h, int bw, WindowPtr sibling) ++present_send_config_notify(WindowPtr window, int x, int y, int w, int h, ++ int bw, WindowPtr sibling, CARD32 flags) + { + present_window_priv_ptr window_priv = present_window_priv(window); + +@@ -122,7 +123,7 @@ present_send_config_notify(WindowPtr window, int x, int y, int w, int h, int bw, + .off_y = 0, + .pixmap_width = w, + .pixmap_height = h, +- .pixmap_flags = 0 ++ .pixmap_flags = flags + }; + present_event_ptr event; + +diff --git a/present/present_priv.h b/present/present_priv.h +index 6ebd009a2..4ad729864 100644 +--- a/present/present_priv.h ++++ b/present/present_priv.h +@@ -43,6 +43,11 @@ + #define DebugPresent(x) + #endif + ++/* XXX this belongs in presentproto */ ++#ifndef PresentWindowDestroyed ++#define PresentWindowDestroyed (1 << 0) ++#endif ++ + extern int present_request; + + extern DevPrivateKeyRec present_screen_private_key; +@@ -307,7 +312,7 @@ void + present_free_events(WindowPtr window); + + void +-present_send_config_notify(WindowPtr window, int x, int y, int w, int h, int bw, WindowPtr sibling); ++present_send_config_notify(WindowPtr window, int x, int y, int w, int h, int bw, WindowPtr sibling, CARD32 flags); + + void + present_send_complete_notify(WindowPtr window, CARD8 kind, CARD8 mode, CARD32 serial, uint64_t ust, uint64_t msc); +diff --git a/present/present_screen.c b/present/present_screen.c +index 15684eda4..2c29aafd2 100644 +--- a/present/present_screen.c ++++ b/present/present_screen.c +@@ -93,6 +93,15 @@ present_destroy_window(WindowPtr window) + present_screen_priv_ptr screen_priv = present_screen_priv(screen); + present_window_priv_ptr window_priv = present_window_priv(window); + ++ present_send_config_notify(window, ++ window->drawable.x, ++ window->drawable.y, ++ window->drawable.width, ++ window->drawable.height, ++ window->borderWidth, ++ window->nextSib, ++ PresentWindowDestroyed); ++ + if (window_priv) { + present_clear_window_notifies(window); + present_free_events(window); +@@ -123,7 +132,7 @@ present_config_notify(WindowPtr window, + ScreenPtr screen = window->drawable.pScreen; + present_screen_priv_ptr screen_priv = present_screen_priv(screen); + +- present_send_config_notify(window, x, y, w, h, bw, sibling); ++ present_send_config_notify(window, x, y, w, h, bw, sibling, 0); + + unwrap(screen_priv, screen, ConfigNotify); + if (screen->ConfigNotify) +-- +2.40.0 + diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 2086fcd..26d66b7 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 22%{?gitdate:.%{gitdate}}%{?dist} +Release: 23%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -137,8 +137,10 @@ Patch122: 0008-Xext-fix-invalid-event-type-mask-in-XTestSwapFakeInp.patch Patch123: 0001-Xi-fix-potential-use-after-free-in-DeepCopyPointerCl.patch # CVE-2023-1393 Patch124: 0001-composite-Fix-use-after-free-of-the-COW.patch - +# https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/1114 Patch125: xorg-x11-server-fb-access-wrapper.patch +# https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/1057 +Patch126: 0001-present-Send-a-PresentConfigureNotify-event-for-dest.patch # Only on F38 and later (patch number starts at 3801, see autopatch below) # Upstream commits 73d6e88, f69280dd and 4127776, minus the xwayland.pc.in change @@ -558,6 +560,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Tue Apr 25 2023 Olivier Fourdan - 1.20.14-23 +- Backport fix for a deadlock with DRI3 (#2189434) + * Thu Apr 13 2023 Florian Weimer - 1.20.14-22 - Make more functions available in fb.h with !FB_ACCESS_WRAPPER From 78721b7ea482c93d27905fdf090063fb91a3c666 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sat, 22 Jul 2023 19:11:32 +0000 Subject: [PATCH 32/74] Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- xorg-x11-server.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 26d66b7..fa40e3e 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 23%{?gitdate:.%{gitdate}}%{?dist} +Release: 24%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -560,6 +560,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Sat Jul 22 2023 Fedora Release Engineering - 1.20.14-24 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild + * Tue Apr 25 2023 Olivier Fourdan - 1.20.14-23 - Backport fix for a deadlock with DRI3 (#2189434) From fdd7c4bbd1151dc311da2f82297f70df2b035700 Mon Sep 17 00:00:00 2001 From: Orion Poplawski Date: Thu, 28 Sep 2023 21:16:17 -0600 Subject: [PATCH 33/74] Fix xvfb-run --error-file / auth-file options --- xorg-x11-server.spec | 5 ++++- xvfb-run.sh | 2 +- 2 files changed, 5 insertions(+), 2 deletions(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index fa40e3e..4f76f9a 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 24%{?gitdate:.%{gitdate}}%{?dist} +Release: 25%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org License: MIT @@ -560,6 +560,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Fri Sep 29 2023 Orion Poplawski - 1.20.14-25 +- Fix xvfb-run --error-file / auth-file options + * Sat Jul 22 2023 Fedora Release Engineering - 1.20.14-24 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild diff --git a/xvfb-run.sh b/xvfb-run.sh index 5d4447b..dec7dfc 100644 --- a/xvfb-run.sh +++ b/xvfb-run.sh @@ -101,7 +101,7 @@ find_free_servernum() { # Parse the command line. ARGS=$(getopt --options +ade:f:hn:lp:s:w: \ - --long auto-servernum,error-file:auth-file:,help,server-num:,listen-tcp,xauth-protocol:,server-args:,wait: \ + --long auto-servernum,error-file:,auth-file:,help,server-num:,listen-tcp,xauth-protocol:,server-args:,wait: \ --name "$PROGNAME" -- "$@") GETOPT_STATUS=$? From 28a268e0aa19293ea5cfe3736bf014aa6b02ccac Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jos=C3=A9=20Exp=C3=B3sito?= Date: Fri, 20 Oct 2023 17:38:41 +0200 Subject: [PATCH 34/74] SPDX migration: license is already SPDX compatible --- xorg-x11-server.spec | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 4f76f9a..36e248d 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -48,6 +48,7 @@ Name: xorg-x11-server Version: 1.20.14 Release: 25%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org +# SPDX License: MIT #VCS: git:git://git.freedesktop.org/git/xorg/xserver @@ -560,6 +561,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Fri Oct 20 2023 José Expósito +- SPDX migration: license is already SPDX compatible + * Fri Sep 29 2023 Orion Poplawski - 1.20.14-25 - Fix xvfb-run --error-file / auth-file options From 54e15127aead5542e24995da0955e72348bc4bf8 Mon Sep 17 00:00:00 2001 From: Peter Hutterer Date: Tue, 17 Oct 2023 15:42:37 +1000 Subject: [PATCH 35/74] CVE fix for: CVE-2023-5367, CVE-2023-5380 --- ...x-handling-of-PropModeAppend-Prepend.patch | 80 +++++++++++++++ ...nterWindows-reference-on-screen-swit.patch | 99 +++++++++++++++++++ xorg-x11-server.spec | 11 ++- 3 files changed, 189 insertions(+), 1 deletion(-) create mode 100644 0001-Xi-randr-fix-handling-of-PropModeAppend-Prepend.patch create mode 100644 0002-mi-reset-the-PointerWindows-reference-on-screen-swit.patch diff --git a/0001-Xi-randr-fix-handling-of-PropModeAppend-Prepend.patch b/0001-Xi-randr-fix-handling-of-PropModeAppend-Prepend.patch new file mode 100644 index 0000000..99625dd --- /dev/null +++ b/0001-Xi-randr-fix-handling-of-PropModeAppend-Prepend.patch @@ -0,0 +1,80 @@ +From a31ba141824a7649e11f0ef7673718ce559d6337 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Tue, 3 Oct 2023 11:53:05 +1000 +Subject: [PATCH xserver 1/4] Xi/randr: fix handling of PropModeAppend/Prepend + +The handling of appending/prepending properties was incorrect, with at +least two bugs: the property length was set to the length of the new +part only, i.e. appending or prepending N elements to a property with P +existing elements always resulted in the property having N elements +instead of N + P. + +Second, when pre-pending a value to a property, the offset for the old +values was incorrect, leaving the new property with potentially +uninitalized values and/or resulting in OOB memory writes. +For example, prepending a 3 element value to a 5 element property would +result in this 8 value array: + [N, N, N, ?, ?, P, P, P ] P, P + ^OOB write + +The XI2 code is a copy/paste of the RandR code, so the bug exists in +both. + +CVE-2023-5367, ZDI-CAN-22153 + +This vulnerability was discovered by: +Jan-Niklas Sohn working with Trend Micro Zero Day Initiative + +Signed-off-by: Peter Hutterer +--- + Xi/xiproperty.c | 4 ++-- + randr/rrproperty.c | 4 ++-- + 2 files changed, 4 insertions(+), 4 deletions(-) + +diff --git a/Xi/xiproperty.c b/Xi/xiproperty.c +index 6ec419e870..563c4f31a5 100644 +--- a/Xi/xiproperty.c ++++ b/Xi/xiproperty.c +@@ -730,7 +730,7 @@ XIChangeDeviceProperty(DeviceIntPtr dev, Atom property, Atom type, + XIDestroyDeviceProperty(prop); + return BadAlloc; + } +- new_value.size = len; ++ new_value.size = total_len; + new_value.type = type; + new_value.format = format; + +@@ -747,7 +747,7 @@ XIChangeDeviceProperty(DeviceIntPtr dev, Atom property, Atom type, + case PropModePrepend: + new_data = new_value.data; + old_data = (void *) (((char *) new_value.data) + +- (prop_value->size * size_in_bytes)); ++ (len * size_in_bytes)); + break; + } + if (new_data) +diff --git a/randr/rrproperty.c b/randr/rrproperty.c +index c2fb9585c6..25469f57b2 100644 +--- a/randr/rrproperty.c ++++ b/randr/rrproperty.c +@@ -209,7 +209,7 @@ RRChangeOutputProperty(RROutputPtr output, Atom property, Atom type, + RRDestroyOutputProperty(prop); + return BadAlloc; + } +- new_value.size = len; ++ new_value.size = total_len; + new_value.type = type; + new_value.format = format; + +@@ -226,7 +226,7 @@ RRChangeOutputProperty(RROutputPtr output, Atom property, Atom type, + case PropModePrepend: + new_data = new_value.data; + old_data = (void *) (((char *) new_value.data) + +- (prop_value->size * size_in_bytes)); ++ (len * size_in_bytes)); + break; + } + if (new_data) +-- +2.41.0 + diff --git a/0002-mi-reset-the-PointerWindows-reference-on-screen-swit.patch b/0002-mi-reset-the-PointerWindows-reference-on-screen-swit.patch new file mode 100644 index 0000000..cbe9804 --- /dev/null +++ b/0002-mi-reset-the-PointerWindows-reference-on-screen-swit.patch @@ -0,0 +1,99 @@ +From 004f461c440cb6611eefb48fbbb4fa53a6d49f80 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Thu, 5 Oct 2023 12:19:45 +1000 +Subject: [PATCH xserver 2/4] mi: reset the PointerWindows reference on screen + switch + +PointerWindows[] keeps a reference to the last window our sprite +entered - changes are usually handled by CheckMotion(). + +If we switch between screens via XWarpPointer our +dev->spriteInfo->sprite->win is set to the new screen's root window. +If there's another window at the cursor location CheckMotion() will +trigger the right enter/leave events later. If there is not, it skips +that process and we never trigger LeaveWindow() - PointerWindows[] for +the device still refers to the previous window. + +If that window is destroyed we have a dangling reference that will +eventually cause a use-after-free bug when checking the window hierarchy +later. + +To trigger this, we require: +- two protocol screens +- XWarpPointer to the other screen's root window +- XDestroyWindow before entering any other window + +This is a niche bug so we hack around it by making sure we reset the +PointerWindows[] entry so we cannot have a dangling pointer. This +doesn't handle Enter/Leave events correctly but the previous code didn't +either. + +CVE-2023-5380, ZDI-CAN-21608 + +This vulnerability was discovered by: +Sri working with Trend Micro Zero Day Initiative + +Signed-off-by: Peter Hutterer +Reviewed-by: Adam Jackson +--- + dix/enterleave.h | 2 -- + include/eventstr.h | 3 +++ + mi/mipointer.c | 17 +++++++++++++++-- + 3 files changed, 18 insertions(+), 4 deletions(-) + +diff --git a/dix/enterleave.h b/dix/enterleave.h +index 4b833d8a3b..e8af924c68 100644 +--- a/dix/enterleave.h ++++ b/dix/enterleave.h +@@ -58,8 +58,6 @@ extern void DeviceFocusEvent(DeviceIntPtr dev, + + extern void EnterWindow(DeviceIntPtr dev, WindowPtr win, int mode); + +-extern void LeaveWindow(DeviceIntPtr dev); +- + extern void CoreFocusEvent(DeviceIntPtr kbd, + int type, int mode, int detail, WindowPtr pWin); + +diff --git a/include/eventstr.h b/include/eventstr.h +index bf3b95fe4a..2bae3b0767 100644 +--- a/include/eventstr.h ++++ b/include/eventstr.h +@@ -296,4 +296,7 @@ union _InternalEvent { + #endif + }; + ++extern void ++LeaveWindow(DeviceIntPtr dev); ++ + #endif +diff --git a/mi/mipointer.c b/mi/mipointer.c +index 75be1aeeb8..b12ae9be1d 100644 +--- a/mi/mipointer.c ++++ b/mi/mipointer.c +@@ -397,8 +397,21 @@ miPointerWarpCursor(DeviceIntPtr pDev, ScreenPtr pScreen, int x, int y) + #ifdef PANORAMIX + && noPanoramiXExtension + #endif +- ) +- UpdateSpriteForScreen(pDev, pScreen); ++ ) { ++ DeviceIntPtr master = GetMaster(pDev, MASTER_POINTER); ++ /* Hack for CVE-2023-5380: if we're moving ++ * screens PointerWindows[] keeps referring to the ++ * old window. If that gets destroyed we have a UAF ++ * bug later. Only happens when jumping from a window ++ * to the root window on the other screen. ++ * Enter/Leave events are incorrect for that case but ++ * too niche to fix. ++ */ ++ LeaveWindow(pDev); ++ if (master) ++ LeaveWindow(master); ++ UpdateSpriteForScreen(pDev, pScreen); ++ } + } + + /** +-- +2.41.0 + diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 36e248d..947af50 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 25%{?gitdate:.%{gitdate}}%{?dist} +Release: 26%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org # SPDX License: MIT @@ -147,6 +147,12 @@ Patch126: 0001-present-Send-a-PresentConfigureNotify-event-for-dest.patch # Upstream commits 73d6e88, f69280dd and 4127776, minus the xwayland.pc.in change Patch3801: 0001-Disallow-byte-swapped-clients-by-default.patch +# CVE-2023-5367 +Patch3810: 0001-Xi-randr-fix-handling-of-PropModeAppend-Prepend.patch +# CVE-2023-5380 +Patch3811: 0002-mi-reset-the-PointerWindows-reference-on-screen-swit.patch + + BuildRequires: make BuildRequires: systemtap-sdt-devel BuildRequires: git-core @@ -561,6 +567,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Wed Oct 25 2023 Peter Hutterer - 1.20.14-26 +- CVE fix for: CVE-2023-5367, CVE-2023-5380 + * Fri Oct 20 2023 José Expósito - SPDX migration: license is already SPDX compatible From d8ec1545f329a3851279b8d2bc9b457076d99ad2 Mon Sep 17 00:00:00 2001 From: Peter Hutterer Date: Fri, 10 Nov 2023 14:31:54 +1000 Subject: [PATCH 36/74] Update with full SPDX license list --- xorg-x11-server.spec | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 947af50..d7e492e 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,10 +46,10 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 26%{?gitdate:.%{gitdate}}%{?dist} +Release: 27%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org # SPDX -License: MIT +License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant #VCS: git:git://git.freedesktop.org/git/xorg/xserver %if 0%{?gitdate} @@ -567,6 +567,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Fri Nov 10 2023 Peter Hutterer - 1.20.14-27 +- Update with full SPDX license list + * Wed Oct 25 2023 Peter Hutterer - 1.20.14-26 - CVE fix for: CVE-2023-5367, CVE-2023-5380 From d887a5b9894b1664f040e0d3b1c94db95998fc70 Mon Sep 17 00:00:00 2001 From: Peter Hutterer Date: Wed, 13 Dec 2023 11:51:29 +1000 Subject: [PATCH 37/74] CVE fix for: CVE-2023-6377, CVE-2023-6478 --- ...te-enough-XkbActions-for-our-buttons.patch | 77 +++++++++++++++++++ ...ger-truncation-in-length-check-of-Pr.patch | 61 +++++++++++++++ xorg-x11-server.spec | 9 ++- 3 files changed, 146 insertions(+), 1 deletion(-) create mode 100644 0001-Xi-allocate-enough-XkbActions-for-our-buttons.patch create mode 100644 0001-randr-avoid-integer-truncation-in-length-check-of-Pr.patch diff --git a/0001-Xi-allocate-enough-XkbActions-for-our-buttons.patch b/0001-Xi-allocate-enough-XkbActions-for-our-buttons.patch new file mode 100644 index 0000000..11236a1 --- /dev/null +++ b/0001-Xi-allocate-enough-XkbActions-for-our-buttons.patch @@ -0,0 +1,77 @@ +From a7bda3080d2b44eae668cdcec7a93095385b9652 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Tue, 28 Nov 2023 15:19:04 +1000 +Subject: [PATCH xserver] Xi: allocate enough XkbActions for our buttons + +button->xkb_acts is supposed to be an array sufficiently large for all +our buttons, not just a single XkbActions struct. Allocating +insufficient memory here means when we memcpy() later in +XkbSetDeviceInfo we write into memory that wasn't ours to begin with, +leading to the usual security ooopsiedaisies. + +CVE-2023-6377, ZDI-CAN-22412, ZDI-CAN-22413 + +This vulnerability was discovered by: +Jan-Niklas Sohn working with Trend Micro Zero Day Initiative + +(cherry picked from commit 0c1a93d319558fe3ab2d94f51d174b4f93810afd) +--- + Xi/exevents.c | 12 ++++++------ + dix/devices.c | 10 ++++++++++ + 2 files changed, 16 insertions(+), 6 deletions(-) + +diff --git a/Xi/exevents.c b/Xi/exevents.c +index dcd4efb3bc..54ea11a938 100644 +--- a/Xi/exevents.c ++++ b/Xi/exevents.c +@@ -611,13 +611,13 @@ DeepCopyPointerClasses(DeviceIntPtr from, DeviceIntPtr to) + } + + if (from->button->xkb_acts) { +- if (!to->button->xkb_acts) { +- to->button->xkb_acts = calloc(1, sizeof(XkbAction)); +- if (!to->button->xkb_acts) +- FatalError("[Xi] not enough memory for xkb_acts.\n"); +- } ++ size_t maxbuttons = max(to->button->numButtons, from->button->numButtons); ++ to->button->xkb_acts = xnfreallocarray(to->button->xkb_acts, ++ maxbuttons, ++ sizeof(XkbAction)); ++ memset(to->button->xkb_acts, 0, maxbuttons * sizeof(XkbAction)); + memcpy(to->button->xkb_acts, from->button->xkb_acts, +- sizeof(XkbAction)); ++ from->button->numButtons * sizeof(XkbAction)); + } + else { + free(to->button->xkb_acts); +diff --git a/dix/devices.c b/dix/devices.c +index 5bf956ead4..15e46a9a5f 100644 +--- a/dix/devices.c ++++ b/dix/devices.c +@@ -2525,6 +2525,8 @@ RecalculateMasterButtons(DeviceIntPtr slave) + + if (master->button && master->button->numButtons != maxbuttons) { + int i; ++ int last_num_buttons = master->button->numButtons; ++ + DeviceChangedEvent event = { + .header = ET_Internal, + .type = ET_DeviceChanged, +@@ -2535,6 +2537,14 @@ RecalculateMasterButtons(DeviceIntPtr slave) + }; + + master->button->numButtons = maxbuttons; ++ if (last_num_buttons < maxbuttons) { ++ master->button->xkb_acts = xnfreallocarray(master->button->xkb_acts, ++ maxbuttons, ++ sizeof(XkbAction)); ++ memset(&master->button->xkb_acts[last_num_buttons], ++ 0, ++ (maxbuttons - last_num_buttons) * sizeof(XkbAction)); ++ } + + memcpy(&event.buttons.names, master->button->labels, maxbuttons * + sizeof(Atom)); +-- +2.43.0 + diff --git a/0001-randr-avoid-integer-truncation-in-length-check-of-Pr.patch b/0001-randr-avoid-integer-truncation-in-length-check-of-Pr.patch new file mode 100644 index 0000000..d88a8d5 --- /dev/null +++ b/0001-randr-avoid-integer-truncation-in-length-check-of-Pr.patch @@ -0,0 +1,61 @@ +From 58e83c683950ac9e253ab05dd7a13a8368b70a3c Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Mon, 27 Nov 2023 16:27:49 +1000 +Subject: [PATCH xserver] randr: avoid integer truncation in length check of + ProcRRChange*Property + +Affected are ProcRRChangeProviderProperty and ProcRRChangeOutputProperty. +See also xserver@8f454b79 where this same bug was fixed for the core +protocol and XI. + +This fixes an OOB read and the resulting information disclosure. + +Length calculation for the request was clipped to a 32-bit integer. With +the correct stuff->nUnits value the expected request size was +truncated, passing the REQUEST_FIXED_SIZE check. + +The server then proceeded with reading at least stuff->num_items bytes +(depending on stuff->format) from the request and stuffing whatever it +finds into the property. In the process it would also allocate at least +stuff->nUnits bytes, i.e. 4GB. + +CVE-2023-6478, ZDI-CAN-22561 + +This vulnerability was discovered by: +Jan-Niklas Sohn working with Trend Micro Zero Day Initiative + +(cherry picked from commit 14f480010a93ff962fef66a16412fafff81ad632) +--- + randr/rrproperty.c | 2 +- + randr/rrproviderproperty.c | 2 +- + 2 files changed, 2 insertions(+), 2 deletions(-) + +diff --git a/randr/rrproperty.c b/randr/rrproperty.c +index 25469f57b2..c4fef8a1f6 100644 +--- a/randr/rrproperty.c ++++ b/randr/rrproperty.c +@@ -530,7 +530,7 @@ ProcRRChangeOutputProperty(ClientPtr client) + char format, mode; + unsigned long len; + int sizeInBytes; +- int totalSize; ++ uint64_t totalSize; + int err; + + REQUEST_AT_LEAST_SIZE(xRRChangeOutputPropertyReq); +diff --git a/randr/rrproviderproperty.c b/randr/rrproviderproperty.c +index b79c17f9bf..90c5a9a933 100644 +--- a/randr/rrproviderproperty.c ++++ b/randr/rrproviderproperty.c +@@ -498,7 +498,7 @@ ProcRRChangeProviderProperty(ClientPtr client) + char format, mode; + unsigned long len; + int sizeInBytes; +- int totalSize; ++ uint64_t totalSize; + int err; + + REQUEST_AT_LEAST_SIZE(xRRChangeProviderPropertyReq); +-- +2.43.0 + diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index d7e492e..07a90fa 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 27%{?gitdate:.%{gitdate}}%{?dist} +Release: 28%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org # SPDX License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant @@ -151,6 +151,10 @@ Patch3801: 0001-Disallow-byte-swapped-clients-by-default.patch Patch3810: 0001-Xi-randr-fix-handling-of-PropModeAppend-Prepend.patch # CVE-2023-5380 Patch3811: 0002-mi-reset-the-PointerWindows-reference-on-screen-swit.patch +# CVE-2023-6377 +Patch3812: 0001-Xi-allocate-enough-XkbActions-for-our-buttons.patch +# CVE-2023-6478 +Patch3813: 0001-randr-avoid-integer-truncation-in-length-check-of-Pr.patch BuildRequires: make @@ -567,6 +571,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Wed Dec 13 2023 Peter Hutterer - 1.20.14-28 +- CVE fix for: CVE-2023-6377, CVE-2023-6478 + * Fri Nov 10 2023 Peter Hutterer - 1.20.14-27 - Update with full SPDX license list From 57dbbbe6c220ca822b1f10b1fc16eb158a3820a3 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jos=C3=A9=20Exp=C3=B3sito?= Date: Tue, 16 Jan 2024 15:19:18 +0100 Subject: [PATCH 38/74] CVE fix for: CVE-2023-6816, CVE-2024-0229, CVE-2024-21885, CVE-2024-21886, CVE-2024-0408 and CVE-2024-0409 --- ...enough-space-for-logical-button-maps.patch | 51 ++++ ...ficient-xEvents-for-our-DeviceStateN.patch | 84 +++++++ ...-DeviceStateNotify-event-calculation.patch | 217 ++++++++++++++++++ ...-a-new-ButtonClass-set-the-number-of.patch | 37 +++ ...hy-events-after-adding-removing-mast.patch | 109 +++++++++ ...linked-list-pointer-during-recursion.patch | 70 ++++++ ...ng-a-master-float-disabled-slaved-de.patch | 53 +++++ ...lx-Call-XACE-hooks-on-the-GLX-buffer.patch | 60 +++++ ...se-the-proper-private-key-for-cursor.patch | 56 +++++ xorg-x11-server.spec | 22 +- 10 files changed, 757 insertions(+), 2 deletions(-) create mode 100644 0001-dix-allocate-enough-space-for-logical-button-maps.patch create mode 100644 0002-dix-Allocate-sufficient-xEvents-for-our-DeviceStateN.patch create mode 100644 0003-dix-fix-DeviceStateNotify-event-calculation.patch create mode 100644 0004-Xi-when-creating-a-new-ButtonClass-set-the-number-of.patch create mode 100644 0005-Xi-flush-hierarchy-events-after-adding-removing-mast.patch create mode 100644 0006-Xi-do-not-keep-linked-list-pointer-during-recursion.patch create mode 100644 0007-dix-when-disabling-a-master-float-disabled-slaved-de.patch create mode 100644 0008-glx-Call-XACE-hooks-on-the-GLX-buffer.patch create mode 100644 0009-ephyr-xwayland-Use-the-proper-private-key-for-cursor.patch diff --git a/0001-dix-allocate-enough-space-for-logical-button-maps.patch b/0001-dix-allocate-enough-space-for-logical-button-maps.patch new file mode 100644 index 0000000..e11eb0e --- /dev/null +++ b/0001-dix-allocate-enough-space-for-logical-button-maps.patch @@ -0,0 +1,51 @@ +From 9e2ecb2af8302dedc49cb6a63ebe063c58a9e7e3 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Thu, 14 Dec 2023 11:29:49 +1000 +Subject: [PATCH 1/9] dix: allocate enough space for logical button maps + +Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for +each logical button currently down. Since buttons can be arbitrarily mapped +to anything up to 255 make sure we have enough bits for the maximum mapping. + +CVE-2023-6816, ZDI-CAN-22664, ZDI-CAN-22665 + +This vulnerability was discovered by: +Jan-Niklas Sohn working with Trend Micro Zero Day Initiative +--- + Xi/xiquerypointer.c | 3 +-- + dix/enterleave.c | 5 +++-- + 2 files changed, 4 insertions(+), 4 deletions(-) + +diff --git a/Xi/xiquerypointer.c b/Xi/xiquerypointer.c +index 5b77b1a44..2b05ac5f3 100644 +--- a/Xi/xiquerypointer.c ++++ b/Xi/xiquerypointer.c +@@ -149,8 +149,7 @@ ProcXIQueryPointer(ClientPtr client) + if (pDev->button) { + int i; + +- rep.buttons_len = +- bytes_to_int32(bits_to_bytes(pDev->button->numButtons)); ++ rep.buttons_len = bytes_to_int32(bits_to_bytes(256)); /* button map up to 255 */ + rep.length += rep.buttons_len; + buttons = calloc(rep.buttons_len, 4); + if (!buttons) +diff --git a/dix/enterleave.c b/dix/enterleave.c +index 867ec7436..ded8679d7 100644 +--- a/dix/enterleave.c ++++ b/dix/enterleave.c +@@ -784,8 +784,9 @@ DeviceFocusEvent(DeviceIntPtr dev, int type, int mode, int detail, + + mouse = IsFloating(dev) ? dev : GetMaster(dev, MASTER_POINTER); + +- /* XI 2 event */ +- btlen = (mouse->button) ? bits_to_bytes(mouse->button->numButtons) : 0; ++ /* XI 2 event contains the logical button map - maps are CARD8 ++ * so we need 256 bits for the possibly maximum mapping */ ++ btlen = (mouse->button) ? bits_to_bytes(256) : 0; + btlen = bytes_to_int32(btlen); + len = sizeof(xXIFocusInEvent) + btlen * 4; + +-- +2.43.0 + diff --git a/0002-dix-Allocate-sufficient-xEvents-for-our-DeviceStateN.patch b/0002-dix-Allocate-sufficient-xEvents-for-our-DeviceStateN.patch new file mode 100644 index 0000000..21c5622 --- /dev/null +++ b/0002-dix-Allocate-sufficient-xEvents-for-our-DeviceStateN.patch @@ -0,0 +1,84 @@ +From ece23be888a93b741aa1209d1dbf64636109d6a5 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Mon, 18 Dec 2023 14:27:50 +1000 +Subject: [PATCH 2/9] dix: Allocate sufficient xEvents for our + DeviceStateNotify + +If a device has both a button class and a key class and numButtons is +zero, we can get an OOB write due to event under-allocation. + +This function seems to assume a device has either keys or buttons, not +both. It has two virtually identical code paths, both of which assume +they're applying to the first event in the sequence. + +A device with both a key and button class triggered a logic bug - only +one xEvent was allocated but the deviceStateNotify pointer was pushed on +once per type. So effectively this logic code: + + int count = 1; + if (button && nbuttons > 32) count++; + if (key && nbuttons > 0) count++; + if (key && nkeys > 32) count++; // this is basically always true + // count is at 2 for our keys + zero button device + + ev = alloc(count * sizeof(xEvent)); + FixDeviceStateNotify(ev); + if (button) + FixDeviceStateNotify(ev++); + if (key) + FixDeviceStateNotify(ev++); // santa drops into the wrong chimney here + +If the device has more than 3 valuators, the OOB is pushed back - we're +off by one so it will happen when the last deviceValuator event is +written instead. + +Fix this by allocating the maximum number of events we may allocate. +Note that the current behavior is not protocol-correct anyway, this +patch fixes only the allocation issue. + +Note that this issue does not trigger if the device has at least one +button. While the server does not prevent a button class with zero +buttons, it is very unlikely. + +CVE-2024-0229, ZDI-CAN-22678 + +This vulnerability was discovered by: +Jan-Niklas Sohn working with Trend Micro Zero Day Initiative +--- + dix/enterleave.c | 6 +++--- + 1 file changed, 3 insertions(+), 3 deletions(-) + +diff --git a/dix/enterleave.c b/dix/enterleave.c +index ded8679d7..17964b00a 100644 +--- a/dix/enterleave.c ++++ b/dix/enterleave.c +@@ -675,7 +675,8 @@ static void + DeliverStateNotifyEvent(DeviceIntPtr dev, WindowPtr win) + { + int evcount = 1; +- deviceStateNotify *ev, *sev; ++ deviceStateNotify sev[6 + (MAX_VALUATORS + 2)/3]; ++ deviceStateNotify *ev; + deviceKeyStateNotify *kev; + deviceButtonStateNotify *bev; + +@@ -714,7 +715,7 @@ DeliverStateNotifyEvent(DeviceIntPtr dev, WindowPtr win) + } + } + +- sev = ev = xallocarray(evcount, sizeof(xEvent)); ++ ev = sev; + FixDeviceStateNotify(dev, ev, NULL, NULL, NULL, first); + + if (b != NULL) { +@@ -770,7 +771,6 @@ DeliverStateNotifyEvent(DeviceIntPtr dev, WindowPtr win) + + DeliverEventsToWindow(dev, win, (xEvent *) sev, evcount, + DeviceStateNotifyMask, NullGrab); +- free(sev); + } + + void +-- +2.43.0 + diff --git a/0003-dix-fix-DeviceStateNotify-event-calculation.patch b/0003-dix-fix-DeviceStateNotify-event-calculation.patch new file mode 100644 index 0000000..2fe2f8e --- /dev/null +++ b/0003-dix-fix-DeviceStateNotify-event-calculation.patch @@ -0,0 +1,217 @@ +From 219c54b8a3337456ce5270ded6a67bcde53553d5 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Mon, 18 Dec 2023 12:26:20 +1000 +Subject: [PATCH 3/9] dix: fix DeviceStateNotify event calculation + +The previous code only made sense if one considers buttons and keys to +be mutually exclusive on a device. That is not necessarily true, causing +a number of issues. + +This function allocates and fills in the number of xEvents we need to +send the device state down the wire. This is split across multiple +32-byte devices including one deviceStateNotify event and optional +deviceKeyStateNotify, deviceButtonStateNotify and (possibly multiple) +deviceValuator events. + +The previous behavior would instead compose a sequence +of [state, buttonstate, state, keystate, valuator...]. This is not +protocol correct, and on top of that made the code extremely convoluted. + +Fix this by streamlining: add both button and key into the deviceStateNotify +and then append the key state and button state, followed by the +valuators. Finally, the deviceValuator events contain up to 6 valuators +per event but we only ever sent through 3 at a time. Let's double that +troughput. + +CVE-2024-0229, ZDI-CAN-22678 + +This vulnerability was discovered by: +Jan-Niklas Sohn working with Trend Micro Zero Day Initiative +--- + dix/enterleave.c | 121 ++++++++++++++++++++--------------------------- + 1 file changed, 52 insertions(+), 69 deletions(-) + +diff --git a/dix/enterleave.c b/dix/enterleave.c +index 17964b00a..7b7ba1098 100644 +--- a/dix/enterleave.c ++++ b/dix/enterleave.c +@@ -615,9 +615,15 @@ FixDeviceValuator(DeviceIntPtr dev, deviceValuator * ev, ValuatorClassPtr v, + + ev->type = DeviceValuator; + ev->deviceid = dev->id; +- ev->num_valuators = nval < 3 ? nval : 3; ++ ev->num_valuators = nval < 6 ? nval : 6; + ev->first_valuator = first; + switch (ev->num_valuators) { ++ case 6: ++ ev->valuator2 = v->axisVal[first + 5]; ++ case 5: ++ ev->valuator2 = v->axisVal[first + 4]; ++ case 4: ++ ev->valuator2 = v->axisVal[first + 3]; + case 3: + ev->valuator2 = v->axisVal[first + 2]; + case 2: +@@ -626,7 +632,6 @@ FixDeviceValuator(DeviceIntPtr dev, deviceValuator * ev, ValuatorClassPtr v, + ev->valuator0 = v->axisVal[first]; + break; + } +- first += ev->num_valuators; + } + + static void +@@ -646,7 +651,7 @@ FixDeviceStateNotify(DeviceIntPtr dev, deviceStateNotify * ev, KeyClassPtr k, + ev->num_buttons = b->numButtons; + memcpy((char *) ev->buttons, (char *) b->down, 4); + } +- else if (k) { ++ if (k) { + ev->classes_reported |= (1 << KeyClass); + ev->num_keys = k->xkbInfo->desc->max_key_code - + k->xkbInfo->desc->min_key_code; +@@ -670,15 +675,26 @@ FixDeviceStateNotify(DeviceIntPtr dev, deviceStateNotify * ev, KeyClassPtr k, + } + } + +- ++/** ++ * The device state notify event is split across multiple 32-byte events. ++ * The first one contains the first 32 button state bits, the first 32 ++ * key state bits, and the first 3 valuator values. ++ * ++ * If a device has more than that, the server sends out: ++ * - one deviceButtonStateNotify for buttons 32 and above ++ * - one deviceKeyStateNotify for keys 32 and above ++ * - one deviceValuator event per 6 valuators above valuator 4 ++ * ++ * All events but the last one have the deviceid binary ORed with MORE_EVENTS, ++ */ + static void + DeliverStateNotifyEvent(DeviceIntPtr dev, WindowPtr win) + { ++ /* deviceStateNotify, deviceKeyStateNotify, deviceButtonStateNotify ++ * and one deviceValuator for each 6 valuators */ ++ deviceStateNotify sev[3 + (MAX_VALUATORS + 6)/6]; + int evcount = 1; +- deviceStateNotify sev[6 + (MAX_VALUATORS + 2)/3]; +- deviceStateNotify *ev; +- deviceKeyStateNotify *kev; +- deviceButtonStateNotify *bev; ++ deviceStateNotify *ev = sev; + + KeyClassPtr k; + ButtonClassPtr b; +@@ -691,82 +707,49 @@ DeliverStateNotifyEvent(DeviceIntPtr dev, WindowPtr win) + + if ((b = dev->button) != NULL) { + nbuttons = b->numButtons; +- if (nbuttons > 32) ++ if (nbuttons > 32) /* first 32 are encoded in deviceStateNotify */ + evcount++; + } + if ((k = dev->key) != NULL) { + nkeys = k->xkbInfo->desc->max_key_code - k->xkbInfo->desc->min_key_code; +- if (nkeys > 32) ++ if (nkeys > 32) /* first 32 are encoded in deviceStateNotify */ + evcount++; +- if (nbuttons > 0) { +- evcount++; +- } + } + if ((v = dev->valuator) != NULL) { + nval = v->numAxes; +- +- if (nval > 3) +- evcount++; +- if (nval > 6) { +- if (!(k && b)) +- evcount++; +- if (nval > 9) +- evcount += ((nval - 7) / 3); +- } ++ /* first three are encoded in deviceStateNotify, then ++ * it's 6 per deviceValuator event */ ++ evcount += ((nval - 3) + 6)/6; + } + +- ev = sev; +- FixDeviceStateNotify(dev, ev, NULL, NULL, NULL, first); +- +- if (b != NULL) { +- FixDeviceStateNotify(dev, ev++, NULL, b, v, first); +- first += 3; +- nval -= 3; +- if (nbuttons > 32) { +- (ev - 1)->deviceid |= MORE_EVENTS; +- bev = (deviceButtonStateNotify *) ev++; +- bev->type = DeviceButtonStateNotify; +- bev->deviceid = dev->id; +- memcpy((char *) &bev->buttons[4], (char *) &b->down[4], +- DOWN_LENGTH - 4); +- } +- if (nval > 0) { +- (ev - 1)->deviceid |= MORE_EVENTS; +- FixDeviceValuator(dev, (deviceValuator *) ev++, v, first); +- first += 3; +- nval -= 3; +- } ++ BUG_RETURN(evcount <= ARRAY_SIZE(sev)); ++ ++ FixDeviceStateNotify(dev, ev, k, b, v, first); ++ ++ if (b != NULL && nbuttons > 32) { ++ deviceButtonStateNotify *bev = (deviceButtonStateNotify *) ++ev; ++ (ev - 1)->deviceid |= MORE_EVENTS; ++ bev->type = DeviceButtonStateNotify; ++ bev->deviceid = dev->id; ++ memcpy((char *) &bev->buttons[4], (char *) &b->down[4], ++ DOWN_LENGTH - 4); + } + +- if (k != NULL) { +- FixDeviceStateNotify(dev, ev++, k, NULL, v, first); +- first += 3; +- nval -= 3; +- if (nkeys > 32) { +- (ev - 1)->deviceid |= MORE_EVENTS; +- kev = (deviceKeyStateNotify *) ev++; +- kev->type = DeviceKeyStateNotify; +- kev->deviceid = dev->id; +- memmove((char *) &kev->keys[0], (char *) &k->down[4], 28); +- } +- if (nval > 0) { +- (ev - 1)->deviceid |= MORE_EVENTS; +- FixDeviceValuator(dev, (deviceValuator *) ev++, v, first); +- first += 3; +- nval -= 3; +- } ++ if (k != NULL && nkeys > 32) { ++ deviceKeyStateNotify *kev = (deviceKeyStateNotify *) ++ev; ++ (ev - 1)->deviceid |= MORE_EVENTS; ++ kev->type = DeviceKeyStateNotify; ++ kev->deviceid = dev->id; ++ memmove((char *) &kev->keys[0], (char *) &k->down[4], 28); + } + ++ first = 3; ++ nval -= 3; + while (nval > 0) { +- FixDeviceStateNotify(dev, ev++, NULL, NULL, v, first); +- first += 3; +- nval -= 3; +- if (nval > 0) { +- (ev - 1)->deviceid |= MORE_EVENTS; +- FixDeviceValuator(dev, (deviceValuator *) ev++, v, first); +- first += 3; +- nval -= 3; +- } ++ ev->deviceid |= MORE_EVENTS; ++ FixDeviceValuator(dev, (deviceValuator *) ++ev, v, first); ++ first += 6; ++ nval -= 6; + } + + DeliverEventsToWindow(dev, win, (xEvent *) sev, evcount, +-- +2.43.0 + diff --git a/0004-Xi-when-creating-a-new-ButtonClass-set-the-number-of.patch b/0004-Xi-when-creating-a-new-ButtonClass-set-the-number-of.patch new file mode 100644 index 0000000..dbe90ce --- /dev/null +++ b/0004-Xi-when-creating-a-new-ButtonClass-set-the-number-of.patch @@ -0,0 +1,37 @@ +From df3c65706eb169d5938df0052059f3e0d5981b74 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Thu, 21 Dec 2023 13:48:10 +1000 +Subject: [PATCH 4/9] Xi: when creating a new ButtonClass, set the number of + buttons + +There's a racy sequence where a master device may copy the button class +from the slave, without ever initializing numButtons. This leads to a +device with zero buttons but a button class which is invalid. + +Let's copy the numButtons value from the source - by definition if we +don't have a button class yet we do not have any other slave devices +with more than this number of buttons anyway. + +CVE-2024-0229, ZDI-CAN-22678 + +This vulnerability was discovered by: +Jan-Niklas Sohn working with Trend Micro Zero Day Initiative +--- + Xi/exevents.c | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/Xi/exevents.c b/Xi/exevents.c +index 54ea11a93..e16171468 100644 +--- a/Xi/exevents.c ++++ b/Xi/exevents.c +@@ -605,6 +605,7 @@ DeepCopyPointerClasses(DeviceIntPtr from, DeviceIntPtr to) + to->button = calloc(1, sizeof(ButtonClassRec)); + if (!to->button) + FatalError("[Xi] no memory for class shift.\n"); ++ to->button->numButtons = from->button->numButtons; + } + else + classes->button = NULL; +-- +2.43.0 + diff --git a/0005-Xi-flush-hierarchy-events-after-adding-removing-mast.patch b/0005-Xi-flush-hierarchy-events-after-adding-removing-mast.patch new file mode 100644 index 0000000..6a21b3c --- /dev/null +++ b/0005-Xi-flush-hierarchy-events-after-adding-removing-mast.patch @@ -0,0 +1,109 @@ +From 4a5e9b1895627d40d26045bd0b7ef3dce503cbd1 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Thu, 4 Jan 2024 10:01:24 +1000 +Subject: [PATCH 5/9] Xi: flush hierarchy events after adding/removing master + devices + +The `XISendDeviceHierarchyEvent()` function allocates space to store up +to `MAXDEVICES` (256) `xXIHierarchyInfo` structures in `info`. + +If a device with a given ID was removed and a new device with the same +ID added both in the same operation, the single device ID will lead to +two info structures being written to `info`. + +Since this case can occur for every device ID at once, a total of two +times `MAXDEVICES` info structures might be written to the allocation. + +To avoid it, once one add/remove master is processed, send out the +device hierarchy event for the current state and continue. That event +thus only ever has exactly one of either added/removed in it (and +optionally slave attached/detached). + +CVE-2024-21885, ZDI-CAN-22744 + +This vulnerability was discovered by: +Jan-Niklas Sohn working with Trend Micro Zero Day Initiative +--- + Xi/xichangehierarchy.c | 27 ++++++++++++++++++++++----- + 1 file changed, 22 insertions(+), 5 deletions(-) + +diff --git a/Xi/xichangehierarchy.c b/Xi/xichangehierarchy.c +index d2d985848..72d00451e 100644 +--- a/Xi/xichangehierarchy.c ++++ b/Xi/xichangehierarchy.c +@@ -416,6 +416,11 @@ ProcXIChangeHierarchy(ClientPtr client) + size_t len; /* length of data remaining in request */ + int rc = Success; + int flags[MAXDEVICES] = { 0 }; ++ enum { ++ NO_CHANGE, ++ FLUSH, ++ CHANGED, ++ } changes = NO_CHANGE; + + REQUEST(xXIChangeHierarchyReq); + REQUEST_AT_LEAST_SIZE(xXIChangeHierarchyReq); +@@ -465,8 +470,9 @@ ProcXIChangeHierarchy(ClientPtr client) + rc = add_master(client, c, flags); + if (rc != Success) + goto unwind; +- } ++ changes = FLUSH; + break; ++ } + case XIRemoveMaster: + { + xXIRemoveMasterInfo *r = (xXIRemoveMasterInfo *) any; +@@ -475,8 +481,9 @@ ProcXIChangeHierarchy(ClientPtr client) + rc = remove_master(client, r, flags); + if (rc != Success) + goto unwind; +- } ++ changes = FLUSH; + break; ++ } + case XIDetachSlave: + { + xXIDetachSlaveInfo *c = (xXIDetachSlaveInfo *) any; +@@ -485,8 +492,9 @@ ProcXIChangeHierarchy(ClientPtr client) + rc = detach_slave(client, c, flags); + if (rc != Success) + goto unwind; +- } ++ changes = CHANGED; + break; ++ } + case XIAttachSlave: + { + xXIAttachSlaveInfo *c = (xXIAttachSlaveInfo *) any; +@@ -495,16 +503,25 @@ ProcXIChangeHierarchy(ClientPtr client) + rc = attach_slave(client, c, flags); + if (rc != Success) + goto unwind; ++ changes = CHANGED; ++ break; + } ++ default: + break; + } + ++ if (changes == FLUSH) { ++ XISendDeviceHierarchyEvent(flags); ++ memset(flags, 0, sizeof(flags)); ++ changes = NO_CHANGE; ++ } ++ + len -= any->length * 4; + any = (xXIAnyHierarchyChangeInfo *) ((char *) any + any->length * 4); + } + + unwind: +- +- XISendDeviceHierarchyEvent(flags); ++ if (changes != NO_CHANGE) ++ XISendDeviceHierarchyEvent(flags); + return rc; + } +-- +2.43.0 + diff --git a/0006-Xi-do-not-keep-linked-list-pointer-during-recursion.patch b/0006-Xi-do-not-keep-linked-list-pointer-during-recursion.patch new file mode 100644 index 0000000..3174635 --- /dev/null +++ b/0006-Xi-do-not-keep-linked-list-pointer-during-recursion.patch @@ -0,0 +1,70 @@ +From bc1fdbe46559dd947674375946bbef54dd0ce36b Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Jos=C3=A9=20Exp=C3=B3sito?= +Date: Fri, 22 Dec 2023 18:28:31 +0100 +Subject: [PATCH 6/9] Xi: do not keep linked list pointer during recursion + +The `DisableDevice()` function is called whenever an enabled device +is disabled and it moves the device from the `inputInfo.devices` linked +list to the `inputInfo.off_devices` linked list. + +However, its link/unlink operation has an issue during the recursive +call to `DisableDevice()` due to the `prev` pointer pointing to a +removed device. + +This issue leads to a length mismatch between the total number of +devices and the number of device in the list, leading to a heap +overflow and, possibly, to local privilege escalation. + +Simplify the code that checked whether the device passed to +`DisableDevice()` was in `inputInfo.devices` or not and find the +previous device after the recursion. + +CVE-2024-21886, ZDI-CAN-22840 + +This vulnerability was discovered by: +Jan-Niklas Sohn working with Trend Micro Zero Day Initiative +--- + dix/devices.c | 15 ++++++++++++--- + 1 file changed, 12 insertions(+), 3 deletions(-) + +diff --git a/dix/devices.c b/dix/devices.c +index dca98c8d1..389d28a23 100644 +--- a/dix/devices.c ++++ b/dix/devices.c +@@ -453,14 +453,20 @@ DisableDevice(DeviceIntPtr dev, BOOL sendevent) + { + DeviceIntPtr *prev, other; + BOOL enabled; ++ BOOL dev_in_devices_list = FALSE; + int flags[MAXDEVICES] = { 0 }; + + if (!dev->enabled) + return TRUE; + +- for (prev = &inputInfo.devices; +- *prev && (*prev != dev); prev = &(*prev)->next); +- if (*prev != dev) ++ for (other = inputInfo.devices; other; other = other->next) { ++ if (other == dev) { ++ dev_in_devices_list = TRUE; ++ break; ++ } ++ } ++ ++ if (!dev_in_devices_list) + return FALSE; + + TouchEndPhysicallyActiveTouches(dev); +@@ -511,6 +517,9 @@ DisableDevice(DeviceIntPtr dev, BOOL sendevent) + LeaveWindow(dev); + SetFocusOut(dev); + ++ for (prev = &inputInfo.devices; ++ *prev && (*prev != dev); prev = &(*prev)->next); ++ + *prev = dev->next; + dev->next = inputInfo.off_devices; + inputInfo.off_devices = dev; +-- +2.43.0 + diff --git a/0007-dix-when-disabling-a-master-float-disabled-slaved-de.patch b/0007-dix-when-disabling-a-master-float-disabled-slaved-de.patch new file mode 100644 index 0000000..32a326a --- /dev/null +++ b/0007-dix-when-disabling-a-master-float-disabled-slaved-de.patch @@ -0,0 +1,53 @@ +From 26769aa71fcbe0a8403b7fb13b7c9010cc07c3a8 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Fri, 5 Jan 2024 09:40:27 +1000 +Subject: [PATCH 7/9] dix: when disabling a master, float disabled slaved + devices too + +Disabling a master device floats all slave devices but we didn't do this +to already-disabled slave devices. As a result those devices kept their +reference to the master device resulting in access to already freed +memory if the master device was removed before the corresponding slave +device. + +And to match this behavior, also forcibly reset that pointer during +CloseDownDevices(). + +Related to CVE-2024-21886, ZDI-CAN-22840 +--- + dix/devices.c | 12 ++++++++++++ + 1 file changed, 12 insertions(+) + +diff --git a/dix/devices.c b/dix/devices.c +index 389d28a23..84a6406d1 100644 +--- a/dix/devices.c ++++ b/dix/devices.c +@@ -483,6 +483,13 @@ DisableDevice(DeviceIntPtr dev, BOOL sendevent) + flags[other->id] |= XISlaveDetached; + } + } ++ ++ for (other = inputInfo.off_devices; other; other = other->next) { ++ if (!IsMaster(other) && GetMaster(other, MASTER_ATTACHED) == dev) { ++ AttachDevice(NULL, other, NULL); ++ flags[other->id] |= XISlaveDetached; ++ } ++ } + } + else { + for (other = inputInfo.devices; other; other = other->next) { +@@ -1088,6 +1095,11 @@ CloseDownDevices(void) + dev->master = NULL; + } + ++ for (dev = inputInfo.off_devices; dev; dev = dev->next) { ++ if (!IsMaster(dev) && !IsFloating(dev)) ++ dev->master = NULL; ++ } ++ + CloseDeviceList(&inputInfo.devices); + CloseDeviceList(&inputInfo.off_devices); + +-- +2.43.0 + diff --git a/0008-glx-Call-XACE-hooks-on-the-GLX-buffer.patch b/0008-glx-Call-XACE-hooks-on-the-GLX-buffer.patch new file mode 100644 index 0000000..0e9e4a0 --- /dev/null +++ b/0008-glx-Call-XACE-hooks-on-the-GLX-buffer.patch @@ -0,0 +1,60 @@ +From e5e8586a12a3ec915673edffa10dc8fe5e15dac3 Mon Sep 17 00:00:00 2001 +From: Olivier Fourdan +Date: Wed, 6 Dec 2023 12:09:41 +0100 +Subject: [PATCH 8/9] glx: Call XACE hooks on the GLX buffer + +The XSELINUX code will label resources at creation by checking the +access mode. When the access mode is DixCreateAccess, it will call the +function to label the new resource SELinuxLabelResource(). + +However, GLX buffers do not go through the XACE hooks when created, +hence leaving the resource actually unlabeled. + +When, later, the client tries to create another resource using that +drawable (like a GC for example), the XSELINUX code would try to use +the security ID of that object which has never been labeled, get a NULL +pointer and crash when checking whether the requested permissions are +granted for subject security ID. + +To avoid the issue, make sure to call the XACE hooks when creating the +GLX buffers. + +Credit goes to Donn Seeley for providing the patch. + +CVE-2024-0408 + +Signed-off-by: Olivier Fourdan +Acked-by: Peter Hutterer +--- + glx/glxcmds.c | 8 ++++++++ + 1 file changed, 8 insertions(+) + +diff --git a/glx/glxcmds.c b/glx/glxcmds.c +index fc26a2e34..1e46d0c72 100644 +--- a/glx/glxcmds.c ++++ b/glx/glxcmds.c +@@ -48,6 +48,7 @@ + #include "indirect_util.h" + #include "protocol-versions.h" + #include "glxvndabi.h" ++#include "xace.h" + + static char GLXServerVendorName[] = "SGI"; + +@@ -1392,6 +1393,13 @@ DoCreatePbuffer(ClientPtr client, int screenNum, XID fbconfigId, + if (!pPixmap) + return BadAlloc; + ++ err = XaceHook(XACE_RESOURCE_ACCESS, client, glxDrawableId, RT_PIXMAP, ++ pPixmap, RT_NONE, NULL, DixCreateAccess); ++ if (err != Success) { ++ (*pGlxScreen->pScreen->DestroyPixmap) (pPixmap); ++ return err; ++ } ++ + /* Assign the pixmap the same id as the pbuffer and add it as a + * resource so it and the DRI2 drawable will be reclaimed when the + * pbuffer is destroyed. */ +-- +2.43.0 + diff --git a/0009-ephyr-xwayland-Use-the-proper-private-key-for-cursor.patch b/0009-ephyr-xwayland-Use-the-proper-private-key-for-cursor.patch new file mode 100644 index 0000000..5fa80fd --- /dev/null +++ b/0009-ephyr-xwayland-Use-the-proper-private-key-for-cursor.patch @@ -0,0 +1,56 @@ +From 2ef0f1116c65d5cb06d7b6d83f8a1aea702c94f7 Mon Sep 17 00:00:00 2001 +From: Olivier Fourdan +Date: Wed, 6 Dec 2023 11:51:56 +0100 +Subject: [PATCH 9/9] ephyr,xwayland: Use the proper private key for cursor + +The cursor in DIX is actually split in two parts, the cursor itself and +the cursor bits, each with their own devPrivates. + +The cursor itself includes the cursor bits, meaning that the cursor bits +devPrivates in within structure of the cursor. + +Both Xephyr and Xwayland were using the private key for the cursor bits +to store the data for the cursor, and when using XSELINUX which comes +with its own special devPrivates, the data stored in that cursor bits' +devPrivates would interfere with the XSELINUX devPrivates data and the +SELINUX security ID would point to some other unrelated data, causing a +crash in the XSELINUX code when trying to (re)use the security ID. + +CVE-2024-0409 + +Signed-off-by: Olivier Fourdan +Reviewed-by: Peter Hutterer +--- + hw/kdrive/ephyr/ephyrcursor.c | 2 +- + hw/xwayland/xwayland-cursor.c | 2 +- + 2 files changed, 2 insertions(+), 2 deletions(-) + +diff --git a/hw/kdrive/ephyr/ephyrcursor.c b/hw/kdrive/ephyr/ephyrcursor.c +index f991899c5..3f192d034 100644 +--- a/hw/kdrive/ephyr/ephyrcursor.c ++++ b/hw/kdrive/ephyr/ephyrcursor.c +@@ -246,7 +246,7 @@ miPointerSpriteFuncRec EphyrPointerSpriteFuncs = { + Bool + ephyrCursorInit(ScreenPtr screen) + { +- if (!dixRegisterPrivateKey(&ephyrCursorPrivateKey, PRIVATE_CURSOR_BITS, ++ if (!dixRegisterPrivateKey(&ephyrCursorPrivateKey, PRIVATE_CURSOR, + sizeof(ephyrCursorRec))) + return FALSE; + +diff --git a/hw/xwayland/xwayland-cursor.c b/hw/xwayland/xwayland-cursor.c +index e3c1aaa50..bd94b0cfb 100644 +--- a/hw/xwayland/xwayland-cursor.c ++++ b/hw/xwayland/xwayland-cursor.c +@@ -431,7 +431,7 @@ static miPointerScreenFuncRec xwl_pointer_screen_funcs = { + Bool + xwl_screen_init_cursor(struct xwl_screen *xwl_screen) + { +- if (!dixRegisterPrivateKey(&xwl_cursor_private_key, PRIVATE_CURSOR_BITS, 0)) ++ if (!dixRegisterPrivateKey(&xwl_cursor_private_key, PRIVATE_CURSOR, 0)) + return FALSE; + + return miPointerInitialize(xwl_screen->screen, +-- +2.43.0 + diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 07a90fa..a30b55b 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 28%{?gitdate:.%{gitdate}}%{?dist} +Release: 29%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org # SPDX License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant @@ -155,7 +155,21 @@ Patch3811: 0002-mi-reset-the-PointerWindows-reference-on-screen-swit.patch Patch3812: 0001-Xi-allocate-enough-XkbActions-for-our-buttons.patch # CVE-2023-6478 Patch3813: 0001-randr-avoid-integer-truncation-in-length-check-of-Pr.patch - +# CVE-2023-6816 +Patch3814: 0001-dix-allocate-enough-space-for-logical-button-maps.patch +# CVE-2024-0229 +Patch3815: 0002-dix-Allocate-sufficient-xEvents-for-our-DeviceStateN.patch +Patch3816: 0003-dix-fix-DeviceStateNotify-event-calculation.patch +Patch3817: 0004-Xi-when-creating-a-new-ButtonClass-set-the-number-of.patch +# CVE-2024-21885 +Patch3818: 0005-Xi-flush-hierarchy-events-after-adding-removing-mast.patch +# CVE-2024-21886 +Patch3819: 0006-Xi-do-not-keep-linked-list-pointer-during-recursion.patch +Patch3820: 0007-dix-when-disabling-a-master-float-disabled-slaved-de.patch +# CVE-2024-0408 +Patch3821: 0008-glx-Call-XACE-hooks-on-the-GLX-buffer.patch +# CVE-2024-0409 +Patch3822: 0009-ephyr-xwayland-Use-the-proper-private-key-for-cursor.patch BuildRequires: make BuildRequires: systemtap-sdt-devel @@ -571,6 +585,10 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Tue Jan 16 2024 José Expósito - 1.20.14-29 +- CVE fix for: CVE-2023-6816, CVE-2024-0229, CVE-2024-21885, CVE-2024-21886, + CVE-2024-0408 and CVE-2024-0409 + * Wed Dec 13 2023 Peter Hutterer - 1.20.14-28 - CVE fix for: CVE-2023-6377, CVE-2023-6478 From 9df532a0270dff0ba124f8363eaa6ad6a314a240 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jos=C3=A9=20Exp=C3=B3sito?= Date: Fri, 19 Jan 2024 11:22:19 +0100 Subject: [PATCH 39/74] Fix use after free related to CVE-2024-21886 --- ...-after-free-in-input-device-shutdown.patch | 77 +++++++++++++++++++ xorg-x11-server.spec | 7 +- 2 files changed, 83 insertions(+), 1 deletion(-) create mode 100644 0001-dix-Fix-use-after-free-in-input-device-shutdown.patch diff --git a/0001-dix-Fix-use-after-free-in-input-device-shutdown.patch b/0001-dix-Fix-use-after-free-in-input-device-shutdown.patch new file mode 100644 index 0000000..c2d723f --- /dev/null +++ b/0001-dix-Fix-use-after-free-in-input-device-shutdown.patch @@ -0,0 +1,77 @@ +From 1801fe0ac3926882d47d7e1ad6c0518a2cdffd41 Mon Sep 17 00:00:00 2001 +From: Povilas Kanapickas +Date: Sun, 19 Dec 2021 18:11:07 +0200 +Subject: [PATCH] dix: Fix use after free in input device shutdown + +This fixes access to freed heap memory via dev->master. E.g. when +running BarrierNotify.ReceivesNotifyEvents/7 test from +xorg-integration-tests: + +==24736==ERROR: AddressSanitizer: heap-use-after-free on address +0x619000065020 at pc 0x55c450e2b9cf bp 0x7fffc532fd20 sp 0x7fffc532fd10 +READ of size 4 at 0x619000065020 thread T0 + #0 0x55c450e2b9ce in GetMaster ../../../dix/devices.c:2722 + #1 0x55c450e9d035 in IsFloating ../../../dix/events.c:346 + #2 0x55c4513209c6 in GetDeviceUse ../../../Xi/xiquerydevice.c:525 +../../../Xi/xichangehierarchy.c:95 + #4 0x55c450e3455c in RemoveDevice ../../../dix/devices.c:1204 +../../../hw/xfree86/common/xf86Xinput.c:1142 + #6 0x55c450e17b04 in CloseDeviceList ../../../dix/devices.c:1038 + #7 0x55c450e1de85 in CloseDownDevices ../../../dix/devices.c:1068 + #8 0x55c450e837ef in dix_main ../../../dix/main.c:302 + #9 0x55c4517a8d93 in main ../../../dix/stubmain.c:34 +(/lib/x86_64-linux-gnu/libc.so.6+0x28564) + #11 0x55c450d0113d in _start (/usr/lib/xorg/Xorg+0x117713d) + +0x619000065020 is located 160 bytes inside of 912-byte region +[0x619000064f80,0x619000065310) +freed by thread T0 here: +(/usr/lib/x86_64-linux-gnu/libasan.so.5+0x10d7cf) + #1 0x55c450e19f1c in CloseDevice ../../../dix/devices.c:1014 + #2 0x55c450e343a4 in RemoveDevice ../../../dix/devices.c:1186 +../../../hw/xfree86/common/xf86Xinput.c:1142 + #4 0x55c450e17b04 in CloseDeviceList ../../../dix/devices.c:1038 + #5 0x55c450e1de85 in CloseDownDevices ../../../dix/devices.c:1068 + #6 0x55c450e837ef in dix_main ../../../dix/main.c:302 + #7 0x55c4517a8d93 in main ../../../dix/stubmain.c:34 +(/lib/x86_64-linux-gnu/libc.so.6+0x28564) + +previously allocated by thread T0 here: +(/usr/lib/x86_64-linux-gnu/libasan.so.5+0x10ddc6) + #1 0x55c450e1c57b in AddInputDevice ../../../dix/devices.c:259 + #2 0x55c450e34840 in AllocDevicePair ../../../dix/devices.c:2755 + #3 0x55c45130318f in add_master ../../../Xi/xichangehierarchy.c:152 +../../../Xi/xichangehierarchy.c:465 + #5 0x55c4512cb9f5 in ProcIDispatch ../../../Xi/extinit.c:390 + #6 0x55c450e6a92b in Dispatch ../../../dix/dispatch.c:551 + #7 0x55c450e834b7 in dix_main ../../../dix/main.c:272 + #8 0x55c4517a8d93 in main ../../../dix/stubmain.c:34 +(/lib/x86_64-linux-gnu/libc.so.6+0x28564) + +The problem is caused by dev->master being not reset when disabling the +device, which then causes dangling pointer when the master device itself +is being deleted when exiting whole server. + +Note that RecalculateMasterButtons() requires dev->master to be still +valid, so we can reset it only at the end of function. + +Signed-off-by: Povilas Kanapickas +--- + dix/devices.c | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/dix/devices.c b/dix/devices.c +index e62c34c55..5f9ce1678 100644 +--- a/dix/devices.c ++++ b/dix/devices.c +@@ -520,6 +520,7 @@ DisableDevice(DeviceIntPtr dev, BOOL sendevent) + } + + RecalculateMasterButtons(dev); ++ dev->master = NULL; + + return TRUE; + } +-- +2.43.0 + diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index a30b55b..81e8f11 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 29%{?gitdate:.%{gitdate}}%{?dist} +Release: 30%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org # SPDX License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant @@ -170,6 +170,8 @@ Patch3820: 0007-dix-when-disabling-a-master-float-disabled-slaved-de.patch Patch3821: 0008-glx-Call-XACE-hooks-on-the-GLX-buffer.patch # CVE-2024-0409 Patch3822: 0009-ephyr-xwayland-Use-the-proper-private-key-for-cursor.patch +# Related to CVE-2024-21886 +Patch3823: 0001-dix-Fix-use-after-free-in-input-device-shutdown.patch BuildRequires: make BuildRequires: systemtap-sdt-devel @@ -585,6 +587,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Fri Jan 19 2024 José Expósito - 1.20.14-30 +- Fix use after free related to CVE-2024-21886 + * Tue Jan 16 2024 José Expósito - 1.20.14-29 - CVE fix for: CVE-2023-6816, CVE-2024-0229, CVE-2024-21885, CVE-2024-21886, CVE-2024-0408 and CVE-2024-0409 From af32bd411c16f7e657aae8ae6ae3a533cf76da5c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jos=C3=A9=20Exp=C3=B3sito?= Date: Mon, 22 Jan 2024 09:25:50 +0100 Subject: [PATCH 40/74] Fix compilation error on i686 --- ...ncompatible-pointer-type-build-error.patch | 54 +++++++++++++++++++ xorg-x11-server.spec | 7 ++- 2 files changed, 60 insertions(+), 1 deletion(-) create mode 100644 0001-ephyr-Fix-incompatible-pointer-type-build-error.patch diff --git a/0001-ephyr-Fix-incompatible-pointer-type-build-error.patch b/0001-ephyr-Fix-incompatible-pointer-type-build-error.patch new file mode 100644 index 0000000..345e660 --- /dev/null +++ b/0001-ephyr-Fix-incompatible-pointer-type-build-error.patch @@ -0,0 +1,54 @@ +From e89edec497bac581ca9b614fb00c25365580f045 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Jos=C3=A9=20Exp=C3=B3sito?= +Date: Fri, 19 Jan 2024 13:05:51 +0100 +Subject: [PATCH] ephyr: Fix incompatible pointer type build error +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Fix a compilation error on 32 bits architectures with gcc 14: + + ephyr_glamor_xv.c: In function ‘ephyr_glamor_xv_init’: + ephyr_glamor_xv.c:154:31: error: assignment to ‘SetPortAttributeFuncPtr’ {aka ‘int (*)(struct _KdScreenInfo *, long unsigned int, int, void *)’} from incompatible pointer type ‘int (*)(KdScreenInfo *, Atom, INT32, void *)’ {aka ‘int (*)(struct _KdScreenInfo *, long unsigned int, long int, void *)’} [-Wincompatible-pointer-types] + 154 | adaptor->SetPortAttribute = ephyr_glamor_xv_set_port_attribute; + | ^ + ephyr_glamor_xv.c:155:31: error: assignment to ‘GetPortAttributeFuncPtr’ {aka ‘int (*)(struct _KdScreenInfo *, long unsigned int, int *, void *)’} from incompatible pointer type ‘int (*)(KdScreenInfo *, Atom, INT32 *, void *)’ {aka ‘int (*)(struct _KdScreenInfo *, long unsigned int, long int *, void *)’} [-Wincompatible-pointer-types] + 155 | adaptor->GetPortAttribute = ephyr_glamor_xv_get_port_attribute; + | ^ + +Build error logs: +https://koji.fedoraproject.org/koji/taskinfo?taskID=111964273 + +Signed-off-by: José Expósito +--- + hw/kdrive/ephyr/ephyr_glamor_xv.c | 8 ++++---- + 1 file changed, 4 insertions(+), 4 deletions(-) + +diff --git a/hw/kdrive/ephyr/ephyr_glamor_xv.c b/hw/kdrive/ephyr/ephyr_glamor_xv.c +index 4dd15cf41..b5eae48c8 100644 +--- a/hw/kdrive/ephyr/ephyr_glamor_xv.c ++++ b/hw/kdrive/ephyr/ephyr_glamor_xv.c +@@ -50,16 +50,16 @@ ephyr_glamor_xv_stop_video(KdScreenInfo *screen, void *data, Bool cleanup) + + static int + ephyr_glamor_xv_set_port_attribute(KdScreenInfo *screen, +- Atom attribute, INT32 value, void *data) ++ Atom attribute, int value, void *data) + { +- return glamor_xv_set_port_attribute(data, attribute, value); ++ return glamor_xv_set_port_attribute(data, attribute, (INT32)value); + } + + static int + ephyr_glamor_xv_get_port_attribute(KdScreenInfo *screen, +- Atom attribute, INT32 *value, void *data) ++ Atom attribute, int *value, void *data) + { +- return glamor_xv_get_port_attribute(data, attribute, value); ++ return glamor_xv_get_port_attribute(data, attribute, (INT32 *)value); + } + + static void +-- +2.43.0 + diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 81e8f11..108cb6f 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 30%{?gitdate:.%{gitdate}}%{?dist} +Release: 31%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org # SPDX License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant @@ -172,6 +172,8 @@ Patch3821: 0008-glx-Call-XACE-hooks-on-the-GLX-buffer.patch Patch3822: 0009-ephyr-xwayland-Use-the-proper-private-key-for-cursor.patch # Related to CVE-2024-21886 Patch3823: 0001-dix-Fix-use-after-free-in-input-device-shutdown.patch +# Fix compilation error on i686 +Patch3824: 0001-ephyr-Fix-incompatible-pointer-type-build-error.patch BuildRequires: make BuildRequires: systemtap-sdt-devel @@ -587,6 +589,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Fri Jan 19 2024 José Expósito - 1.20.14-31 +- Fix compilation error on i686 + * Fri Jan 19 2024 José Expósito - 1.20.14-30 - Fix use after free related to CVE-2024-21886 From 3982aab455824f967ed736ee47f9f24cbf50bf85 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sat, 27 Jan 2024 10:01:05 +0000 Subject: [PATCH 41/74] Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild --- xorg-x11-server.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 108cb6f..d0b2d47 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 31%{?gitdate:.%{gitdate}}%{?dist} +Release: 32%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org # SPDX License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant @@ -589,6 +589,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Sat Jan 27 2024 Fedora Release Engineering - 1.20.14-32 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + * Fri Jan 19 2024 José Expósito - 1.20.14-31 - Fix compilation error on i686 From c88593e07dcdaae526de35cb6a34ffc50d3ba7b9 Mon Sep 17 00:00:00 2001 From: Yaakov Selkowitz Date: Tue, 30 Jan 2024 19:44:53 -0500 Subject: [PATCH 42/74] Apply all CVE patches to RHEL builds Patch 3801 is specific to Fedora, but all the other patches, even those that are newer, should be applied both to Fedora and RHEL (or, possibly in the future, EPEL) builds. --- xorg-x11-server.spec | 58 +++++++++++++++++++++++--------------------- 1 file changed, 30 insertions(+), 28 deletions(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index d0b2d47..7efa161 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -143,38 +143,40 @@ Patch125: xorg-x11-server-fb-access-wrapper.patch # https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/1057 Patch126: 0001-present-Send-a-PresentConfigureNotify-event-for-dest.patch +# CVE-2023-5367 +Patch1010: 0001-Xi-randr-fix-handling-of-PropModeAppend-Prepend.patch +# CVE-2023-5380 +Patch1011: 0002-mi-reset-the-PointerWindows-reference-on-screen-swit.patch +# CVE-2023-6377 +Patch1012: 0001-Xi-allocate-enough-XkbActions-for-our-buttons.patch +# CVE-2023-6478 +Patch1013: 0001-randr-avoid-integer-truncation-in-length-check-of-Pr.patch +# CVE-2023-6816 +Patch1014: 0001-dix-allocate-enough-space-for-logical-button-maps.patch +# CVE-2024-0229 +Patch1015: 0002-dix-Allocate-sufficient-xEvents-for-our-DeviceStateN.patch +Patch1016: 0003-dix-fix-DeviceStateNotify-event-calculation.patch +Patch1017: 0004-Xi-when-creating-a-new-ButtonClass-set-the-number-of.patch +# CVE-2024-21885 +Patch1018: 0005-Xi-flush-hierarchy-events-after-adding-removing-mast.patch +# CVE-2024-21886 +Patch1019: 0006-Xi-do-not-keep-linked-list-pointer-during-recursion.patch +Patch1020: 0007-dix-when-disabling-a-master-float-disabled-slaved-de.patch +# CVE-2024-0408 +Patch1021: 0008-glx-Call-XACE-hooks-on-the-GLX-buffer.patch +# CVE-2024-0409 +Patch1022: 0009-ephyr-xwayland-Use-the-proper-private-key-for-cursor.patch +# Related to CVE-2024-21886 +Patch1023: 0001-dix-Fix-use-after-free-in-input-device-shutdown.patch +# Fix compilation error on i686 +Patch1024: 0001-ephyr-Fix-incompatible-pointer-type-build-error.patch + +## Add new patches above; Fedora-specific patches below + # Only on F38 and later (patch number starts at 3801, see autopatch below) # Upstream commits 73d6e88, f69280dd and 4127776, minus the xwayland.pc.in change Patch3801: 0001-Disallow-byte-swapped-clients-by-default.patch -# CVE-2023-5367 -Patch3810: 0001-Xi-randr-fix-handling-of-PropModeAppend-Prepend.patch -# CVE-2023-5380 -Patch3811: 0002-mi-reset-the-PointerWindows-reference-on-screen-swit.patch -# CVE-2023-6377 -Patch3812: 0001-Xi-allocate-enough-XkbActions-for-our-buttons.patch -# CVE-2023-6478 -Patch3813: 0001-randr-avoid-integer-truncation-in-length-check-of-Pr.patch -# CVE-2023-6816 -Patch3814: 0001-dix-allocate-enough-space-for-logical-button-maps.patch -# CVE-2024-0229 -Patch3815: 0002-dix-Allocate-sufficient-xEvents-for-our-DeviceStateN.patch -Patch3816: 0003-dix-fix-DeviceStateNotify-event-calculation.patch -Patch3817: 0004-Xi-when-creating-a-new-ButtonClass-set-the-number-of.patch -# CVE-2024-21885 -Patch3818: 0005-Xi-flush-hierarchy-events-after-adding-removing-mast.patch -# CVE-2024-21886 -Patch3819: 0006-Xi-do-not-keep-linked-list-pointer-during-recursion.patch -Patch3820: 0007-dix-when-disabling-a-master-float-disabled-slaved-de.patch -# CVE-2024-0408 -Patch3821: 0008-glx-Call-XACE-hooks-on-the-GLX-buffer.patch -# CVE-2024-0409 -Patch3822: 0009-ephyr-xwayland-Use-the-proper-private-key-for-cursor.patch -# Related to CVE-2024-21886 -Patch3823: 0001-dix-Fix-use-after-free-in-input-device-shutdown.patch -# Fix compilation error on i686 -Patch3824: 0001-ephyr-Fix-incompatible-pointer-type-build-error.patch - BuildRequires: make BuildRequires: systemtap-sdt-devel BuildRequires: git-core From 43f6ceeda4e140feff387cb509965a6c32658485 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jos=C3=A9=20Exp=C3=B3sito?= Date: Mon, 4 Mar 2024 15:39:48 +0100 Subject: [PATCH 43/74] Add util-linux as a dependency of Xvfb The xvfb-run command uses getopt, provided by util-linux, but the dependency is not listed. Resolves: https://bugzilla.redhat.com/show_bug.cgi?id=2267450 --- xorg-x11-server.spec | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 7efa161..6976b5f 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 32%{?gitdate:.%{gitdate}}%{?dist} +Release: 33%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org # SPDX License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant @@ -306,6 +306,7 @@ License: MIT and GPLv2 Requires: xorg-x11-server-common >= %{version}-%{release} # required for xvfb-run Requires: xorg-x11-xauth +Requires: util-linux Provides: Xvfb %description Xvfb @@ -591,6 +592,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Mon Mar 04 2024 José Expósito - 1.20.14-33 +- Add util-linux as a dependency of Xvfb + * Sat Jan 27 2024 Fedora Release Engineering - 1.20.14-32 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild From 0ad871b912f6a37727f1034d98c9f9a8a7b8d3a1 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jos=C3=A9=20Exp=C3=B3sito?= Date: Wed, 3 Apr 2024 18:10:41 +0200 Subject: [PATCH 44/74] CVE fix for: CVE-2024-31080, CVE-2024-31081, CVE-2024-31082 and CVE-2024-31083 --- ...ctedEvents-needs-to-use-unswapped-le.patch | 45 +++++++ ...-copy-paste-error-in-the-DeviceState.patch | 33 ++++++ ...GrabDevice-needs-to-use-unswapped-le.patch | 43 +++++++ ...eDRICreatePixmap-needs-to-use-unswap.patch | 47 ++++++++ ...unting-of-glyphs-during-ProcRenderAd.patch | 112 ++++++++++++++++++ xorg-x11-server.spec | 16 ++- 6 files changed, 295 insertions(+), 1 deletion(-) create mode 100644 0001-Xi-ProcXIGetSelectedEvents-needs-to-use-unswapped-le.patch create mode 100644 0001-dix-fix-valuator-copy-paste-error-in-the-DeviceState.patch create mode 100644 0002-Xi-ProcXIPassiveGrabDevice-needs-to-use-unswapped-le.patch create mode 100644 0003-Xquartz-ProcAppleDRICreatePixmap-needs-to-use-unswap.patch create mode 100644 0004-render-fix-refcounting-of-glyphs-during-ProcRenderAd.patch diff --git a/0001-Xi-ProcXIGetSelectedEvents-needs-to-use-unswapped-le.patch b/0001-Xi-ProcXIGetSelectedEvents-needs-to-use-unswapped-le.patch new file mode 100644 index 0000000..5a64c75 --- /dev/null +++ b/0001-Xi-ProcXIGetSelectedEvents-needs-to-use-unswapped-le.patch @@ -0,0 +1,45 @@ +From 96798fc1967491c80a4d0c8d9e0a80586cb2152b Mon Sep 17 00:00:00 2001 +From: Alan Coopersmith +Date: Fri, 22 Mar 2024 18:51:45 -0700 +Subject: [PATCH 1/4] Xi: ProcXIGetSelectedEvents needs to use unswapped length + to send reply + +CVE-2024-31080 + +Reported-by: https://debbugs.gnu.org/cgi/bugreport.cgi?bug=69762 +Fixes: 53e821ab4 ("Xi: add request processing for XIGetSelectedEvents.") +Signed-off-by: Alan Coopersmith +Part-of: +--- + Xi/xiselectev.c | 5 ++++- + 1 file changed, 4 insertions(+), 1 deletion(-) + +diff --git a/Xi/xiselectev.c b/Xi/xiselectev.c +index edcb8a0d3..ac1494987 100644 +--- a/Xi/xiselectev.c ++++ b/Xi/xiselectev.c +@@ -349,6 +349,7 @@ ProcXIGetSelectedEvents(ClientPtr client) + InputClientsPtr others = NULL; + xXIEventMask *evmask = NULL; + DeviceIntPtr dev; ++ uint32_t length; + + REQUEST(xXIGetSelectedEventsReq); + REQUEST_SIZE_MATCH(xXIGetSelectedEventsReq); +@@ -418,10 +419,12 @@ ProcXIGetSelectedEvents(ClientPtr client) + } + } + ++ /* save the value before SRepXIGetSelectedEvents swaps it */ ++ length = reply.length; + WriteReplyToClient(client, sizeof(xXIGetSelectedEventsReply), &reply); + + if (reply.num_masks) +- WriteToClient(client, reply.length * 4, buffer); ++ WriteToClient(client, length * 4, buffer); + + free(buffer); + return Success; +-- +2.44.0 + diff --git a/0001-dix-fix-valuator-copy-paste-error-in-the-DeviceState.patch b/0001-dix-fix-valuator-copy-paste-error-in-the-DeviceState.patch new file mode 100644 index 0000000..363af1f --- /dev/null +++ b/0001-dix-fix-valuator-copy-paste-error-in-the-DeviceState.patch @@ -0,0 +1,33 @@ +From 133e0d651c5d12bf01999d6289e84e224ba77adc Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Mon, 22 Jan 2024 14:22:12 +1000 +Subject: [PATCH] dix: fix valuator copy/paste error in the DeviceStateNotify + event + +Fixes 219c54b8a3337456ce5270ded6a67bcde53553d5 +--- + dix/enterleave.c | 6 +++--- + 1 file changed, 3 insertions(+), 3 deletions(-) + +diff --git a/dix/enterleave.c b/dix/enterleave.c +index 7b7ba1098..c1e6ac600 100644 +--- a/dix/enterleave.c ++++ b/dix/enterleave.c +@@ -619,11 +619,11 @@ FixDeviceValuator(DeviceIntPtr dev, deviceValuator * ev, ValuatorClassPtr v, + ev->first_valuator = first; + switch (ev->num_valuators) { + case 6: +- ev->valuator2 = v->axisVal[first + 5]; ++ ev->valuator5 = v->axisVal[first + 5]; + case 5: +- ev->valuator2 = v->axisVal[first + 4]; ++ ev->valuator4 = v->axisVal[first + 4]; + case 4: +- ev->valuator2 = v->axisVal[first + 3]; ++ ev->valuator3 = v->axisVal[first + 3]; + case 3: + ev->valuator2 = v->axisVal[first + 2]; + case 2: +-- +2.44.0 + diff --git a/0002-Xi-ProcXIPassiveGrabDevice-needs-to-use-unswapped-le.patch b/0002-Xi-ProcXIPassiveGrabDevice-needs-to-use-unswapped-le.patch new file mode 100644 index 0000000..4e061f7 --- /dev/null +++ b/0002-Xi-ProcXIPassiveGrabDevice-needs-to-use-unswapped-le.patch @@ -0,0 +1,43 @@ +From 3e77295f888c67fc7645db5d0c00926a29ffecee Mon Sep 17 00:00:00 2001 +From: Alan Coopersmith +Date: Fri, 22 Mar 2024 18:56:27 -0700 +Subject: [PATCH 2/4] Xi: ProcXIPassiveGrabDevice needs to use unswapped length + to send reply + +CVE-2024-31081 + +Fixes: d220d6907 ("Xi: add GrabButton and GrabKeysym code.") +Signed-off-by: Alan Coopersmith +Part-of: +--- + Xi/xipassivegrab.c | 5 ++++- + 1 file changed, 4 insertions(+), 1 deletion(-) + +diff --git a/Xi/xipassivegrab.c b/Xi/xipassivegrab.c +index c9ac2f855..896233bec 100644 +--- a/Xi/xipassivegrab.c ++++ b/Xi/xipassivegrab.c +@@ -93,6 +93,7 @@ ProcXIPassiveGrabDevice(ClientPtr client) + GrabParameters param; + void *tmp; + int mask_len; ++ uint32_t length; + + REQUEST(xXIPassiveGrabDeviceReq); + REQUEST_FIXED_SIZE(xXIPassiveGrabDeviceReq, +@@ -247,9 +248,11 @@ ProcXIPassiveGrabDevice(ClientPtr client) + } + } + ++ /* save the value before SRepXIPassiveGrabDevice swaps it */ ++ length = rep.length; + WriteReplyToClient(client, sizeof(rep), &rep); + if (rep.num_modifiers) +- WriteToClient(client, rep.length * 4, modifiers_failed); ++ WriteToClient(client, length * 4, modifiers_failed); + + out: + free(modifiers_failed); +-- +2.44.0 + diff --git a/0003-Xquartz-ProcAppleDRICreatePixmap-needs-to-use-unswap.patch b/0003-Xquartz-ProcAppleDRICreatePixmap-needs-to-use-unswap.patch new file mode 100644 index 0000000..df0a498 --- /dev/null +++ b/0003-Xquartz-ProcAppleDRICreatePixmap-needs-to-use-unswap.patch @@ -0,0 +1,47 @@ +From 6c684d035c06fd41c727f0ef0744517580864cef Mon Sep 17 00:00:00 2001 +From: Alan Coopersmith +Date: Fri, 22 Mar 2024 19:07:34 -0700 +Subject: [PATCH 3/4] Xquartz: ProcAppleDRICreatePixmap needs to use unswapped + length to send reply + +CVE-2024-31082 + +Fixes: 14205ade0 ("XQuartz: appledri: Fix byte swapping in replies") +Signed-off-by: Alan Coopersmith +Part-of: +--- + hw/xquartz/xpr/appledri.c | 4 +++- + 1 file changed, 3 insertions(+), 1 deletion(-) + +diff --git a/hw/xquartz/xpr/appledri.c b/hw/xquartz/xpr/appledri.c +index 77574655b..40422b61a 100644 +--- a/hw/xquartz/xpr/appledri.c ++++ b/hw/xquartz/xpr/appledri.c +@@ -272,6 +272,7 @@ ProcAppleDRICreatePixmap(ClientPtr client) + xAppleDRICreatePixmapReply rep; + int width, height, pitch, bpp; + void *ptr; ++ CARD32 stringLength; + + REQUEST_SIZE_MATCH(xAppleDRICreatePixmapReq); + +@@ -307,6 +308,7 @@ ProcAppleDRICreatePixmap(ClientPtr client) + if (sizeof(rep) != sz_xAppleDRICreatePixmapReply) + ErrorF("error sizeof(rep) is %zu\n", sizeof(rep)); + ++ stringLength = rep.stringLength; /* save unswapped value */ + if (client->swapped) { + swaps(&rep.sequenceNumber); + swapl(&rep.length); +@@ -319,7 +321,7 @@ ProcAppleDRICreatePixmap(ClientPtr client) + } + + WriteToClient(client, sizeof(rep), &rep); +- WriteToClient(client, rep.stringLength, path); ++ WriteToClient(client, stringLength, path); + + return Success; + } +-- +2.44.0 + diff --git a/0004-render-fix-refcounting-of-glyphs-during-ProcRenderAd.patch b/0004-render-fix-refcounting-of-glyphs-during-ProcRenderAd.patch new file mode 100644 index 0000000..dcbf337 --- /dev/null +++ b/0004-render-fix-refcounting-of-glyphs-during-ProcRenderAd.patch @@ -0,0 +1,112 @@ +From bdca6c3d1f5057eeb31609b1280fc93237b00c77 Mon Sep 17 00:00:00 2001 +From: Peter Hutterer +Date: Tue, 30 Jan 2024 13:13:35 +1000 +Subject: [PATCH 4/4] render: fix refcounting of glyphs during + ProcRenderAddGlyphs + +Previously, AllocateGlyph would return a new glyph with refcount=0 and a +re-used glyph would end up not changing the refcount at all. The +resulting glyph_new array would thus have multiple entries pointing to +the same non-refcounted glyphs. + +AddGlyph may free a glyph, resulting in a UAF when the same glyph +pointer is then later used. + +Fix this by returning a refcount of 1 for a new glyph and always +incrementing the refcount for a re-used glyph, followed by dropping that +refcount back down again when we're done with it. + +CVE-2024-31083, ZDI-CAN-22880 + +This vulnerability was discovered by: +Jan-Niklas Sohn working with Trend Micro Zero Day Initiative + +Part-of: +--- + render/glyph.c | 5 +++-- + render/glyphstr_priv.h | 1 + + render/render.c | 15 +++++++++++---- + 3 files changed, 15 insertions(+), 6 deletions(-) + +diff --git a/render/glyph.c b/render/glyph.c +index 850ea8440..13991f8a1 100644 +--- a/render/glyph.c ++++ b/render/glyph.c +@@ -245,10 +245,11 @@ FreeGlyphPicture(GlyphPtr glyph) + } + } + +-static void ++void + FreeGlyph(GlyphPtr glyph, int format) + { + CheckDuplicates(&globalGlyphs[format], "FreeGlyph"); ++ BUG_RETURN(glyph->refcnt == 0); + if (--glyph->refcnt == 0) { + GlyphRefPtr gr; + int i; +@@ -354,7 +355,7 @@ AllocateGlyph(xGlyphInfo * gi, int fdepth) + glyph = (GlyphPtr) malloc(size); + if (!glyph) + return 0; +- glyph->refcnt = 0; ++ glyph->refcnt = 1; + glyph->size = size + sizeof(xGlyphInfo); + glyph->info = *gi; + dixInitPrivates(glyph, (char *) glyph + head_size, PRIVATE_GLYPH); +diff --git a/render/glyphstr.h b/render/glyphstr.h +index 2f51bd244..3b1d806d1 100644 +--- a/render/glyphstr.h ++++ b/render/glyphstr.h +@@ -108,6 +108,7 @@ extern Bool + extern GlyphPtr FindGlyph(GlyphSetPtr glyphSet, Glyph id); + + extern GlyphPtr AllocateGlyph(xGlyphInfo * gi, int format); ++extern void FreeGlyph(GlyphPtr glyph, int format); + + extern Bool + ResizeGlyphSet(GlyphSetPtr glyphSet, CARD32 change); +diff --git a/render/render.c b/render/render.c +index 29c5055c6..fe5e37dd9 100644 +--- a/render/render.c ++++ b/render/render.c +@@ -1076,6 +1076,7 @@ ProcRenderAddGlyphs(ClientPtr client) + + if (glyph_new->glyph && glyph_new->glyph != DeletedGlyph) { + glyph_new->found = TRUE; ++ ++glyph_new->glyph->refcnt; + } + else { + GlyphPtr glyph; +@@ -1168,8 +1169,10 @@ ProcRenderAddGlyphs(ClientPtr client) + err = BadAlloc; + goto bail; + } +- for (i = 0; i < nglyphs; i++) ++ for (i = 0; i < nglyphs; i++) { + AddGlyph(glyphSet, glyphs[i].glyph, glyphs[i].id); ++ FreeGlyph(glyphs[i].glyph, glyphSet->fdepth); ++ } + + if (glyphsBase != glyphsLocal) + free(glyphsBase); +@@ -1179,9 +1182,13 @@ ProcRenderAddGlyphs(ClientPtr client) + FreePicture((void *) pSrc, 0); + if (pSrcPix) + FreeScratchPixmapHeader(pSrcPix); +- for (i = 0; i < nglyphs; i++) +- if (glyphs[i].glyph && !glyphs[i].found) +- free(glyphs[i].glyph); ++ for (i = 0; i < nglyphs; i++) { ++ if (glyphs[i].glyph) { ++ --glyphs[i].glyph->refcnt; ++ if (!glyphs[i].found) ++ free(glyphs[i].glyph); ++ } ++ } + if (glyphsBase != glyphsLocal) + free(glyphsBase); + return err; +-- +2.44.0 + diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 6976b5f..8a921eb 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 33%{?gitdate:.%{gitdate}}%{?dist} +Release: 34%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org # SPDX License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant @@ -170,6 +170,16 @@ Patch1022: 0009-ephyr-xwayland-Use-the-proper-private-key-for-cursor.patch Patch1023: 0001-dix-Fix-use-after-free-in-input-device-shutdown.patch # Fix compilation error on i686 Patch1024: 0001-ephyr-Fix-incompatible-pointer-type-build-error.patch +# Fix copy and paste error in CVE-2024-0229 +Patch1025: 0001-dix-fix-valuator-copy-paste-error-in-the-DeviceState.patch +# CVE-2024-31080 +Patch1026: 0001-Xi-ProcXIGetSelectedEvents-needs-to-use-unswapped-le.patch +# CVE-2024-31081 +Patch1027: 0002-Xi-ProcXIPassiveGrabDevice-needs-to-use-unswapped-le.patch +# CVE-2024-31082 +Patch1028: 0003-Xquartz-ProcAppleDRICreatePixmap-needs-to-use-unswap.patch +# CVE-2024-31083 +Patch1029: 0004-render-fix-refcounting-of-glyphs-during-ProcRenderAd.patch ## Add new patches above; Fedora-specific patches below @@ -592,6 +602,10 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Wed Apr 03 2024 José Expósito - 1.20.14-34 +- CVE fix for: CVE-2024-31080, CVE-2024-31081, CVE-2024-31082 and + CVE-2024-31083 + * Mon Mar 04 2024 José Expósito - 1.20.14-33 - Add util-linux as a dependency of Xvfb From 47092bca4f4e0d5a730cdc2bb49f4fb9c8f4528d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jos=C3=A9=20Exp=C3=B3sito?= Date: Wed, 10 Apr 2024 09:56:49 +0200 Subject: [PATCH 45/74] Fix regression caused by the fix for CVE-2024-31083 --- ...sible-double-free-in-ProcRenderAddGl.patch | 72 +++++++++++++++++++ xorg-x11-server.spec | 6 +- 2 files changed, 77 insertions(+), 1 deletion(-) create mode 100644 0001-render-Avoid-possible-double-free-in-ProcRenderAddGl.patch diff --git a/0001-render-Avoid-possible-double-free-in-ProcRenderAddGl.patch b/0001-render-Avoid-possible-double-free-in-ProcRenderAddGl.patch new file mode 100644 index 0000000..549f90a --- /dev/null +++ b/0001-render-Avoid-possible-double-free-in-ProcRenderAddGl.patch @@ -0,0 +1,72 @@ +From 337d8d48b618d4fc0168a7b978be4c3447650b04 Mon Sep 17 00:00:00 2001 +From: Olivier Fourdan +Date: Fri, 5 Apr 2024 15:24:49 +0200 +Subject: [PATCH] render: Avoid possible double-free in ProcRenderAddGlyphs() + +ProcRenderAddGlyphs() adds the glyph to the glyphset using AddGlyph() and +then frees it using FreeGlyph() to decrease the reference count, after +AddGlyph() has increased it. + +AddGlyph() however may chose to reuse an existing glyph if it's already +in the glyphSet, and free the glyph that was given, in which case the +caller function, ProcRenderAddGlyphs() will call FreeGlyph() on an +already freed glyph, as reported by ASan: + + READ of size 4 thread T0 + #0 in FreeGlyph xserver/render/glyph.c:252 + #1 in ProcRenderAddGlyphs xserver/render/render.c:1174 + #2 in Dispatch xserver/dix/dispatch.c:546 + #3 in dix_main xserver/dix/main.c:271 + #4 in main xserver/dix/stubmain.c:34 + #5 in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58 + #6 in __libc_start_main_impl ../csu/libc-start.c:360 + #7 (/usr/bin/Xwayland+0x44fe4) + Address is located 0 bytes inside of 64-byte region + freed by thread T0 here: + #0 in __interceptor_free libsanitizer/asan/asan_malloc_linux.cpp:52 + #1 in _dixFreeObjectWithPrivates xserver/dix/privates.c:538 + #2 in AddGlyph xserver/render/glyph.c:295 + #3 in ProcRenderAddGlyphs xserver/render/render.c:1173 + #4 in Dispatch xserver/dix/dispatch.c:546 + #5 in dix_main xserver/dix/main.c:271 + #6 in main xserver/dix/stubmain.c:34 + #7 in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58 + previously allocated by thread T0 here: + #0 in __interceptor_malloc libsanitizer/asan/asan_malloc_linux.cpp:69 + #1 in AllocateGlyph xserver/render/glyph.c:355 + #2 in ProcRenderAddGlyphs xserver/render/render.c:1085 + #3 in Dispatch xserver/dix/dispatch.c:546 + #4 in dix_main xserver/dix/main.c:271 + #5 in main xserver/dix/stubmain.c:34 + #6 in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58 + SUMMARY: AddressSanitizer: heap-use-after-free xserver/render/glyph.c:252 in FreeGlyph + +To avoid that, make sure not to free the given glyph in AddGlyph(). + +v2: Simplify the test using the boolean returned from AddGlyph() (Michel) +v3: Simplify even more by not freeing the glyph in AddGlyph() (Peter) + +Fixes: bdca6c3d1 - render: fix refcounting of glyphs during ProcRenderAddGlyphs +Closes: https://gitlab.freedesktop.org/xorg/xserver/-/issues/1659 +Signed-off-by: Olivier Fourdan +Part-of: +--- + render/glyph.c | 2 -- + 1 file changed, 2 deletions(-) + +diff --git a/render/glyph.c b/render/glyph.c +index 13991f8a1..5fa7f3b5b 100644 +--- a/render/glyph.c ++++ b/render/glyph.c +@@ -291,8 +291,6 @@ AddGlyph(GlyphSetPtr glyphSet, GlyphPtr glyph, Glyph id) + gr = FindGlyphRef(&globalGlyphs[glyphSet->fdepth], signature, + TRUE, glyph->sha1); + if (gr->glyph && gr->glyph != DeletedGlyph && gr->glyph != glyph) { +- FreeGlyphPicture(glyph); +- dixFreeObjectWithPrivates(glyph, PRIVATE_GLYPH); + glyph = gr->glyph; + } + else if (gr->glyph != glyph) { +-- +2.44.0 + diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 8a921eb..d5cfe46 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 34%{?gitdate:.%{gitdate}}%{?dist} +Release: 35%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org # SPDX License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant @@ -180,6 +180,7 @@ Patch1027: 0002-Xi-ProcXIPassiveGrabDevice-needs-to-use-unswapped-le.patch Patch1028: 0003-Xquartz-ProcAppleDRICreatePixmap-needs-to-use-unswap.patch # CVE-2024-31083 Patch1029: 0004-render-fix-refcounting-of-glyphs-during-ProcRenderAd.patch +Patch1030: 0001-render-Avoid-possible-double-free-in-ProcRenderAddGl.patch ## Add new patches above; Fedora-specific patches below @@ -602,6 +603,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Wed Apr 10 2024 José Expósito - 1.20.14-35 +- Fix regression caused by the fix for CVE-2024-31083 + * Wed Apr 03 2024 José Expósito - 1.20.14-34 - CVE fix for: CVE-2024-31080, CVE-2024-31081, CVE-2024-31082 and CVE-2024-31083 From ef7d64c39f7c4a503fe17f5bcc807def02c42c06 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jos=C3=A9=20Exp=C3=B3sito?= Date: Wed, 8 May 2024 10:01:49 +0200 Subject: [PATCH 46/74] Backport fix for invalid Unicode sequence --- ...artz-Remove-invalid-Unicode-sequence.patch | 30 +++++++++++++++++++ xorg-x11-server.spec | 6 +++- 2 files changed, 35 insertions(+), 1 deletion(-) create mode 100644 0001-xquartz-Remove-invalid-Unicode-sequence.patch diff --git a/0001-xquartz-Remove-invalid-Unicode-sequence.patch b/0001-xquartz-Remove-invalid-Unicode-sequence.patch new file mode 100644 index 0000000..926849e --- /dev/null +++ b/0001-xquartz-Remove-invalid-Unicode-sequence.patch @@ -0,0 +1,30 @@ +From a7ba1e9fe41019296a0f3ddff3d681f77e041ad7 Mon Sep 17 00:00:00 2001 +From: Olivier Fourdan +Date: Tue, 7 May 2024 18:04:02 +0200 +Subject: [PATCH] xquartz: Remove invalid Unicode sequence + +This is flagged by the automatic scanning tools. + +Signed-off-by: Olivier Fourdan +Closes: https://gitlab.freedesktop.org/xorg/xserver/-/issues/1673 +Part-of: +--- + hw/xquartz/bundle/Resources/he.lproj/main.nib/designable.nib | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/hw/xquartz/bundle/Resources/he.lproj/main.nib/designable.nib b/hw/xquartz/bundle/Resources/he.lproj/main.nib/designable.nib +index e56c1adbc..42042a18d 100644 +--- a/hw/xquartz/bundle/Resources/he.lproj/main.nib/designable.nib ++++ b/hw/xquartz/bundle/Resources/he.lproj/main.nib/designable.nib +@@ -438,7 +438,7 @@ + + + +- ++ + + + +-- +2.45.0 + diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index d5cfe46..979899a 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 35%{?gitdate:.%{gitdate}}%{?dist} +Release: 36%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org # SPDX License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant @@ -107,6 +107,7 @@ Patch102: 0001-xf86-Accept-devices-with-the-simpledrm-driver.patch Patch103: 0001-Don-t-hardcode-fps-for-fake-screen.patch Patch104: 0001-hw-Rename-boolean-config-value-field-from-bool-to-bo.patch Patch105: 0001-add-a-quirk-for-apple-silicon.patch +Patch106: 0001-xquartz-Remove-invalid-Unicode-sequence.patch # CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070 Patch110: 0001-xkb-switch-to-array-index-loops-to-moving-pointers.patch @@ -603,6 +604,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Wed Apr 10 2024 José Expósito - 1.20.14-35 +- Backport fix for invalid Unicode sequence + * Wed Apr 10 2024 José Expósito - 1.20.14-35 - Fix regression caused by the fix for CVE-2024-31083 From aa17c8dba19993ef99b01a6cb4fd57494e91b356 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sat, 20 Jul 2024 10:21:44 +0000 Subject: [PATCH 47/74] Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild --- xorg-x11-server.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 979899a..bd5f3e3 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -46,7 +46,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 1.20.14 -Release: 36%{?gitdate:.%{gitdate}}%{?dist} +Release: 37%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org # SPDX License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant @@ -604,6 +604,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Sat Jul 20 2024 Fedora Release Engineering - 1.20.14-37 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild + * Wed Apr 10 2024 José Expósito - 1.20.14-35 - Backport fix for invalid Unicode sequence From 422064e45a4226682c5d5c2904bd3857ea41faec Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?S=C3=A9rgio=20M=2E=20Basto?= Date: Mon, 2 Sep 2024 14:58:29 +0100 Subject: [PATCH 48/74] Update X11-server to 21.1.13 and ABI numbers of videodrv and xinput DMX DDX was dropped 0001-Disallow-byte-swapped-clients-by-default.patch is upstremaed 0001-autobind-GPUs-to-the-screen.patch is upstreamed 0001-xf86-dri2-Use-va_gl-as-vdpau_driver-for-Intel-i965-G.patch updated --- ..._gl-as-vdpau_driver-for-Intel-i965-G.patch | 31 +-- sources | 2 +- xorg-x11-server.spec | 211 +++++------------- 3 files changed, 75 insertions(+), 169 deletions(-) diff --git a/0001-xf86-dri2-Use-va_gl-as-vdpau_driver-for-Intel-i965-G.patch b/0001-xf86-dri2-Use-va_gl-as-vdpau_driver-for-Intel-i965-G.patch index cce0348..2134a44 100644 --- a/0001-xf86-dri2-Use-va_gl-as-vdpau_driver-for-Intel-i965-G.patch +++ b/0001-xf86-dri2-Use-va_gl-as-vdpau_driver-for-Intel-i965-G.patch @@ -52,7 +52,7 @@ index 6619e3aa7..1f8ad14bc 100644 /* For non-PCI devices and drmGetDevice fail, just assume that * the 3D driver is named the same as the kernel driver. This is * currently true for vc4 and msm (freedreno). -@@ -1456,12 +1460,14 @@ dri2_probe_driver_name(ScreenPtr pScreen, DRI2InfoPtr info) +@@ -1454,12 +1458,14 @@ dri2_probe_driver_name(ScreenPtr pScreen, DRI2InfoPtr info) xf86DrvMsg(pScreen->myNum, X_ERROR, "[DRI2] Couldn't drmGetVersion() on non-PCI device, " "no driver name found.\n"); @@ -70,7 +70,7 @@ index 6619e3aa7..1f8ad14bc 100644 } for (i = 0; driver_map[i].driver; i++) { -@@ -1469,13 +1475,15 @@ dri2_probe_driver_name(ScreenPtr pScreen, DRI2InfoPtr info) +@@ -1467,13 +1473,15 @@ dri2_probe_driver_name(ScreenPtr pScreen, DRI2InfoPtr info) continue; if (driver_map[i].num_chips_ids == -1) { @@ -88,7 +88,7 @@ index 6619e3aa7..1f8ad14bc 100644 goto out; } } -@@ -1487,9 +1495,9 @@ dri2_probe_driver_name(ScreenPtr pScreen, DRI2InfoPtr info) +@@ -1485,9 +1493,9 @@ dri2_probe_driver_name(ScreenPtr pScreen, DRI2InfoPtr info) dev->deviceinfo.pci->vendor_id, dev->deviceinfo.pci->device_id); out: drmFreeDevice(&dev); @@ -100,21 +100,21 @@ index 6619e3aa7..1f8ad14bc 100644 #endif } -@@ -1610,7 +1618,8 @@ DRI2ScreenInit(ScreenPtr pScreen, DRI2InfoPtr info) - if (info->driverName) { - ds->driverNames[0] = info->driverName; +@@ -1604,7 +1612,8 @@ DRI2ScreenInit(ScreenPtr pScreen, DRI2InfoPtr info) } else { + /* FIXME dri2_probe_driver_name() returns a strdup-ed string, + * currently this gets leaked */ - ds->driverNames[0] = ds->driverNames[1] = dri2_probe_driver_name(pScreen, info); + dri2_probe_driver_name(pScreen, info, + &ds->driverNames[0], &ds->driverNames[1]); if (!ds->driverNames[0]) return FALSE; - } + diff --git a/hw/xfree86/dri2/pci_ids/pci_id_driver_map.h b/hw/xfree86/dri2/pci_ids/pci_id_driver_map.h index da7ea1c1e..7036d1003 100644 --- a/hw/xfree86/dri2/pci_ids/pci_id_driver_map.h +++ b/hw/xfree86/dri2/pci_ids/pci_id_driver_map.h -@@ -66,21 +66,22 @@ static const int vmwgfx_chip_ids[] = { +@@ -60,23 +60,24 @@ static const int vmwgfx_chip_ids[] = { static const struct { int vendor_id; const char *driver; @@ -124,8 +124,10 @@ index da7ea1c1e..7036d1003 100644 } driver_map[] = { - { 0x8086, "i915", i915_chip_ids, ARRAY_SIZE(i915_chip_ids) }, - { 0x8086, "i965", i965_chip_ids, ARRAY_SIZE(i965_chip_ids) }, +- { 0x8086, "i965", NULL, -1 }, + { 0x8086, "i915", "i915", i915_chip_ids, ARRAY_SIZE(i915_chip_ids) }, + { 0x8086, "i965", "va_gl", i965_chip_ids, ARRAY_SIZE(i965_chip_ids) }, ++ { 0x8086, "i965", "va_gl", NULL, -1 }, #ifndef DRIVER_MAP_GALLIUM_ONLY - { 0x1002, "radeon", r100_chip_ids, ARRAY_SIZE(r100_chip_ids) }, - { 0x1002, "r200", r200_chip_ids, ARRAY_SIZE(r200_chip_ids) }, @@ -134,19 +136,18 @@ index da7ea1c1e..7036d1003 100644 #endif - { 0x1002, "r300", r300_chip_ids, ARRAY_SIZE(r300_chip_ids) }, - { 0x1002, "r600", r600_chip_ids, ARRAY_SIZE(r600_chip_ids) }, -- { 0x1002, "radeonsi", radeonsi_chip_ids, ARRAY_SIZE(radeonsi_chip_ids) }, +- { 0x1002, "radeonsi", NULL, -1 }, - { 0x10de, "nouveau", NULL, -1 }, - { 0x1af4, "virtio_gpu", virtio_gpu_chip_ids, ARRAY_SIZE(virtio_gpu_chip_ids) }, - { 0x15ad, "vmwgfx", vmwgfx_chip_ids, ARRAY_SIZE(vmwgfx_chip_ids) }, +- { 0x0000, NULL, NULL, 0 }, + { 0x1002, "r300", "r300", r300_chip_ids, ARRAY_SIZE(r300_chip_ids) }, -+ { 0x1002, "r600","r600", r600_chip_ids, ARRAY_SIZE(r600_chip_ids) }, -+ { 0x1002, "radeonsi", "radeonsi", radeonsi_chip_ids, ARRAY_SIZE(radeonsi_chip_ids) }, ++ { 0x1002, "r600", "r600", r600_chip_ids, ARRAY_SIZE(r600_chip_ids) }, ++ { 0x1002, "radeonsi", "radeonsi", NULL, -1 }, + { 0x10de, "nouveau", "nouveau", NULL, -1 }, + { 0x1af4, "virtio_gpu", "virtio_gpu", virtio_gpu_chip_ids, ARRAY_SIZE(virtio_gpu_chip_ids) }, + { 0x15ad, "vmwgfx", "vmwgfx", vmwgfx_chip_ids, ARRAY_SIZE(vmwgfx_chip_ids) }, - { 0x0000, NULL, NULL, 0 }, ++ { 0x0000, NULL, NULL, NULL, 0 }, }; --- -2.19.0 - + #endif /* _PCI_ID_DRIVER_MAP_H_ */ diff --git a/sources b/sources index 32cd6fa..475e678 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (xorg-server-1.20.14.tar.xz) = be3dc32cce7d55d7e38c5f6557027f13f39224c76cc83e5800555d5ce89dbdc3731773a2d186a5b97db9fc8731a2b2dd6e9829af2b01ee2559246d4aef7c4963 +SHA512 (xorg-server-21.1.13.tar.xz) = a55fbeeed227c12c67f166f2c06a7f4f8d78feeea04c6e73509dbc723185fd0772349aa23f7c44cf0828ac0a0e2f9e4b26cffb220e6dfa7186d60f88b25ccaf1 diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index bd5f3e3..01c5b1f 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -20,10 +20,10 @@ # source because rpm is a terrible language. %global ansic_major 0 %global ansic_minor 4 -%global videodrv_major 24 -%global videodrv_minor 1 +%global videodrv_major 25 +%global videodrv_minor 2 %global xinput_major 24 -%global xinput_minor 1 +%global xinput_minor 4 %global extension_major 10 %global extension_minor 0 %endif @@ -45,8 +45,8 @@ Summary: X.Org X11 X server Name: xorg-x11-server -Version: 1.20.14 -Release: 37%{?gitdate:.%{gitdate}}%{?dist} +Version: 21.1.13 +Release: 1%{?gitdate:.%{gitdate}}%{?dist} URL: http://www.x.org # SPDX License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant @@ -85,9 +85,6 @@ Patch2: 0001-xfree86-use-modesetting-driver-by-default-on-GeForce.patch # va_gl should probably just be the default everywhere ? Patch3: 0001-xf86-dri2-Use-va_gl-as-vdpau_driver-for-Intel-i965-G.patch -# Submitted upstream, but not going anywhere -Patch5: 0001-autobind-GPUs-to-the-screen.patch - # because the display-managers are not ready yet, do not upstream Patch6: 0001-Fedora-hack-Make-the-suid-root-wrapper-always-start-.patch @@ -97,129 +94,60 @@ Patch6: 0001-Fedora-hack-Make-the-suid-root-wrapper-always-start-.patch # https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/1001` Patch7: 0001-configure.ac-search-for-the-fontrootdir-ourselves.patch -# Backports from current stable "server-1.20-branch": +# Backports from current stable "server-21.1-branch": # -# Backports from "master" upstream: -Patch100: 0001-present-Check-for-NULL-to-prevent-crash.patch -Patch101: 0001-render-Fix-build-with-gcc-12.patch -Patch102: 0001-xf86-Accept-devices-with-the-simpledrm-driver.patch -Patch103: 0001-Don-t-hardcode-fps-for-fake-screen.patch -Patch104: 0001-hw-Rename-boolean-config-value-field-from-bool-to-bo.patch -Patch105: 0001-add-a-quirk-for-apple-silicon.patch -Patch106: 0001-xquartz-Remove-invalid-Unicode-sequence.patch - -# CVE-2022-2319/ZDI-CAN-16062, CVE-2022-2320/ZDI-CAN-16070 -Patch110: 0001-xkb-switch-to-array-index-loops-to-moving-pointers.patch -Patch111: 0002-xkb-swap-XkbSetDeviceInfo-and-XkbSetDeviceInfoCheck.patch -Patch112: 0003-xkb-add-request-length-validation-for-XkbSetGeometry.patch - -# CVE-2022-3550 -Patch113: 0001-xkb-proof-GetCountedString-against-request-length-at.patch -# CVE-2022-3551 -Patch114: 0001-xkb-fix-some-possible-memleaks-in-XkbGetKbdByName.patch - -# CVE-2022-46340 -Patch115: 0001-Xtest-disallow-GenericEvents-in-XTestSwapFakeInput.patch -# related to CVE-2022-46344 -Patch116: 0002-Xi-return-an-error-from-XI-property-changes-if-verif.patch -# CVE-2022-46344 -Patch117: 0003-Xi-avoid-integer-truncation-in-length-check-of-ProcX.patch -# CVE-2022-46341 -Patch118: 0004-Xi-disallow-passive-grabs-with-a-detail-255.patch -# CVE-2022-46343 -Patch119: 0005-Xext-free-the-screen-saver-resource-when-replacing-i.patch -# CVE-2022-46342 -Patch120: 0006-Xext-free-the-XvRTVideoNotify-when-turning-off-from-.patch -# CVE-2022-46283 -Patch121: 0007-xkb-reset-the-radio_groups-pointer-to-NULL-after-fre.patch -# Fix for buggy patch to CVE-2022-46340 -Patch122: 0008-Xext-fix-invalid-event-type-mask-in-XTestSwapFakeInp.patch -# CVE-2023-0494 -Patch123: 0001-Xi-fix-potential-use-after-free-in-DeepCopyPointerCl.patch -# CVE-2023-1393 -Patch124: 0001-composite-Fix-use-after-free-of-the-COW.patch -# https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/1114 -Patch125: xorg-x11-server-fb-access-wrapper.patch -# https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/1057 -Patch126: 0001-present-Send-a-PresentConfigureNotify-event-for-dest.patch - -# CVE-2023-5367 -Patch1010: 0001-Xi-randr-fix-handling-of-PropModeAppend-Prepend.patch -# CVE-2023-5380 -Patch1011: 0002-mi-reset-the-PointerWindows-reference-on-screen-swit.patch -# CVE-2023-6377 -Patch1012: 0001-Xi-allocate-enough-XkbActions-for-our-buttons.patch -# CVE-2023-6478 -Patch1013: 0001-randr-avoid-integer-truncation-in-length-check-of-Pr.patch -# CVE-2023-6816 -Patch1014: 0001-dix-allocate-enough-space-for-logical-button-maps.patch -# CVE-2024-0229 -Patch1015: 0002-dix-Allocate-sufficient-xEvents-for-our-DeviceStateN.patch -Patch1016: 0003-dix-fix-DeviceStateNotify-event-calculation.patch -Patch1017: 0004-Xi-when-creating-a-new-ButtonClass-set-the-number-of.patch -# CVE-2024-21885 -Patch1018: 0005-Xi-flush-hierarchy-events-after-adding-removing-mast.patch -# CVE-2024-21886 -Patch1019: 0006-Xi-do-not-keep-linked-list-pointer-during-recursion.patch -Patch1020: 0007-dix-when-disabling-a-master-float-disabled-slaved-de.patch -# CVE-2024-0408 -Patch1021: 0008-glx-Call-XACE-hooks-on-the-GLX-buffer.patch -# CVE-2024-0409 -Patch1022: 0009-ephyr-xwayland-Use-the-proper-private-key-for-cursor.patch -# Related to CVE-2024-21886 -Patch1023: 0001-dix-Fix-use-after-free-in-input-device-shutdown.patch # Fix compilation error on i686 +# https://gitlab.freedesktop.org/xorg/xserver/-/commit/8407181c7dfe14086d99697af0b86120320ab73e Patch1024: 0001-ephyr-Fix-incompatible-pointer-type-build-error.patch -# Fix copy and paste error in CVE-2024-0229 -Patch1025: 0001-dix-fix-valuator-copy-paste-error-in-the-DeviceState.patch -# CVE-2024-31080 -Patch1026: 0001-Xi-ProcXIGetSelectedEvents-needs-to-use-unswapped-le.patch -# CVE-2024-31081 -Patch1027: 0002-Xi-ProcXIPassiveGrabDevice-needs-to-use-unswapped-le.patch -# CVE-2024-31082 -Patch1028: 0003-Xquartz-ProcAppleDRICreatePixmap-needs-to-use-unswap.patch -# CVE-2024-31083 -Patch1029: 0004-render-fix-refcounting-of-glyphs-during-ProcRenderAd.patch -Patch1030: 0001-render-Avoid-possible-double-free-in-ProcRenderAddGl.patch ## Add new patches above; Fedora-specific patches below -# Only on F38 and later (patch number starts at 3801, see autopatch below) -# Upstream commits 73d6e88, f69280dd and 4127776, minus the xwayland.pc.in change -Patch3801: 0001-Disallow-byte-swapped-clients-by-default.patch BuildRequires: make BuildRequires: systemtap-sdt-devel BuildRequires: git-core -BuildRequires: automake autoconf libtool pkgconfig +BuildRequires: automake +BuildRequires: autoconf +BuildRequires: libtool +BuildRequires: pkgconfig BuildRequires: xorg-x11-util-macros >= 1.17 BuildRequires: xorg-x11-proto-devel >= 7.7-10 -BuildRequires: dbus-devel libepoxy-devel systemd-devel +BuildRequires: dbus-devel +BuildRequires: libepoxy-devel +BuildRequires: systemd-devel BuildRequires: xorg-x11-xtrans-devel >= 1.3.2 -BuildRequires: libXfont2-devel libXau-devel libxkbfile-devel libXres-devel -BuildRequires: libfontenc-devel libXtst-devel libXdmcp-devel -BuildRequires: libX11-devel libXext-devel -BuildRequires: libXinerama-devel libXi-devel - -# DMX config utils buildreqs. -BuildRequires: libXt-devel libdmx-devel libXmu-devel libXrender-devel -BuildRequires: libXi-devel libXpm-devel libXaw-devel libXfixes-devel +BuildRequires: libXfont2-devel +BuildRequires: libXau-devel +BuildRequires: libxkbfile-devel +BuildRequires: libXres-devel +BuildRequires: libfontenc-devel +BuildRequires: libXtst-devel +BuildRequires: libXdmcp-devel +BuildRequires: libX11-devel +BuildRequires: libXext-devel +BuildRequires: libXinerama-devel +BuildRequires: libXi-devel BuildRequires: pkgconfig(epoxy) BuildRequires: pkgconfig(xshmfence) >= 1.1 BuildRequires: libXv-devel BuildRequires: pixman-devel >= 0.30.0 -BuildRequires: libpciaccess-devel >= 0.13.1 openssl-devel bison flex +BuildRequires: libpciaccess-devel >= 0.13.1 +BuildRequires: openssl-devel +BuildRequires: bison +BuildRequires: flex BuildRequires: mesa-libGL-devel >= 9.2 BuildRequires: mesa-libEGL-devel BuildRequires: mesa-libgbm-devel # XXX silly... -BuildRequires: libdrm-devel >= 2.4.0 kernel-headers +BuildRequires: libdrm-devel >= 2.4.0 +BuildRequires: kernel-headers -BuildRequires: audit-libs-devel libselinux-devel >= 2.0.86-1 +BuildRequires: audit-libs-devel +BuildRequires: libselinux-devel >= 2.0.86-1 BuildRequires: libudev-devel # libunwind is Exclusive for the following arches %ifarch aarch64 %{arm} hppa ia64 mips ppc ppc64 %{ix86} x86_64 @@ -228,8 +156,12 @@ BuildRequires: libunwind-devel %endif %endif -BuildRequires: pkgconfig(xcb-aux) pkgconfig(xcb-image) pkgconfig(xcb-icccm) -BuildRequires: pkgconfig(xcb-keysyms) pkgconfig(xcb-renderutil) +BuildRequires: pkgconfig(xcb-aux) +BuildRequires: pkgconfig(xcb-image) +BuildRequires: pkgconfig(xcb-icccm) +BuildRequires: pkgconfig(xcb-keysyms) +BuildRequires: pkgconfig(xcb-renderutil) +BuildRequires: pkgconfig(libxcvt) %description X.Org X11 X server @@ -269,6 +201,9 @@ Obsoletes: xorg-x11-drv-modesetting < %{version}-%{release} Provides: xorg-x11-drv-modesetting = %{version}-%{release} # Dropped from F25 Obsoletes: xorg-x11-drv-vmmouse < 13.1.0-4 +# Dropped from xorg-x11-server-21.1 +# https://gitlab.freedesktop.org/xorg/xserver/-/commit/b3b81c8c2090cd49410960a021baf0d27fdd2ab3 +Obsoletes: xorg-x11-server-Xdmx < 1.20.15 Requires: xorg-x11-server-common >= %{version}-%{release} Requires: system-setup-keyboard @@ -295,22 +230,6 @@ is a very useful tool for developers who wish to test their applications without running them on their real X server. -%package Xdmx -Summary: Distributed Multihead X Server and utilities -Requires: xorg-x11-server-common >= %{version}-%{release} -Provides: Xdmx - -%description Xdmx -Xdmx is proxy X server that provides multi-head support for multiple displays -attached to different machines (each of which is running a typical X server). -When Xinerama is used with Xdmx, the multiple displays on multiple machines -are presented to the user as a single unified screen. A simple application -for Xdmx would be to provide multi-head support using two desktop machines, -each of which has a single display device attached to it. A complex -application for Xdmx would be to unify a 4 by 4 grid of 1280x1024 displays -(each attached to one of 16 computers) into a unified 5120x4096 display. - - %package Xvfb Summary: A X Windows System virtual framebuffer X server # xvfb-run is GPLv2, rest is MIT @@ -374,14 +293,11 @@ Xserver source code needed to build VNC server (Xvnc) %autosetup -N -n %{pkgname}-%{?gitdate:%{gitdate}}%{!?gitdate:%{version}} rm -rf .git cp %{SOURCE1} .gitignore +%global _default_patch_flags -f # ick -%global __scm git -%{expand:%__scm_setup_git -q} -%if 0%{?fedora} >= 38 -%autopatch -%else -%autopatch -M 3800 -%endif +#%%global __scm git +#%%{expand:%%__scm_setup_git -q} +%autopatch -p1 %if 0%{?stable_abi} # check the ABI in the source against what we expect. @@ -484,7 +400,7 @@ mkdir -p %{inst_srcdir}/{hw/dmx/doc,man,doc,hw/dmx/doxygen} cp {,%{inst_srcdir}/}hw/xquartz/bundle/cpprules.in cp {,%{inst_srcdir}/}man/Xserver.man cp {,%{inst_srcdir}/}doc/smartsched -cp {,%{inst_srcdir}/}hw/dmx/doxygen/doxygen.conf.in +#cp {,%{inst_srcdir}/}hw/dmx/doxygen/doxygen.conf.in cp {,%{inst_srcdir}/}xserver.ent.in cp {,%{inst_srcdir}/}hw/xfree86/Xorg.sh.in cp xkb/README.compiled %{inst_srcdir}/xkb @@ -524,7 +440,6 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %{_bindir}/Xorg %{_libexecdir}/Xorg %{Xorgperms} %{_libexecdir}/Xorg.wrap -%{_bindir}/cvt %{_bindir}/gtf %dir %{_libdir}/xorg %dir %{_libdir}/xorg/modules @@ -533,9 +448,10 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %dir %{_libdir}/xorg/modules/extensions %{_libdir}/xorg/modules/extensions/libglx.so %dir %{_libdir}/xorg/modules/input +%{_libdir}/xorg/modules/input/inputtest_drv.so %{_libdir}/xorg/modules/libfbdevhw.so %{_libdir}/xorg/modules/libexa.so -%{_libdir}/xorg/modules/libfb.so +#%%{_libdir}/xorg/modules/libfb.so %{_libdir}/xorg/modules/libglamoregl.so %{_libdir}/xorg/modules/libshadow.so %{_libdir}/xorg/modules/libshadowfb.so @@ -543,14 +459,14 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %{_libdir}/xorg/modules/libwfb.so %if %{defined int10_arch} %{_libdir}/xorg/modules/libint10.so -%{_libdir}/xorg/modules/libvbe.so +#%%{_libdir}/xorg/modules/libvbe.so %endif %{_mandir}/man1/gtf.1* %{_mandir}/man1/Xorg.1* %{_mandir}/man1/Xorg.wrap.1* -%{_mandir}/man1/cvt.1* %{_mandir}/man4/fbdevhw.4* %{_mandir}/man4/exa.4* +%{_mandir}/man4//inputtestdrv.4* %{_mandir}/man4/modesetting.4* %{_mandir}/man5/Xwrapper.config.5* %{_mandir}/man5/xorg.conf.5* @@ -563,24 +479,6 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %{_bindir}/Xnest %{_mandir}/man1/Xnest.1* -%files Xdmx -%{_bindir}/Xdmx -%{_bindir}/dmxaddinput -%{_bindir}/dmxaddscreen -%{_bindir}/dmxreconfig -%{_bindir}/dmxresize -%{_bindir}/dmxrminput -%{_bindir}/dmxrmscreen -%{_bindir}/dmxtodmx -%{_bindir}/dmxwininfo -%{_bindir}/vdltodmx -%{_bindir}/dmxinfo -%{_bindir}/xdmxconfig -%{_mandir}/man1/Xdmx.1* -%{_mandir}/man1/dmxtodmx.1* -%{_mandir}/man1/vdltodmx.1* -%{_mandir}/man1/xdmxconfig.1* - %files Xvfb %{_bindir}/Xvfb %{_bindir}/xvfb-run @@ -604,6 +502,13 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Mon Sep 02 2024 Sérgio Basto - 21.1.13-1 +- Update X11-server to 21.1.13 and ABI numbers of videodrv and xinput +- DMX DDX was dropped +- 0001-Disallow-byte-swapped-clients-by-default.patch is upstreamed +- 0001-autobind-GPUs-to-the-screen.patch is upstreamed +- 0001-xf86-dri2-Use-va_gl-as-vdpau_driver-for-Intel-i965-G.patch updated + * Sat Jul 20 2024 Fedora Release Engineering - 1.20.14-37 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild From 72accf2c5acec0be38e8a7dfb48c37299dceb728 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?S=C3=A9rgio=20M=2E=20Basto?= Date: Wed, 17 Jul 2024 18:08:52 +0100 Subject: [PATCH 49/74] Remove unused patches with fedpkg unused-patches --- ...llow-byte-swapped-clients-by-default.patch | 272 ---------------- 0001-Don-t-hardcode-fps-for-fake-screen.patch | 135 -------- ...ctedEvents-needs-to-use-unswapped-le.patch | 45 --- ...te-enough-XkbActions-for-our-buttons.patch | 77 ----- ...-use-after-free-in-DeepCopyPointerCl.patch | 35 --- ...x-handling-of-PropModeAppend-Prepend.patch | 80 ----- ...-GenericEvents-in-XTestSwapFakeInput.patch | 52 ---- 0001-add-a-quirk-for-apple-silicon.patch | 30 -- 0001-autobind-GPUs-to-the-screen.patch | 293 ------------------ ...posite-Fix-use-after-free-of-the-COW.patch | 42 --- ...-after-free-in-input-device-shutdown.patch | 77 ----- ...enough-space-for-logical-button-maps.patch | 51 --- ...-copy-paste-error-in-the-DeviceState.patch | 33 -- ...n-config-value-field-from-bool-to-bo.patch | 154 --------- ...sent-Check-for-NULL-to-prevent-crash.patch | 43 --- ...resentConfigureNotify-event-for-dest.patch | 105 ------- ...ger-truncation-in-length-check-of-Pr.patch | 61 ---- ...sible-double-free-in-ProcRenderAddGl.patch | 72 ----- 0001-render-Fix-build-with-gcc-12.patch | 90 ------ ...pt-devices-with-the-simpledrm-driver.patch | 34 -- ...possible-memleaks-in-XkbGetKbdByName.patch | 59 ---- ...ntedString-against-request-length-at.patch | 35 --- ...array-index-loops-to-moving-pointers.patch | 76 ----- ...GrabDevice-needs-to-use-unswapped-le.patch | 43 --- ...or-from-XI-property-changes-if-verif.patch | 41 --- ...ficient-xEvents-for-our-DeviceStateN.patch | 84 ----- ...nterWindows-reference-on-screen-swit.patch | 99 ------ ...DeviceInfo-and-XkbSetDeviceInfoCheck.patch | 179 ----------- ...-truncation-in-length-check-of-ProcX.patch | 71 ----- ...eDRICreatePixmap-needs-to-use-unswap.patch | 47 --- ...-DeviceStateNotify-event-calculation.patch | 217 ------------- ...length-validation-for-XkbSetGeometry.patch | 182 ----------- ...llow-passive-grabs-with-a-detail-255.patch | 82 ----- ...-a-new-ButtonClass-set-the-number-of.patch | 37 --- ...unting-of-glyphs-during-ProcRenderAd.patch | 112 ------- ...reen-saver-resource-when-replacing-i.patch | 48 --- ...hy-events-after-adding-removing-mast.patch | 109 ------- ...RTVideoNotify-when-turning-off-from-.patch | 74 ----- ...linked-list-pointer-during-recursion.patch | 70 ----- ...ng-a-master-float-disabled-slaved-de.patch | 53 ---- ...dio_groups-pointer-to-NULL-after-fre.patch | 36 --- ...-event-type-mask-in-XTestSwapFakeInp.patch | 35 --- ...lx-Call-XACE-hooks-on-the-GLX-buffer.patch | 60 ---- ...se-the-proper-private-key-for-cursor.patch | 56 ---- xorg-x11-server-fb-access-wrapper.patch | 31 -- 45 files changed, 3717 deletions(-) delete mode 100644 0001-Disallow-byte-swapped-clients-by-default.patch delete mode 100644 0001-Don-t-hardcode-fps-for-fake-screen.patch delete mode 100644 0001-Xi-ProcXIGetSelectedEvents-needs-to-use-unswapped-le.patch delete mode 100644 0001-Xi-allocate-enough-XkbActions-for-our-buttons.patch delete mode 100644 0001-Xi-fix-potential-use-after-free-in-DeepCopyPointerCl.patch delete mode 100644 0001-Xi-randr-fix-handling-of-PropModeAppend-Prepend.patch delete mode 100644 0001-Xtest-disallow-GenericEvents-in-XTestSwapFakeInput.patch delete mode 100644 0001-add-a-quirk-for-apple-silicon.patch delete mode 100644 0001-autobind-GPUs-to-the-screen.patch delete mode 100644 0001-composite-Fix-use-after-free-of-the-COW.patch delete mode 100644 0001-dix-Fix-use-after-free-in-input-device-shutdown.patch delete mode 100644 0001-dix-allocate-enough-space-for-logical-button-maps.patch delete mode 100644 0001-dix-fix-valuator-copy-paste-error-in-the-DeviceState.patch delete mode 100644 0001-hw-Rename-boolean-config-value-field-from-bool-to-bo.patch delete mode 100644 0001-present-Check-for-NULL-to-prevent-crash.patch delete mode 100644 0001-present-Send-a-PresentConfigureNotify-event-for-dest.patch delete mode 100644 0001-randr-avoid-integer-truncation-in-length-check-of-Pr.patch delete mode 100644 0001-render-Avoid-possible-double-free-in-ProcRenderAddGl.patch delete mode 100644 0001-render-Fix-build-with-gcc-12.patch delete mode 100644 0001-xf86-Accept-devices-with-the-simpledrm-driver.patch delete mode 100644 0001-xkb-fix-some-possible-memleaks-in-XkbGetKbdByName.patch delete mode 100644 0001-xkb-proof-GetCountedString-against-request-length-at.patch delete mode 100644 0001-xkb-switch-to-array-index-loops-to-moving-pointers.patch delete mode 100644 0002-Xi-ProcXIPassiveGrabDevice-needs-to-use-unswapped-le.patch delete mode 100644 0002-Xi-return-an-error-from-XI-property-changes-if-verif.patch delete mode 100644 0002-dix-Allocate-sufficient-xEvents-for-our-DeviceStateN.patch delete mode 100644 0002-mi-reset-the-PointerWindows-reference-on-screen-swit.patch delete mode 100644 0002-xkb-swap-XkbSetDeviceInfo-and-XkbSetDeviceInfoCheck.patch delete mode 100644 0003-Xi-avoid-integer-truncation-in-length-check-of-ProcX.patch delete mode 100644 0003-Xquartz-ProcAppleDRICreatePixmap-needs-to-use-unswap.patch delete mode 100644 0003-dix-fix-DeviceStateNotify-event-calculation.patch delete mode 100644 0003-xkb-add-request-length-validation-for-XkbSetGeometry.patch delete mode 100644 0004-Xi-disallow-passive-grabs-with-a-detail-255.patch delete mode 100644 0004-Xi-when-creating-a-new-ButtonClass-set-the-number-of.patch delete mode 100644 0004-render-fix-refcounting-of-glyphs-during-ProcRenderAd.patch delete mode 100644 0005-Xext-free-the-screen-saver-resource-when-replacing-i.patch delete mode 100644 0005-Xi-flush-hierarchy-events-after-adding-removing-mast.patch delete mode 100644 0006-Xext-free-the-XvRTVideoNotify-when-turning-off-from-.patch delete mode 100644 0006-Xi-do-not-keep-linked-list-pointer-during-recursion.patch delete mode 100644 0007-dix-when-disabling-a-master-float-disabled-slaved-de.patch delete mode 100644 0007-xkb-reset-the-radio_groups-pointer-to-NULL-after-fre.patch delete mode 100644 0008-Xext-fix-invalid-event-type-mask-in-XTestSwapFakeInp.patch delete mode 100644 0008-glx-Call-XACE-hooks-on-the-GLX-buffer.patch delete mode 100644 0009-ephyr-xwayland-Use-the-proper-private-key-for-cursor.patch delete mode 100644 xorg-x11-server-fb-access-wrapper.patch diff --git a/0001-Disallow-byte-swapped-clients-by-default.patch b/0001-Disallow-byte-swapped-clients-by-default.patch deleted file mode 100644 index 2cbf798..0000000 --- a/0001-Disallow-byte-swapped-clients-by-default.patch +++ /dev/null @@ -1,272 +0,0 @@ -From 73d6e888c6058b28a0e87ab65aa4172b17d8327d Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Mon, 19 Dec 2022 10:34:29 +1000 -Subject: [PATCH xserver] Fix some indentation issues - -Signed-off-by: Peter Hutterer ---- - dix/dispatch.c | 22 +++++++++++----------- - 1 file changed, 11 insertions(+), 11 deletions(-) - -diff --git a/dix/dispatch.c b/dix/dispatch.c -index 210df75c63..e38a8fecaa 100644 ---- a/dix/dispatch.c -+++ b/dix/dispatch.c -@@ -492,10 +492,10 @@ Dispatch(void) - if (!WaitForSomething(clients_are_ready())) - continue; - -- /***************** -- * Handle events in round robin fashion, doing input between -- * each round -- *****************/ -+ /***************** -+ * Handle events in round robin fashion, doing input between -+ * each round -+ *****************/ - - if (!dispatchException && clients_are_ready()) { - client = SmartScheduleClient(); -@@ -3657,11 +3657,11 @@ ProcInitialConnection(ClientPtr client) - prefix = (xConnClientPrefix *) ((char *)stuff + sz_xReq); - order = prefix->byteOrder; - if (order != 'l' && order != 'B' && order != 'r' && order != 'R') -- return client->noClientException = -1; -+ return client->noClientException = -1; - if (((*(char *) &whichbyte) && (order == 'B' || order == 'R')) || -- (!(*(char *) &whichbyte) && (order == 'l' || order == 'r'))) { -- client->swapped = TRUE; -- SwapConnClientPrefix(prefix); -+ (!(*(char *) &whichbyte) && (order == 'l' || order == 'r'))) { -+ client->swapped = TRUE; -+ SwapConnClientPrefix(prefix); - } - stuff->reqType = 2; - stuff->length += bytes_to_int32(prefix->nbytesAuthProto) + -@@ -3670,7 +3670,7 @@ ProcInitialConnection(ClientPtr client) - swaps(&stuff->length); - } - if (order == 'r' || order == 'R') { -- client->local = FALSE; -+ client->local = FALSE; - } - ResetCurrentRequest(client); - return Success; -@@ -3781,8 +3781,8 @@ ProcEstablishConnection(ClientPtr client) - auth_string = auth_proto + pad_to_int32(prefix->nbytesAuthProto); - - if ((client->req_len << 2) != sz_xReq + sz_xConnClientPrefix + -- pad_to_int32(prefix->nbytesAuthProto) + -- pad_to_int32(prefix->nbytesAuthString)) -+ pad_to_int32(prefix->nbytesAuthProto) + -+ pad_to_int32(prefix->nbytesAuthString)) - reason = "Bad length"; - else if ((prefix->majorVersion != X_PROTOCOL) || - (prefix->minorVersion != X_PROTOCOL_REVISION)) --- -2.39.0 - -From f69280ddcdd3115ee4717f22e85e0f43569b60dd Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Tue, 20 Dec 2022 11:40:16 +1000 -Subject: [PATCH xserver] dix: localize two variables - -Signed-off-by: Peter Hutterer ---- - dix/dispatch.c | 8 ++++---- - 1 file changed, 4 insertions(+), 4 deletions(-) - -diff --git a/dix/dispatch.c b/dix/dispatch.c -index c651c3d887..92be773e6c 100644 ---- a/dix/dispatch.c -+++ b/dix/dispatch.c -@@ -3766,14 +3766,11 @@ int - ProcEstablishConnection(ClientPtr client) - { - const char *reason; -- char *auth_proto, *auth_string; - xConnClientPrefix *prefix; - - REQUEST(xReq); - - prefix = (xConnClientPrefix *) ((char *) stuff + sz_xReq); -- auth_proto = (char *) prefix + sz_xConnClientPrefix; -- auth_string = auth_proto + pad_to_int32(prefix->nbytesAuthProto); - - if ((client->req_len << 2) != sz_xReq + sz_xConnClientPrefix + - pad_to_int32(prefix->nbytesAuthProto) + -@@ -3782,12 +3779,15 @@ ProcEstablishConnection(ClientPtr client) - else if ((prefix->majorVersion != X_PROTOCOL) || - (prefix->minorVersion != X_PROTOCOL_REVISION)) - reason = "Protocol version mismatch"; -- else -+ else { -+ char *auth_proto = (char *) prefix + sz_xConnClientPrefix; -+ char *auth_string = auth_proto + pad_to_int32(prefix->nbytesAuthProto); - reason = ClientAuthorized(client, - (unsigned short) prefix->nbytesAuthProto, - auth_proto, - (unsigned short) prefix->nbytesAuthString, - auth_string); -+ } - - return (SendConnSetup(client, reason)); - } --- -2.39.0 - -From 412777664a20dd3561b936c02c96571a756fe9b2 Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Tue, 20 Dec 2022 10:42:03 +1000 -Subject: [PATCH xserver] Disallow byte-swapped clients by default - -The X server swapping code is a huge attack surface, much of this code -is untested and prone to security issues. The use-case of byte-swapped -clients is very niche, so let's disable this by default and allow it -only when the respective config option or commandline flag is given. - -For Xorg, this adds the ServerFlag "AllowByteSwappedClients" "on". -For all DDX, this adds the commandline options +byteswappedclients and --byteswappedclients to enable or disable, respectively. - -Fixes #1201 - -https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/1029 - -Signed-off-by: Peter Hutterer ---- - dix/dispatch.c | 4 +++- - hw/xfree86/common/xf86Config.c | 8 ++++++++ - hw/xfree86/man/xorg.conf.man | 2 ++ - hw/xwayland/xwayland.pc.in | 1 + - include/opaque.h | 2 ++ - man/Xserver.man | 6 ++++++ - os/utils.c | 9 +++++++++ - 7 files changed, 31 insertions(+), 1 deletion(-) - -diff --git a/dix/dispatch.c b/dix/dispatch.c -index 92be773e6c..9c26753a96 100644 ---- a/dix/dispatch.c -+++ b/dix/dispatch.c -@@ -3772,7 +3772,9 @@ ProcEstablishConnection(ClientPtr client) - - prefix = (xConnClientPrefix *) ((char *) stuff + sz_xReq); - -- if ((client->req_len << 2) != sz_xReq + sz_xConnClientPrefix + -+ if (client->swapped && !AllowByteSwappedClients) { -+ reason = "Prohibited client endianess, see the Xserver man page "; -+ } else if ((client->req_len << 2) != sz_xReq + sz_xConnClientPrefix + - pad_to_int32(prefix->nbytesAuthProto) + - pad_to_int32(prefix->nbytesAuthString)) - reason = "Bad length"; -diff --git a/hw/xfree86/common/xf86Config.c b/hw/xfree86/common/xf86Config.c -index 5d814c1485..41acb25aa2 100644 ---- a/hw/xfree86/common/xf86Config.c -+++ b/hw/xfree86/common/xf86Config.c -@@ -646,6 +646,7 @@ typedef enum { - FLAG_MAX_CLIENTS, - FLAG_IGLX, - FLAG_DEBUG, -+ FLAG_ALLOW_BYTE_SWAPPED_CLIENTS, - } FlagValues; - - /** -@@ -705,6 +706,8 @@ static OptionInfoRec FlagOptions[] = { - {0}, FALSE}, - {FLAG_DEBUG, "Debug", OPTV_STRING, - {0}, FALSE}, -+ {FLAG_ALLOW_BYTE_SWAPPED_CLIENTS, "AllowByteSwappedClients", OPTV_BOOLEAN, -+ {0}, FALSE}, - {-1, NULL, OPTV_NONE, - {0}, FALSE}, - }; -@@ -746,6 +749,11 @@ configServerFlags(XF86ConfFlagsPtr flagsconf, XF86OptionPtr layoutopts) - xf86Msg(X_CONFIG, "Ignoring ABI Version\n"); - } - -+ xf86GetOptValBool(FlagOptions, FLAG_ALLOW_BYTE_SWAPPED_CLIENTS, &AllowByteSwappedClients); -+ if (AllowByteSwappedClients) { -+ xf86Msg(X_CONFIG, "Allowing byte-swapped clients\n"); -+ } -+ - if (xf86IsOptionSet(FlagOptions, FLAG_AUTO_ADD_DEVICES)) { - xf86GetOptValBool(FlagOptions, FLAG_AUTO_ADD_DEVICES, - &xf86Info.autoAddDevices); -diff --git a/hw/xfree86/man/xorg.conf.man b/hw/xfree86/man/xorg.conf.man -index 01b47247ee..d057f26ecd 100644 ---- a/hw/xfree86/man/xorg.conf.man -+++ b/hw/xfree86/man/xorg.conf.man -@@ -677,6 +677,8 @@ Possible values are - or - .BR sync . - Unset by default. -+.BI "Option \*qAllowByteSwappedClients\*q \*q" boolean \*q -+Allow clients with a different byte-order than the server. Disabled by default. - .SH "MODULE SECTION" - The - .B Module -diff --git a/include/opaque.h b/include/opaque.h -index 256261c2ad..398d4b4e51 100644 ---- a/include/opaque.h -+++ b/include/opaque.h -@@ -74,4 +74,6 @@ extern _X_EXPORT Bool bgNoneRoot; - extern _X_EXPORT Bool CoreDump; - extern _X_EXPORT Bool NoListenAll; - -+extern _X_EXPORT Bool AllowByteSwappedClients; -+ - #endif /* OPAQUE_H */ -diff --git a/man/Xserver.man b/man/Xserver.man -index 764bd1d907..e7adf9eb35 100644 ---- a/man/Xserver.man -+++ b/man/Xserver.man -@@ -114,6 +114,12 @@ pattern. This is the default unless -retro or -wr is specified. - .B \-bs - disables backing store support on all screens. - .TP 8 -+.B \+byteswappedclients -+Allow connections from clients with an endianess different to that of the server. -+.TP 8 -+.B \-byteswappedclients -+Prohibit connections from clients with an endianess different to that of the server. -+.TP 8 - .B \-c - turns off key-click. - .TP 8 -diff --git a/os/utils.c b/os/utils.c -index fe94912f34..405bf7d8b4 100644 ---- a/os/utils.c -+++ b/os/utils.c -@@ -189,6 +189,8 @@ Bool CoreDump; - - Bool enableIndirectGLX = FALSE; - -+Bool AllowByteSwappedClients = FALSE; -+ - #ifdef PANORAMIX - Bool PanoramiXExtensionDisabledHack = FALSE; - #endif -@@ -523,6 +525,8 @@ UseMsg(void) - ErrorF("-br create root window with black background\n"); - ErrorF("+bs enable any backing store support\n"); - ErrorF("-bs disable any backing store support\n"); -+ ErrorF("+byteswappedclients Allow clients with endianess different to that of the server\n"); -+ ErrorF("-byteswappedclients Prohibit clients with endianess different to that of the server\n"); - ErrorF("-c turns off key-click\n"); - ErrorF("c # key-click volume (0-100)\n"); - ErrorF("-cc int default color visual class\n"); -@@ -720,6 +724,11 @@ ProcessCommandLine(int argc, char *argv[]) - else - UseMsg(); - } -+ else if (strcmp(argv[i], "-byteswappedclients") == 0) { -+ AllowByteSwappedClients = FALSE; -+ } else if (strcmp(argv[i], "+byteswappedclients") == 0) { -+ AllowByteSwappedClients = TRUE; -+ } - else if (strcmp(argv[i], "-br") == 0); /* default */ - else if (strcmp(argv[i], "+bs") == 0) - enableBackingStore = TRUE; --- -2.39.0 - diff --git a/0001-Don-t-hardcode-fps-for-fake-screen.patch b/0001-Don-t-hardcode-fps-for-fake-screen.patch deleted file mode 100644 index 465a92b..0000000 --- a/0001-Don-t-hardcode-fps-for-fake-screen.patch +++ /dev/null @@ -1,135 +0,0 @@ -From 6497eeeb1a6552315132340565a3901d4db2144c Mon Sep 17 00:00:00 2001 -From: Boris-Barboris -Date: Tue, 22 Jun 2021 00:51:08 +0300 -Subject: [PATCH] Don't hardcode fps for fake screen - -Currently, when main hardware screen is powered-off, -X server initializes fake screen's timer with -1 second update interval. - -Streaming software like Nomachine or Vnc, as well as -desktop input automation suffers from it, since it -will forever be stuck on 1 fps until the display is -turned back on. - -This commit adds command line option -fakescreenfps -that allows the user to change the default fake screen -timer. - -Signed-off-by: Baranin Alexander ---- - man/Xserver.man | 3 +++ - os/utils.c | 12 ++++++++++++ - present/present.h | 2 ++ - present/present_fake.c | 28 ++++++++++++++++++---------- - 4 files changed, 35 insertions(+), 10 deletions(-) - -diff --git a/man/Xserver.man b/man/Xserver.man -index 31ffb8c..b1a3f40 100644 ---- a/man/Xserver.man -+++ b/man/Xserver.man -@@ -169,6 +169,9 @@ sets default cursor font. - .B \-fn \fIfont\fP - sets the default font. - .TP 8 -+.B \-fakescreenfps \fFps\fP -+sets fake presenter screen default fps (allowable range: 1-600). -+.TP 8 - .B \-fp \fIfontPath\fP - sets the search path for fonts. This path is a comma separated list - of directories which the X server searches for font databases. -diff --git a/os/utils.c b/os/utils.c -index 2ba1c80..721d4e9 100644 ---- a/os/utils.c -+++ b/os/utils.c -@@ -110,6 +110,8 @@ __stdcall unsigned long GetTickCount(void); - - #include "picture.h" - -+#include "present.h" -+ - Bool noTestExtensions; - - #ifdef COMPOSITE -@@ -526,6 +528,7 @@ UseMsg(void) - ErrorF - ("-deferglyphs [none|all|16] defer loading of [no|all|16-bit] glyphs\n"); - ErrorF("-f # bell base (0-100)\n"); -+ ErrorF("-fakescreenfps # fake screen default fps (1-600)\n"); - ErrorF("-fc string cursor font\n"); - ErrorF("-fn string default font name\n"); - ErrorF("-fp string default font path\n"); -@@ -776,6 +779,15 @@ ProcessCommandLine(int argc, char *argv[]) - else - UseMsg(); - } -+ else if (strcmp(argv[i], "-fakescreenfps") == 0) { -+ if (++i < argc) { -+ FakeScreenFps = (uint32_t) atoi(argv[i]); -+ if (FakeScreenFps < 1 || FakeScreenFps > 600) -+ FatalError("fakescreenfps must be an integer in [1;600] range\n"); -+ } -+ else -+ UseMsg(); -+ } - else if (strcmp(argv[i], "-fc") == 0) { - if (++i < argc) - defaultCursorFont = argv[i]; -diff --git a/present/present.h b/present/present.h -index 3d0b972..e7cc50d 100644 ---- a/present/present.h -+++ b/present/present.h -@@ -190,4 +190,6 @@ present_register_complete_notify(present_complete_notify_proc proc); - extern _X_EXPORT Bool - present_can_window_flip(WindowPtr window); - -+extern _X_EXPORT uint32_t FakeScreenFps; -+ - #endif /* _PRESENT_H_ */ -diff --git a/present/present_fake.c b/present/present_fake.c -index 2350638..d9ac598 100644 ---- a/present/present_fake.c -+++ b/present/present_fake.c -@@ -117,21 +117,29 @@ present_fake_queue_vblank(ScreenPtr screen, - return Success; - } - -+uint32_t FakeScreenFps = 0; -+ - void - present_fake_screen_init(ScreenPtr screen) - { -+ uint32_t fake_fps; - present_screen_priv_ptr screen_priv = present_screen_priv(screen); - -- /* For screens with hardware vblank support, the fake code -- * will be used for off-screen windows and while screens are blanked, -- * in which case we want a slow interval here -- * -- * Otherwise, pretend that the screen runs at 60Hz -- */ -- if (screen_priv->info && screen_priv->info->get_crtc) -- screen_priv->fake_interval = 1000000; -- else -- screen_priv->fake_interval = 16667; -+ if (FakeScreenFps) -+ fake_fps = FakeScreenFps; -+ else { -+ /* For screens with hardware vblank support, the fake code -+ * will be used for off-screen windows and while screens are blanked, -+ * in which case we want a large interval here: 1Hz -+ * -+ * Otherwise, pretend that the screen runs at 60Hz -+ */ -+ if (screen_priv->info && screen_priv->info->get_crtc) -+ fake_fps = 1; -+ else -+ fake_fps = 60; -+ } -+ screen_priv->fake_interval = 1000000 / fake_fps; - } - - void --- -2.34.1 - diff --git a/0001-Xi-ProcXIGetSelectedEvents-needs-to-use-unswapped-le.patch b/0001-Xi-ProcXIGetSelectedEvents-needs-to-use-unswapped-le.patch deleted file mode 100644 index 5a64c75..0000000 --- a/0001-Xi-ProcXIGetSelectedEvents-needs-to-use-unswapped-le.patch +++ /dev/null @@ -1,45 +0,0 @@ -From 96798fc1967491c80a4d0c8d9e0a80586cb2152b Mon Sep 17 00:00:00 2001 -From: Alan Coopersmith -Date: Fri, 22 Mar 2024 18:51:45 -0700 -Subject: [PATCH 1/4] Xi: ProcXIGetSelectedEvents needs to use unswapped length - to send reply - -CVE-2024-31080 - -Reported-by: https://debbugs.gnu.org/cgi/bugreport.cgi?bug=69762 -Fixes: 53e821ab4 ("Xi: add request processing for XIGetSelectedEvents.") -Signed-off-by: Alan Coopersmith -Part-of: ---- - Xi/xiselectev.c | 5 ++++- - 1 file changed, 4 insertions(+), 1 deletion(-) - -diff --git a/Xi/xiselectev.c b/Xi/xiselectev.c -index edcb8a0d3..ac1494987 100644 ---- a/Xi/xiselectev.c -+++ b/Xi/xiselectev.c -@@ -349,6 +349,7 @@ ProcXIGetSelectedEvents(ClientPtr client) - InputClientsPtr others = NULL; - xXIEventMask *evmask = NULL; - DeviceIntPtr dev; -+ uint32_t length; - - REQUEST(xXIGetSelectedEventsReq); - REQUEST_SIZE_MATCH(xXIGetSelectedEventsReq); -@@ -418,10 +419,12 @@ ProcXIGetSelectedEvents(ClientPtr client) - } - } - -+ /* save the value before SRepXIGetSelectedEvents swaps it */ -+ length = reply.length; - WriteReplyToClient(client, sizeof(xXIGetSelectedEventsReply), &reply); - - if (reply.num_masks) -- WriteToClient(client, reply.length * 4, buffer); -+ WriteToClient(client, length * 4, buffer); - - free(buffer); - return Success; --- -2.44.0 - diff --git a/0001-Xi-allocate-enough-XkbActions-for-our-buttons.patch b/0001-Xi-allocate-enough-XkbActions-for-our-buttons.patch deleted file mode 100644 index 11236a1..0000000 --- a/0001-Xi-allocate-enough-XkbActions-for-our-buttons.patch +++ /dev/null @@ -1,77 +0,0 @@ -From a7bda3080d2b44eae668cdcec7a93095385b9652 Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Tue, 28 Nov 2023 15:19:04 +1000 -Subject: [PATCH xserver] Xi: allocate enough XkbActions for our buttons - -button->xkb_acts is supposed to be an array sufficiently large for all -our buttons, not just a single XkbActions struct. Allocating -insufficient memory here means when we memcpy() later in -XkbSetDeviceInfo we write into memory that wasn't ours to begin with, -leading to the usual security ooopsiedaisies. - -CVE-2023-6377, ZDI-CAN-22412, ZDI-CAN-22413 - -This vulnerability was discovered by: -Jan-Niklas Sohn working with Trend Micro Zero Day Initiative - -(cherry picked from commit 0c1a93d319558fe3ab2d94f51d174b4f93810afd) ---- - Xi/exevents.c | 12 ++++++------ - dix/devices.c | 10 ++++++++++ - 2 files changed, 16 insertions(+), 6 deletions(-) - -diff --git a/Xi/exevents.c b/Xi/exevents.c -index dcd4efb3bc..54ea11a938 100644 ---- a/Xi/exevents.c -+++ b/Xi/exevents.c -@@ -611,13 +611,13 @@ DeepCopyPointerClasses(DeviceIntPtr from, DeviceIntPtr to) - } - - if (from->button->xkb_acts) { -- if (!to->button->xkb_acts) { -- to->button->xkb_acts = calloc(1, sizeof(XkbAction)); -- if (!to->button->xkb_acts) -- FatalError("[Xi] not enough memory for xkb_acts.\n"); -- } -+ size_t maxbuttons = max(to->button->numButtons, from->button->numButtons); -+ to->button->xkb_acts = xnfreallocarray(to->button->xkb_acts, -+ maxbuttons, -+ sizeof(XkbAction)); -+ memset(to->button->xkb_acts, 0, maxbuttons * sizeof(XkbAction)); - memcpy(to->button->xkb_acts, from->button->xkb_acts, -- sizeof(XkbAction)); -+ from->button->numButtons * sizeof(XkbAction)); - } - else { - free(to->button->xkb_acts); -diff --git a/dix/devices.c b/dix/devices.c -index 5bf956ead4..15e46a9a5f 100644 ---- a/dix/devices.c -+++ b/dix/devices.c -@@ -2525,6 +2525,8 @@ RecalculateMasterButtons(DeviceIntPtr slave) - - if (master->button && master->button->numButtons != maxbuttons) { - int i; -+ int last_num_buttons = master->button->numButtons; -+ - DeviceChangedEvent event = { - .header = ET_Internal, - .type = ET_DeviceChanged, -@@ -2535,6 +2537,14 @@ RecalculateMasterButtons(DeviceIntPtr slave) - }; - - master->button->numButtons = maxbuttons; -+ if (last_num_buttons < maxbuttons) { -+ master->button->xkb_acts = xnfreallocarray(master->button->xkb_acts, -+ maxbuttons, -+ sizeof(XkbAction)); -+ memset(&master->button->xkb_acts[last_num_buttons], -+ 0, -+ (maxbuttons - last_num_buttons) * sizeof(XkbAction)); -+ } - - memcpy(&event.buttons.names, master->button->labels, maxbuttons * - sizeof(Atom)); --- -2.43.0 - diff --git a/0001-Xi-fix-potential-use-after-free-in-DeepCopyPointerCl.patch b/0001-Xi-fix-potential-use-after-free-in-DeepCopyPointerCl.patch deleted file mode 100644 index 2389895..0000000 --- a/0001-Xi-fix-potential-use-after-free-in-DeepCopyPointerCl.patch +++ /dev/null @@ -1,35 +0,0 @@ -From 7150ba655c0cc08fa6ded309b81265bb672f2869 Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Wed, 25 Jan 2023 11:41:40 +1000 -Subject: [PATCH xserver] Xi: fix potential use-after-free in - DeepCopyPointerClasses - -CVE-2023-0494, ZDI-CAN 19596 - -This vulnerability was discovered by: -Jan-Niklas Sohn working with Trend Micro Zero Day Initiative - -Signed-off-by: Peter Hutterer ---- - Xi/exevents.c | 4 +++- - 1 file changed, 3 insertions(+), 1 deletion(-) - -diff --git a/Xi/exevents.c b/Xi/exevents.c -index 217baa9561..dcd4efb3bc 100644 ---- a/Xi/exevents.c -+++ b/Xi/exevents.c -@@ -619,8 +619,10 @@ DeepCopyPointerClasses(DeviceIntPtr from, DeviceIntPtr to) - memcpy(to->button->xkb_acts, from->button->xkb_acts, - sizeof(XkbAction)); - } -- else -+ else { - free(to->button->xkb_acts); -+ to->button->xkb_acts = NULL; -+ } - - memcpy(to->button->labels, from->button->labels, - from->button->numButtons * sizeof(Atom)); --- -2.39.0 - diff --git a/0001-Xi-randr-fix-handling-of-PropModeAppend-Prepend.patch b/0001-Xi-randr-fix-handling-of-PropModeAppend-Prepend.patch deleted file mode 100644 index 99625dd..0000000 --- a/0001-Xi-randr-fix-handling-of-PropModeAppend-Prepend.patch +++ /dev/null @@ -1,80 +0,0 @@ -From a31ba141824a7649e11f0ef7673718ce559d6337 Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Tue, 3 Oct 2023 11:53:05 +1000 -Subject: [PATCH xserver 1/4] Xi/randr: fix handling of PropModeAppend/Prepend - -The handling of appending/prepending properties was incorrect, with at -least two bugs: the property length was set to the length of the new -part only, i.e. appending or prepending N elements to a property with P -existing elements always resulted in the property having N elements -instead of N + P. - -Second, when pre-pending a value to a property, the offset for the old -values was incorrect, leaving the new property with potentially -uninitalized values and/or resulting in OOB memory writes. -For example, prepending a 3 element value to a 5 element property would -result in this 8 value array: - [N, N, N, ?, ?, P, P, P ] P, P - ^OOB write - -The XI2 code is a copy/paste of the RandR code, so the bug exists in -both. - -CVE-2023-5367, ZDI-CAN-22153 - -This vulnerability was discovered by: -Jan-Niklas Sohn working with Trend Micro Zero Day Initiative - -Signed-off-by: Peter Hutterer ---- - Xi/xiproperty.c | 4 ++-- - randr/rrproperty.c | 4 ++-- - 2 files changed, 4 insertions(+), 4 deletions(-) - -diff --git a/Xi/xiproperty.c b/Xi/xiproperty.c -index 6ec419e870..563c4f31a5 100644 ---- a/Xi/xiproperty.c -+++ b/Xi/xiproperty.c -@@ -730,7 +730,7 @@ XIChangeDeviceProperty(DeviceIntPtr dev, Atom property, Atom type, - XIDestroyDeviceProperty(prop); - return BadAlloc; - } -- new_value.size = len; -+ new_value.size = total_len; - new_value.type = type; - new_value.format = format; - -@@ -747,7 +747,7 @@ XIChangeDeviceProperty(DeviceIntPtr dev, Atom property, Atom type, - case PropModePrepend: - new_data = new_value.data; - old_data = (void *) (((char *) new_value.data) + -- (prop_value->size * size_in_bytes)); -+ (len * size_in_bytes)); - break; - } - if (new_data) -diff --git a/randr/rrproperty.c b/randr/rrproperty.c -index c2fb9585c6..25469f57b2 100644 ---- a/randr/rrproperty.c -+++ b/randr/rrproperty.c -@@ -209,7 +209,7 @@ RRChangeOutputProperty(RROutputPtr output, Atom property, Atom type, - RRDestroyOutputProperty(prop); - return BadAlloc; - } -- new_value.size = len; -+ new_value.size = total_len; - new_value.type = type; - new_value.format = format; - -@@ -226,7 +226,7 @@ RRChangeOutputProperty(RROutputPtr output, Atom property, Atom type, - case PropModePrepend: - new_data = new_value.data; - old_data = (void *) (((char *) new_value.data) + -- (prop_value->size * size_in_bytes)); -+ (len * size_in_bytes)); - break; - } - if (new_data) --- -2.41.0 - diff --git a/0001-Xtest-disallow-GenericEvents-in-XTestSwapFakeInput.patch b/0001-Xtest-disallow-GenericEvents-in-XTestSwapFakeInput.patch deleted file mode 100644 index 017f247..0000000 --- a/0001-Xtest-disallow-GenericEvents-in-XTestSwapFakeInput.patch +++ /dev/null @@ -1,52 +0,0 @@ -From 8dba686dc277d6d262ad0c77b4632a5b276697ba Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Tue, 29 Nov 2022 12:55:45 +1000 -Subject: [PATCH xserver 1/7] Xtest: disallow GenericEvents in - XTestSwapFakeInput - -XTestSwapFakeInput assumes all events in this request are -sizeof(xEvent) and iterates through these in 32-byte increments. -However, a GenericEvent may be of arbitrary length longer than 32 bytes, -so any GenericEvent in this list would result in subsequent events to be -misparsed. - -Additional, the swapped event is written into a stack-allocated struct -xEvent (size 32 bytes). For any GenericEvent longer than 32 bytes, -swapping the event may thus smash the stack like an avocado on toast. - -Catch this case early and return BadValue for any GenericEvent. -Which is what would happen in unswapped setups anyway since XTest -doesn't support GenericEvent. - -CVE-2022-46340, ZDI-CAN 19265 - -This vulnerability was discovered by: -Jan-Niklas Sohn working with Trend Micro Zero Day Initiative - -Signed-off-by: Peter Hutterer -Acked-by: Olivier Fourdan ---- - Xext/xtest.c | 5 +++-- - 1 file changed, 3 insertions(+), 2 deletions(-) - -diff --git a/Xext/xtest.c b/Xext/xtest.c -index bf27eb590b..2985a4ce6e 100644 ---- a/Xext/xtest.c -+++ b/Xext/xtest.c -@@ -502,10 +502,11 @@ XTestSwapFakeInput(ClientPtr client, xReq * req) - - nev = ((req->length << 2) - sizeof(xReq)) / sizeof(xEvent); - for (ev = (xEvent *) &req[1]; --nev >= 0; ev++) { -+ int evtype = ev->u.u.type & 0x177; - /* Swap event */ -- proc = EventSwapVector[ev->u.u.type & 0177]; -+ proc = EventSwapVector[evtype]; - /* no swapping proc; invalid event type? */ -- if (!proc || proc == NotImplemented) { -+ if (!proc || proc == NotImplemented || evtype == GenericEvent) { - client->errorValue = ev->u.u.type; - return BadValue; - } --- -2.38.1 - diff --git a/0001-add-a-quirk-for-apple-silicon.patch b/0001-add-a-quirk-for-apple-silicon.patch deleted file mode 100644 index 17c40e5..0000000 --- a/0001-add-a-quirk-for-apple-silicon.patch +++ /dev/null @@ -1,30 +0,0 @@ -commit 39934a656a44722d16a80bf4db411c53e2d67b38 (HEAD -> master, origin/master, origin/HEAD) -Author: Eric Curtin -Date: Fri Dec 16 11:10:12 2022 +0000 - - config: add a quirk for Apple Silicon appledrm - - Xorg server does not correctly select the DCP for the display without a - quirk on Apple Silicon. - - Signed-off-by: Eric Curtin - Suggested-by: Hector Martin - -diff --git a/config/10-quirks.conf b/config/10-quirks.conf -index 47907d82d..54dd908a7 100644 ---- a/config/10-quirks.conf -+++ b/config/10-quirks.conf -@@ -36,3 +36,13 @@ Section "InputClass" - MatchDriver "evdev" - Option "TypeName" "MOUSE" - EndSection -+ -+# https://bugzilla.redhat.com/show_bug.cgi?id=2152414 -+# Xorg server does not correctly select the DCP for the display without -+# a quirk on Apple Silicon -+Section "OutputClass" -+ Identifier "appledrm" -+ MatchDriver "apple" -+ Driver "modesetting" -+ Option "PrimaryGPU" "true" -+EndSection diff --git a/0001-autobind-GPUs-to-the-screen.patch b/0001-autobind-GPUs-to-the-screen.patch deleted file mode 100644 index 86b96a2..0000000 --- a/0001-autobind-GPUs-to-the-screen.patch +++ /dev/null @@ -1,293 +0,0 @@ -From 471289fa1dc359555ceed6302f7d9605ab6be3ea Mon Sep 17 00:00:00 2001 -From: Dave Airlie -Date: Mon, 2 Apr 2018 16:49:02 -0400 -Subject: [PATCH] autobind GPUs to the screen - -This is a modified version of a patch we've been carry-ing in Fedora and -RHEL for years now. This patch automatically adds secondary GPUs to the -master as output sink / offload source making e.g. the use of -slave-outputs just work, with requiring the user to manually run -"xrandr --setprovideroutputsource" before he can hookup an external -monitor to his hybrid graphics laptop. - -There is one problem with this patch, which is why it was not upstreamed -before. What to do when a secondary GPU gets detected really is a policy -decission (e.g. one may want to autobind PCI GPUs but not USB ones) and -as such should be under control of the Desktop Environment. - -Unconditionally adding autobinding support to the xserver will result -in races between the DE dealing with the hotplug of a secondary GPU -and the server itself dealing with it. - -However we've waited for years for any Desktop Environments to actually -start doing some sort of autoconfiguration of secondary GPUs and there -is still not a single DE dealing with this, so I believe that it is -time to upstream this now. - -To avoid potential future problems if any DEs get support for doing -secondary GPU configuration themselves, the new autobind functionality -is made optional. Since no DEs currently support doing this themselves it -is enabled by default. When DEs grow support for doing this themselves -they can disable the servers autobinding through the servers cmdline or a -xorg.conf snippet. - -Signed-off-by: Dave Airlie -[hdegoede@redhat.com: Make configurable, fix with nvidia, submit upstream] -Signed-off-by: Hans de Goede ---- - hw/xfree86/common/xf86Config.c | 19 +++++++++++++++++++ - hw/xfree86/common/xf86Globals.c | 2 ++ - hw/xfree86/common/xf86Init.c | 20 ++++++++++++++++++++ - hw/xfree86/common/xf86Priv.h | 1 + - hw/xfree86/common/xf86Privstr.h | 1 + - hw/xfree86/common/xf86platformBus.c | 4 ++++ - hw/xfree86/man/Xorg.man | 7 +++++++ - hw/xfree86/man/xorg.conf.man | 6 ++++++ - randr/randrstr.h | 3 +++ - randr/rrprovider.c | 22 ++++++++++++++++++++++ - 10 files changed, 85 insertions(+) - -diff --git a/hw/xfree86/common/xf86Config.c b/hw/xfree86/common/xf86Config.c -index 2c1d335..d7d7c2e 100644 ---- a/hw/xfree86/common/xf86Config.c -+++ b/hw/xfree86/common/xf86Config.c -@@ -643,6 +643,7 @@ typedef enum { - FLAG_DRI2, - FLAG_USE_SIGIO, - FLAG_AUTO_ADD_GPU, -+ FLAG_AUTO_BIND_GPU, - FLAG_MAX_CLIENTS, - FLAG_IGLX, - FLAG_DEBUG, -@@ -699,6 +700,8 @@ static OptionInfoRec FlagOptions[] = { - {0}, FALSE}, - {FLAG_AUTO_ADD_GPU, "AutoAddGPU", OPTV_BOOLEAN, - {0}, FALSE}, -+ {FLAG_AUTO_BIND_GPU, "AutoBindGPU", OPTV_BOOLEAN, -+ {0}, FALSE}, - {FLAG_MAX_CLIENTS, "MaxClients", OPTV_INTEGER, - {0}, FALSE }, - {FLAG_IGLX, "IndirectGLX", OPTV_BOOLEAN, -@@ -779,6 +782,22 @@ configServerFlags(XF86ConfFlagsPtr flagsconf, XF86OptionPtr layoutopts) - } - xf86Msg(from, "%sutomatically adding GPU devices\n", - xf86Info.autoAddGPU ? "A" : "Not a"); -+ -+ if (xf86AutoBindGPUDisabled) { -+ xf86Info.autoBindGPU = FALSE; -+ from = X_CMDLINE; -+ } -+ else if (xf86IsOptionSet(FlagOptions, FLAG_AUTO_BIND_GPU)) { -+ xf86GetOptValBool(FlagOptions, FLAG_AUTO_BIND_GPU, -+ &xf86Info.autoBindGPU); -+ from = X_CONFIG; -+ } -+ else { -+ from = X_DEFAULT; -+ } -+ xf86Msg(from, "%sutomatically binding GPU devices\n", -+ xf86Info.autoBindGPU ? "A" : "Not a"); -+ - /* - * Set things up based on the config file information. Some of these - * settings may be overridden later when the command line options are -diff --git a/hw/xfree86/common/xf86Globals.c b/hw/xfree86/common/xf86Globals.c -index e890f05..7b27b4c 100644 ---- a/hw/xfree86/common/xf86Globals.c -+++ b/hw/xfree86/common/xf86Globals.c -@@ -131,6 +131,7 @@ xf86InfoRec xf86Info = { - #else - .autoAddGPU = FALSE, - #endif -+ .autoBindGPU = TRUE, - }; - - const char *xf86ConfigFile = NULL; -@@ -191,6 +192,7 @@ Bool xf86FlipPixels = FALSE; - Gamma xf86Gamma = { 0.0, 0.0, 0.0 }; - - Bool xf86AllowMouseOpenFail = FALSE; -+Bool xf86AutoBindGPUDisabled = FALSE; - - #ifdef XF86VIDMODE - Bool xf86VidModeDisabled = FALSE; -diff --git a/hw/xfree86/common/xf86Init.c b/hw/xfree86/common/xf86Init.c -index ea42ec9..ec255b6 100644 ---- a/hw/xfree86/common/xf86Init.c -+++ b/hw/xfree86/common/xf86Init.c -@@ -76,6 +76,7 @@ - #include "xf86DDC.h" - #include "xf86Xinput.h" - #include "xf86InPriv.h" -+#include "xf86Crtc.h" - #include "picturestr.h" - #include "randrstr.h" - #include "glxvndabi.h" -@@ -237,6 +238,19 @@ xf86PrivsElevated(void) - return PrivsElevated(); - } - -+static void -+xf86AutoConfigOutputDevices(void) -+{ -+ int i; -+ -+ if (!xf86Info.autoBindGPU) -+ return; -+ -+ for (i = 0; i < xf86NumGPUScreens; i++) -+ RRProviderAutoConfigGpuScreen(xf86ScrnToScreen(xf86GPUScreens[i]), -+ xf86ScrnToScreen(xf86Screens[0])); -+} -+ - static void - TrapSignals(void) - { -@@ -770,6 +784,8 @@ InitOutput(ScreenInfo * pScreenInfo, int argc, char **argv) - for (i = 0; i < xf86NumGPUScreens; i++) - AttachUnboundGPU(xf86Screens[0]->pScreen, xf86GPUScreens[i]->pScreen); - -+ xf86AutoConfigOutputDevices(); -+ - xf86VGAarbiterWrapFunctions(); - if (sigio_blocked) - input_unlock(); -@@ -1278,6 +1294,10 @@ ddxProcessArgument(int argc, char **argv, int i) - xf86Info.iglxFrom = X_CMDLINE; - return 0; - } -+ if (!strcmp(argv[i], "-noautoBindGPU")) { -+ xf86AutoBindGPUDisabled = TRUE; -+ return 1; -+ } - - /* OS-specific processing */ - return xf86ProcessArgument(argc, argv, i); -diff --git a/hw/xfree86/common/xf86Priv.h b/hw/xfree86/common/xf86Priv.h -index 4fe2b5f..6566622 100644 ---- a/hw/xfree86/common/xf86Priv.h -+++ b/hw/xfree86/common/xf86Priv.h -@@ -46,6 +46,7 @@ - extern _X_EXPORT const char *xf86ConfigFile; - extern _X_EXPORT const char *xf86ConfigDir; - extern _X_EXPORT Bool xf86AllowMouseOpenFail; -+extern _X_EXPORT Bool xf86AutoBindGPUDisabled; - - #ifdef XF86VIDMODE - extern _X_EXPORT Bool xf86VidModeDisabled; -diff --git a/hw/xfree86/common/xf86Privstr.h b/hw/xfree86/common/xf86Privstr.h -index 21c2e1f..6c71863 100644 ---- a/hw/xfree86/common/xf86Privstr.h -+++ b/hw/xfree86/common/xf86Privstr.h -@@ -98,6 +98,7 @@ typedef struct { - - Bool autoAddGPU; - const char *debug; -+ Bool autoBindGPU; - } xf86InfoRec, *xf86InfoPtr; - - /* ISC's cc can't handle ~ of UL constants, so explicitly type cast them. */ -diff --git a/hw/xfree86/common/xf86platformBus.c b/hw/xfree86/common/xf86platformBus.c -index cef47da..913a324 100644 ---- a/hw/xfree86/common/xf86platformBus.c -+++ b/hw/xfree86/common/xf86platformBus.c -@@ -49,6 +49,7 @@ - #include "Pci.h" - #include "xf86platformBus.h" - #include "xf86Config.h" -+#include "xf86Crtc.h" - - #include "randrstr.h" - int platformSlotClaimed; -@@ -665,6 +666,9 @@ xf86platformAddDevice(int index) - } - /* attach unbound to 0 protocol screen */ - AttachUnboundGPU(xf86Screens[0]->pScreen, xf86GPUScreens[i]->pScreen); -+ if (xf86Info.autoBindGPU) -+ RRProviderAutoConfigGpuScreen(xf86ScrnToScreen(xf86GPUScreens[i]), -+ xf86ScrnToScreen(xf86Screens[0])); - - RRResourcesChanged(xf86Screens[0]->pScreen); - RRTellChanged(xf86Screens[0]->pScreen); -diff --git a/hw/xfree86/man/Xorg.man b/hw/xfree86/man/Xorg.man -index 13a9dc3..745f986 100644 ---- a/hw/xfree86/man/Xorg.man -+++ b/hw/xfree86/man/Xorg.man -@@ -283,6 +283,13 @@ is a comma separated list of directories to search for - server modules. This option is only available when the server is run - as root (i.e, with real-uid 0). - .TP 8 -+.B \-noautoBindGPU -+Disable automatically setting secondary GPUs up as output sinks and offload -+sources. This is equivalent to setting the -+.B AutoBindGPU -+xorg.conf(__filemansuffix__) file option. To -+.B false. -+.TP 8 - .B \-nosilk - Disable Silken Mouse support. - .TP 8 -diff --git a/hw/xfree86/man/xorg.conf.man b/hw/xfree86/man/xorg.conf.man -index 9589262..8d51e06 100644 ---- a/hw/xfree86/man/xorg.conf.man -+++ b/hw/xfree86/man/xorg.conf.man -@@ -672,6 +672,12 @@ Enabled by default. - If this option is disabled, then no GPU devices will be added from the udev - backend. Enabled by default. (May need to be disabled to setup Xinerama). - .TP 7 -+.BI "Option \*qAutoBindGPU\*q \*q" boolean \*q -+If enabled then secondary GPUs will be automatically set up as output-sinks and -+offload-sources. Making e.g. laptop outputs connected only to the secondary -+GPU directly available for use without needing to run -+"xrandr --setprovideroutputsource". Enabled by default. -+.TP 7 - .BI "Option \*qLog\*q \*q" string \*q - This option controls whether the log is flushed and/or synced to disk after - each message. -diff --git a/randr/randrstr.h b/randr/randrstr.h -index f94174b..092d726 100644 ---- a/randr/randrstr.h -+++ b/randr/randrstr.h -@@ -1039,6 +1039,9 @@ RRProviderLookup(XID id, RRProviderPtr *provider_p); - extern _X_EXPORT void - RRDeliverProviderEvent(ClientPtr client, WindowPtr pWin, RRProviderPtr provider); - -+extern _X_EXPORT void -+RRProviderAutoConfigGpuScreen(ScreenPtr pScreen, ScreenPtr masterScreen); -+ - /* rrproviderproperty.c */ - - extern _X_EXPORT void -diff --git a/randr/rrprovider.c b/randr/rrprovider.c -index e4bc2bf..e04c18f 100644 ---- a/randr/rrprovider.c -+++ b/randr/rrprovider.c -@@ -485,3 +485,25 @@ RRDeliverProviderEvent(ClientPtr client, WindowPtr pWin, RRProviderPtr provider) - - WriteEventsToClient(client, 1, (xEvent *) &pe); - } -+ -+void -+RRProviderAutoConfigGpuScreen(ScreenPtr pScreen, ScreenPtr masterScreen) -+{ -+ rrScrPrivPtr pScrPriv = rrGetScrPriv(pScreen); -+ rrScrPrivPtr masterPriv = rrGetScrPriv(masterScreen); -+ RRProviderPtr provider = pScrPriv->provider; -+ RRProviderPtr master_provider = masterPriv->provider; -+ -+ if (!provider || !master_provider) -+ return; -+ -+ if ((provider->capabilities & RR_Capability_SinkOutput) && -+ (master_provider->capabilities & RR_Capability_SourceOutput)) { -+ pScrPriv->rrProviderSetOutputSource(pScreen, provider, master_provider); -+ RRInitPrimeSyncProps(pScreen); -+ } -+ -+ if ((provider->capabilities & RR_Capability_SourceOffload) && -+ (master_provider->capabilities & RR_Capability_SinkOffload)) -+ pScrPriv->rrProviderSetOffloadSink(pScreen, provider, master_provider); -+} --- -2.16.2 - diff --git a/0001-composite-Fix-use-after-free-of-the-COW.patch b/0001-composite-Fix-use-after-free-of-the-COW.patch deleted file mode 100644 index bb21d7e..0000000 --- a/0001-composite-Fix-use-after-free-of-the-COW.patch +++ /dev/null @@ -1,42 +0,0 @@ -From 26ef545b3502f61ca722a7a3373507e88ef64110 Mon Sep 17 00:00:00 2001 -From: Olivier Fourdan -Date: Mon, 13 Mar 2023 11:08:47 +0100 -Subject: [PATCH xserver] composite: Fix use-after-free of the COW - -ZDI-CAN-19866/CVE-2023-1393 - -If a client explicitly destroys the compositor overlay window (aka COW), -we would leave a dangling pointer to that window in the CompScreen -structure, which will trigger a use-after-free later. - -Make sure to clear the CompScreen pointer to the COW when the latter gets -destroyed explicitly by the client. - -This vulnerability was discovered by: -Jan-Niklas Sohn working with Trend Micro Zero Day Initiative - -Signed-off-by: Olivier Fourdan -Reviewed-by: Adam Jackson ---- - composite/compwindow.c | 5 +++++ - 1 file changed, 5 insertions(+) - -diff --git a/composite/compwindow.c b/composite/compwindow.c -index 4e2494b86..b30da589e 100644 ---- a/composite/compwindow.c -+++ b/composite/compwindow.c -@@ -620,6 +620,11 @@ compDestroyWindow(WindowPtr pWin) - ret = (*pScreen->DestroyWindow) (pWin); - cs->DestroyWindow = pScreen->DestroyWindow; - pScreen->DestroyWindow = compDestroyWindow; -+ -+ /* Did we just destroy the overlay window? */ -+ if (pWin == cs->pOverlayWin) -+ cs->pOverlayWin = NULL; -+ - /* compCheckTree (pWin->drawable.pScreen); can't check -- tree isn't good*/ - return ret; - } --- -2.40.0 - diff --git a/0001-dix-Fix-use-after-free-in-input-device-shutdown.patch b/0001-dix-Fix-use-after-free-in-input-device-shutdown.patch deleted file mode 100644 index c2d723f..0000000 --- a/0001-dix-Fix-use-after-free-in-input-device-shutdown.patch +++ /dev/null @@ -1,77 +0,0 @@ -From 1801fe0ac3926882d47d7e1ad6c0518a2cdffd41 Mon Sep 17 00:00:00 2001 -From: Povilas Kanapickas -Date: Sun, 19 Dec 2021 18:11:07 +0200 -Subject: [PATCH] dix: Fix use after free in input device shutdown - -This fixes access to freed heap memory via dev->master. E.g. when -running BarrierNotify.ReceivesNotifyEvents/7 test from -xorg-integration-tests: - -==24736==ERROR: AddressSanitizer: heap-use-after-free on address -0x619000065020 at pc 0x55c450e2b9cf bp 0x7fffc532fd20 sp 0x7fffc532fd10 -READ of size 4 at 0x619000065020 thread T0 - #0 0x55c450e2b9ce in GetMaster ../../../dix/devices.c:2722 - #1 0x55c450e9d035 in IsFloating ../../../dix/events.c:346 - #2 0x55c4513209c6 in GetDeviceUse ../../../Xi/xiquerydevice.c:525 -../../../Xi/xichangehierarchy.c:95 - #4 0x55c450e3455c in RemoveDevice ../../../dix/devices.c:1204 -../../../hw/xfree86/common/xf86Xinput.c:1142 - #6 0x55c450e17b04 in CloseDeviceList ../../../dix/devices.c:1038 - #7 0x55c450e1de85 in CloseDownDevices ../../../dix/devices.c:1068 - #8 0x55c450e837ef in dix_main ../../../dix/main.c:302 - #9 0x55c4517a8d93 in main ../../../dix/stubmain.c:34 -(/lib/x86_64-linux-gnu/libc.so.6+0x28564) - #11 0x55c450d0113d in _start (/usr/lib/xorg/Xorg+0x117713d) - -0x619000065020 is located 160 bytes inside of 912-byte region -[0x619000064f80,0x619000065310) -freed by thread T0 here: -(/usr/lib/x86_64-linux-gnu/libasan.so.5+0x10d7cf) - #1 0x55c450e19f1c in CloseDevice ../../../dix/devices.c:1014 - #2 0x55c450e343a4 in RemoveDevice ../../../dix/devices.c:1186 -../../../hw/xfree86/common/xf86Xinput.c:1142 - #4 0x55c450e17b04 in CloseDeviceList ../../../dix/devices.c:1038 - #5 0x55c450e1de85 in CloseDownDevices ../../../dix/devices.c:1068 - #6 0x55c450e837ef in dix_main ../../../dix/main.c:302 - #7 0x55c4517a8d93 in main ../../../dix/stubmain.c:34 -(/lib/x86_64-linux-gnu/libc.so.6+0x28564) - -previously allocated by thread T0 here: -(/usr/lib/x86_64-linux-gnu/libasan.so.5+0x10ddc6) - #1 0x55c450e1c57b in AddInputDevice ../../../dix/devices.c:259 - #2 0x55c450e34840 in AllocDevicePair ../../../dix/devices.c:2755 - #3 0x55c45130318f in add_master ../../../Xi/xichangehierarchy.c:152 -../../../Xi/xichangehierarchy.c:465 - #5 0x55c4512cb9f5 in ProcIDispatch ../../../Xi/extinit.c:390 - #6 0x55c450e6a92b in Dispatch ../../../dix/dispatch.c:551 - #7 0x55c450e834b7 in dix_main ../../../dix/main.c:272 - #8 0x55c4517a8d93 in main ../../../dix/stubmain.c:34 -(/lib/x86_64-linux-gnu/libc.so.6+0x28564) - -The problem is caused by dev->master being not reset when disabling the -device, which then causes dangling pointer when the master device itself -is being deleted when exiting whole server. - -Note that RecalculateMasterButtons() requires dev->master to be still -valid, so we can reset it only at the end of function. - -Signed-off-by: Povilas Kanapickas ---- - dix/devices.c | 1 + - 1 file changed, 1 insertion(+) - -diff --git a/dix/devices.c b/dix/devices.c -index e62c34c55..5f9ce1678 100644 ---- a/dix/devices.c -+++ b/dix/devices.c -@@ -520,6 +520,7 @@ DisableDevice(DeviceIntPtr dev, BOOL sendevent) - } - - RecalculateMasterButtons(dev); -+ dev->master = NULL; - - return TRUE; - } --- -2.43.0 - diff --git a/0001-dix-allocate-enough-space-for-logical-button-maps.patch b/0001-dix-allocate-enough-space-for-logical-button-maps.patch deleted file mode 100644 index e11eb0e..0000000 --- a/0001-dix-allocate-enough-space-for-logical-button-maps.patch +++ /dev/null @@ -1,51 +0,0 @@ -From 9e2ecb2af8302dedc49cb6a63ebe063c58a9e7e3 Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Thu, 14 Dec 2023 11:29:49 +1000 -Subject: [PATCH 1/9] dix: allocate enough space for logical button maps - -Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for -each logical button currently down. Since buttons can be arbitrarily mapped -to anything up to 255 make sure we have enough bits for the maximum mapping. - -CVE-2023-6816, ZDI-CAN-22664, ZDI-CAN-22665 - -This vulnerability was discovered by: -Jan-Niklas Sohn working with Trend Micro Zero Day Initiative ---- - Xi/xiquerypointer.c | 3 +-- - dix/enterleave.c | 5 +++-- - 2 files changed, 4 insertions(+), 4 deletions(-) - -diff --git a/Xi/xiquerypointer.c b/Xi/xiquerypointer.c -index 5b77b1a44..2b05ac5f3 100644 ---- a/Xi/xiquerypointer.c -+++ b/Xi/xiquerypointer.c -@@ -149,8 +149,7 @@ ProcXIQueryPointer(ClientPtr client) - if (pDev->button) { - int i; - -- rep.buttons_len = -- bytes_to_int32(bits_to_bytes(pDev->button->numButtons)); -+ rep.buttons_len = bytes_to_int32(bits_to_bytes(256)); /* button map up to 255 */ - rep.length += rep.buttons_len; - buttons = calloc(rep.buttons_len, 4); - if (!buttons) -diff --git a/dix/enterleave.c b/dix/enterleave.c -index 867ec7436..ded8679d7 100644 ---- a/dix/enterleave.c -+++ b/dix/enterleave.c -@@ -784,8 +784,9 @@ DeviceFocusEvent(DeviceIntPtr dev, int type, int mode, int detail, - - mouse = IsFloating(dev) ? dev : GetMaster(dev, MASTER_POINTER); - -- /* XI 2 event */ -- btlen = (mouse->button) ? bits_to_bytes(mouse->button->numButtons) : 0; -+ /* XI 2 event contains the logical button map - maps are CARD8 -+ * so we need 256 bits for the possibly maximum mapping */ -+ btlen = (mouse->button) ? bits_to_bytes(256) : 0; - btlen = bytes_to_int32(btlen); - len = sizeof(xXIFocusInEvent) + btlen * 4; - --- -2.43.0 - diff --git a/0001-dix-fix-valuator-copy-paste-error-in-the-DeviceState.patch b/0001-dix-fix-valuator-copy-paste-error-in-the-DeviceState.patch deleted file mode 100644 index 363af1f..0000000 --- a/0001-dix-fix-valuator-copy-paste-error-in-the-DeviceState.patch +++ /dev/null @@ -1,33 +0,0 @@ -From 133e0d651c5d12bf01999d6289e84e224ba77adc Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Mon, 22 Jan 2024 14:22:12 +1000 -Subject: [PATCH] dix: fix valuator copy/paste error in the DeviceStateNotify - event - -Fixes 219c54b8a3337456ce5270ded6a67bcde53553d5 ---- - dix/enterleave.c | 6 +++--- - 1 file changed, 3 insertions(+), 3 deletions(-) - -diff --git a/dix/enterleave.c b/dix/enterleave.c -index 7b7ba1098..c1e6ac600 100644 ---- a/dix/enterleave.c -+++ b/dix/enterleave.c -@@ -619,11 +619,11 @@ FixDeviceValuator(DeviceIntPtr dev, deviceValuator * ev, ValuatorClassPtr v, - ev->first_valuator = first; - switch (ev->num_valuators) { - case 6: -- ev->valuator2 = v->axisVal[first + 5]; -+ ev->valuator5 = v->axisVal[first + 5]; - case 5: -- ev->valuator2 = v->axisVal[first + 4]; -+ ev->valuator4 = v->axisVal[first + 4]; - case 4: -- ev->valuator2 = v->axisVal[first + 3]; -+ ev->valuator3 = v->axisVal[first + 3]; - case 3: - ev->valuator2 = v->axisVal[first + 2]; - case 2: --- -2.44.0 - diff --git a/0001-hw-Rename-boolean-config-value-field-from-bool-to-bo.patch b/0001-hw-Rename-boolean-config-value-field-from-bool-to-bo.patch deleted file mode 100644 index 52ea4d0..0000000 --- a/0001-hw-Rename-boolean-config-value-field-from-bool-to-bo.patch +++ /dev/null @@ -1,154 +0,0 @@ -From 454b3a826edb5fc6d0fea3a9cfd1a5e8fc568747 Mon Sep 17 00:00:00 2001 -From: Adam Jackson -Date: Mon, 22 Jul 2019 13:51:06 -0400 -Subject: [PATCH xserver] hw: Rename boolean config value field from bool to - boolean - -"bool" conflicts with C++ (meh) and stdbool.h (ngh alright fine). This -is a driver-visible change and will likely break the build for mach64, -but it can be fixed by simply using xf86ReturnOptValBool like every -other driver. - -Signed-off-by: Adam Jackson ---- - hw/xfree86/common/xf86Opt.h | 2 +- - hw/xfree86/common/xf86Option.c | 10 +++++----- - hw/xwin/winconfig.c | 22 +++++++++++----------- - hw/xwin/winconfig.h | 2 +- - 4 files changed, 18 insertions(+), 18 deletions(-) - -diff --git a/hw/xfree86/common/xf86Opt.h b/hw/xfree86/common/xf86Opt.h -index 3be2a0fc7..3046fbd41 100644 ---- a/hw/xfree86/common/xf86Opt.h -+++ b/hw/xfree86/common/xf86Opt.h -@@ -41,7 +41,7 @@ typedef union { - unsigned long num; - const char *str; - double realnum; -- Bool bool; -+ Bool boolean; - OptFrequency freq; - } ValueUnion; - -diff --git a/hw/xfree86/common/xf86Option.c b/hw/xfree86/common/xf86Option.c -index 06973bca3..ca538cc57 100644 ---- a/hw/xfree86/common/xf86Option.c -+++ b/hw/xfree86/common/xf86Option.c -@@ -213,7 +213,7 @@ LookupBoolOption(XF86OptionPtr optlist, const char *name, int deflt, - o.name = name; - o.type = OPTV_BOOLEAN; - if (ParseOptionValue(-1, optlist, &o, markUsed)) -- deflt = o.value.bool; -+ deflt = o.value.boolean; - return deflt; - } - -@@ -474,7 +474,7 @@ xf86ShowUnusedOptions(int scrnIndex, XF86OptionPtr opt) - static Bool - GetBoolValue(OptionInfoPtr p, const char *s) - { -- return xf86getBoolValue(&p->value.bool, s); -+ return xf86getBoolValue(&p->value.boolean, s); - } - - static Bool -@@ -678,7 +678,7 @@ ParseOptionValue(int scrnIndex, XF86OptionPtr options, OptionInfoPtr p, - if (markUsed) - xf86MarkOptionUsedByName(options, newn); - if (GetBoolValue(&opt, s)) { -- p->value.bool = !opt.value.bool; -+ p->value.boolean = !opt.value.boolean; - p->found = TRUE; - } - else { -@@ -869,7 +869,7 @@ xf86GetOptValBool(const OptionInfoRec * table, int token, Bool *value) - - p = xf86TokenToOptinfo(table, token); - if (p && p->found) { -- *value = p->value.bool; -+ *value = p->value.boolean; - return TRUE; - } - else -@@ -883,7 +883,7 @@ xf86ReturnOptValBool(const OptionInfoRec * table, int token, Bool def) - - p = xf86TokenToOptinfo(table, token); - if (p && p->found) { -- return p->value.bool; -+ return p->value.boolean; - } - else - return def; -diff --git a/hw/xwin/winconfig.c b/hw/xwin/winconfig.c -index 31894d2fb..646d69006 100644 ---- a/hw/xwin/winconfig.c -+++ b/hw/xwin/winconfig.c -@@ -623,7 +623,7 @@ winSetBoolOption(void *optlist, const char *name, int deflt) - o.name = name; - o.type = OPTV_BOOLEAN; - if (ParseOptionValue(-1, optlist, &o)) -- deflt = o.value.bool; -+ deflt = o.value.boolean; - return deflt; - } - -@@ -918,7 +918,7 @@ ParseOptionValue(int scrnIndex, void *options, OptionInfoPtr p) - } - if ((s = winFindOptionValue(options, newn)) != NULL) { - if (GetBoolValue(&opt, s)) { -- p->value.bool = !opt.value.bool; -+ p->value.boolean = !opt.value.boolean; - p->found = TRUE; - } - else { -@@ -968,25 +968,25 @@ static Bool - GetBoolValue(OptionInfoPtr p, const char *s) - { - if (*s == 0) { -- p->value.bool = TRUE; -+ p->value.boolean = TRUE; - } - else { - if (winNameCompare(s, "1") == 0) -- p->value.bool = TRUE; -+ p->value.boolean = TRUE; - else if (winNameCompare(s, "on") == 0) -- p->value.bool = TRUE; -+ p->value.boolean = TRUE; - else if (winNameCompare(s, "true") == 0) -- p->value.bool = TRUE; -+ p->value.boolean = TRUE; - else if (winNameCompare(s, "yes") == 0) -- p->value.bool = TRUE; -+ p->value.boolean = TRUE; - else if (winNameCompare(s, "0") == 0) -- p->value.bool = FALSE; -+ p->value.boolean = FALSE; - else if (winNameCompare(s, "off") == 0) -- p->value.bool = FALSE; -+ p->value.boolean = FALSE; - else if (winNameCompare(s, "false") == 0) -- p->value.bool = FALSE; -+ p->value.boolean = FALSE; - else if (winNameCompare(s, "no") == 0) -- p->value.bool = FALSE; -+ p->value.boolean = FALSE; - } - return TRUE; - } -diff --git a/hw/xwin/winconfig.h b/hw/xwin/winconfig.h -index f079368c7..bd1f59650 100644 ---- a/hw/xwin/winconfig.h -+++ b/hw/xwin/winconfig.h -@@ -199,7 +199,7 @@ typedef union { - unsigned long num; - char *str; - double realnum; -- Bool bool; -+ Bool boolean; - OptFrequency freq; - } ValueUnion; - --- -2.39.0 - diff --git a/0001-present-Check-for-NULL-to-prevent-crash.patch b/0001-present-Check-for-NULL-to-prevent-crash.patch deleted file mode 100644 index 894ad0e..0000000 --- a/0001-present-Check-for-NULL-to-prevent-crash.patch +++ /dev/null @@ -1,43 +0,0 @@ -From 94b4a3d45451d29e9539ea234ce8b5e9ed58546c Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?B=C5=82a=C5=BCej=20Szczygie=C5=82?= -Date: Thu, 13 Jan 2022 00:47:27 +0100 -Subject: [PATCH xserver] present: Check for NULL to prevent crash -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Closes: https://gitlab.freedesktop.org/xorg/xserver/-/issues/1275 -Signed-off-by: Błażej Szczygieł -Tested-by: Aaron Plattner -(cherry picked from commit 22d5818851967408bb7c903cb345b7ca8766094c) ---- - present/present_scmd.c | 6 ++++++ - 1 file changed, 6 insertions(+) - -diff --git a/present/present_scmd.c b/present/present_scmd.c -index 3c68e690b..11391adbb 100644 ---- a/present/present_scmd.c -+++ b/present/present_scmd.c -@@ -168,6 +168,9 @@ present_scmd_get_crtc(present_screen_priv_ptr screen_priv, WindowPtr window) - if (!screen_priv->info) - return NULL; - -+ if (!screen_priv->info->get_crtc) -+ return NULL; -+ - return (*screen_priv->info->get_crtc)(window); - } - -@@ -206,6 +209,9 @@ present_flush(WindowPtr window) - if (!screen_priv->info) - return; - -+ if (!screen_priv->info->flush) -+ return; -+ - (*screen_priv->info->flush) (window); - } - --- -2.34.1 - diff --git a/0001-present-Send-a-PresentConfigureNotify-event-for-dest.patch b/0001-present-Send-a-PresentConfigureNotify-event-for-dest.patch deleted file mode 100644 index d9eea48..0000000 --- a/0001-present-Send-a-PresentConfigureNotify-event-for-dest.patch +++ /dev/null @@ -1,105 +0,0 @@ -From b98fc07d3442a289c6bef82df50dd0a2d01de71a Mon Sep 17 00:00:00 2001 -From: Adam Jackson -Date: Thu, 2 Feb 2023 12:26:27 -0500 -Subject: [PATCH xserver] present: Send a PresentConfigureNotify event for - destroyed windows -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -This enables fixing a deadlock case on the client side, where the client -ends up blocked waiting for a Present event that will never come because -the window was destroyed. The new PresentWindowDestroyed flag allows the -client to avoid blocking indefinitely. - -Signed-off-by: Adam Jackson -See-also: https://gitlab.freedesktop.org/mesa/mesa/-/issues/116 -See-also: https://gitlab.freedesktop.org/mesa/mesa/-/issues/6685 -Reviewed-by: Michel Dänzer -(cherry picked from commit 462b06033e66a32308d940eb5fc47f5e4c914dc0) ---- - present/present_event.c | 5 +++-- - present/present_priv.h | 7 ++++++- - present/present_screen.c | 11 ++++++++++- - 3 files changed, 19 insertions(+), 4 deletions(-) - -diff --git a/present/present_event.c b/present/present_event.c -index 435b26b70..849732dc8 100644 ---- a/present/present_event.c -+++ b/present/present_event.c -@@ -102,7 +102,8 @@ present_event_swap(xGenericEvent *from, xGenericEvent *to) - } - - void --present_send_config_notify(WindowPtr window, int x, int y, int w, int h, int bw, WindowPtr sibling) -+present_send_config_notify(WindowPtr window, int x, int y, int w, int h, -+ int bw, WindowPtr sibling, CARD32 flags) - { - present_window_priv_ptr window_priv = present_window_priv(window); - -@@ -122,7 +123,7 @@ present_send_config_notify(WindowPtr window, int x, int y, int w, int h, int bw, - .off_y = 0, - .pixmap_width = w, - .pixmap_height = h, -- .pixmap_flags = 0 -+ .pixmap_flags = flags - }; - present_event_ptr event; - -diff --git a/present/present_priv.h b/present/present_priv.h -index 6ebd009a2..4ad729864 100644 ---- a/present/present_priv.h -+++ b/present/present_priv.h -@@ -43,6 +43,11 @@ - #define DebugPresent(x) - #endif - -+/* XXX this belongs in presentproto */ -+#ifndef PresentWindowDestroyed -+#define PresentWindowDestroyed (1 << 0) -+#endif -+ - extern int present_request; - - extern DevPrivateKeyRec present_screen_private_key; -@@ -307,7 +312,7 @@ void - present_free_events(WindowPtr window); - - void --present_send_config_notify(WindowPtr window, int x, int y, int w, int h, int bw, WindowPtr sibling); -+present_send_config_notify(WindowPtr window, int x, int y, int w, int h, int bw, WindowPtr sibling, CARD32 flags); - - void - present_send_complete_notify(WindowPtr window, CARD8 kind, CARD8 mode, CARD32 serial, uint64_t ust, uint64_t msc); -diff --git a/present/present_screen.c b/present/present_screen.c -index 15684eda4..2c29aafd2 100644 ---- a/present/present_screen.c -+++ b/present/present_screen.c -@@ -93,6 +93,15 @@ present_destroy_window(WindowPtr window) - present_screen_priv_ptr screen_priv = present_screen_priv(screen); - present_window_priv_ptr window_priv = present_window_priv(window); - -+ present_send_config_notify(window, -+ window->drawable.x, -+ window->drawable.y, -+ window->drawable.width, -+ window->drawable.height, -+ window->borderWidth, -+ window->nextSib, -+ PresentWindowDestroyed); -+ - if (window_priv) { - present_clear_window_notifies(window); - present_free_events(window); -@@ -123,7 +132,7 @@ present_config_notify(WindowPtr window, - ScreenPtr screen = window->drawable.pScreen; - present_screen_priv_ptr screen_priv = present_screen_priv(screen); - -- present_send_config_notify(window, x, y, w, h, bw, sibling); -+ present_send_config_notify(window, x, y, w, h, bw, sibling, 0); - - unwrap(screen_priv, screen, ConfigNotify); - if (screen->ConfigNotify) --- -2.40.0 - diff --git a/0001-randr-avoid-integer-truncation-in-length-check-of-Pr.patch b/0001-randr-avoid-integer-truncation-in-length-check-of-Pr.patch deleted file mode 100644 index d88a8d5..0000000 --- a/0001-randr-avoid-integer-truncation-in-length-check-of-Pr.patch +++ /dev/null @@ -1,61 +0,0 @@ -From 58e83c683950ac9e253ab05dd7a13a8368b70a3c Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Mon, 27 Nov 2023 16:27:49 +1000 -Subject: [PATCH xserver] randr: avoid integer truncation in length check of - ProcRRChange*Property - -Affected are ProcRRChangeProviderProperty and ProcRRChangeOutputProperty. -See also xserver@8f454b79 where this same bug was fixed for the core -protocol and XI. - -This fixes an OOB read and the resulting information disclosure. - -Length calculation for the request was clipped to a 32-bit integer. With -the correct stuff->nUnits value the expected request size was -truncated, passing the REQUEST_FIXED_SIZE check. - -The server then proceeded with reading at least stuff->num_items bytes -(depending on stuff->format) from the request and stuffing whatever it -finds into the property. In the process it would also allocate at least -stuff->nUnits bytes, i.e. 4GB. - -CVE-2023-6478, ZDI-CAN-22561 - -This vulnerability was discovered by: -Jan-Niklas Sohn working with Trend Micro Zero Day Initiative - -(cherry picked from commit 14f480010a93ff962fef66a16412fafff81ad632) ---- - randr/rrproperty.c | 2 +- - randr/rrproviderproperty.c | 2 +- - 2 files changed, 2 insertions(+), 2 deletions(-) - -diff --git a/randr/rrproperty.c b/randr/rrproperty.c -index 25469f57b2..c4fef8a1f6 100644 ---- a/randr/rrproperty.c -+++ b/randr/rrproperty.c -@@ -530,7 +530,7 @@ ProcRRChangeOutputProperty(ClientPtr client) - char format, mode; - unsigned long len; - int sizeInBytes; -- int totalSize; -+ uint64_t totalSize; - int err; - - REQUEST_AT_LEAST_SIZE(xRRChangeOutputPropertyReq); -diff --git a/randr/rrproviderproperty.c b/randr/rrproviderproperty.c -index b79c17f9bf..90c5a9a933 100644 ---- a/randr/rrproviderproperty.c -+++ b/randr/rrproviderproperty.c -@@ -498,7 +498,7 @@ ProcRRChangeProviderProperty(ClientPtr client) - char format, mode; - unsigned long len; - int sizeInBytes; -- int totalSize; -+ uint64_t totalSize; - int err; - - REQUEST_AT_LEAST_SIZE(xRRChangeProviderPropertyReq); --- -2.43.0 - diff --git a/0001-render-Avoid-possible-double-free-in-ProcRenderAddGl.patch b/0001-render-Avoid-possible-double-free-in-ProcRenderAddGl.patch deleted file mode 100644 index 549f90a..0000000 --- a/0001-render-Avoid-possible-double-free-in-ProcRenderAddGl.patch +++ /dev/null @@ -1,72 +0,0 @@ -From 337d8d48b618d4fc0168a7b978be4c3447650b04 Mon Sep 17 00:00:00 2001 -From: Olivier Fourdan -Date: Fri, 5 Apr 2024 15:24:49 +0200 -Subject: [PATCH] render: Avoid possible double-free in ProcRenderAddGlyphs() - -ProcRenderAddGlyphs() adds the glyph to the glyphset using AddGlyph() and -then frees it using FreeGlyph() to decrease the reference count, after -AddGlyph() has increased it. - -AddGlyph() however may chose to reuse an existing glyph if it's already -in the glyphSet, and free the glyph that was given, in which case the -caller function, ProcRenderAddGlyphs() will call FreeGlyph() on an -already freed glyph, as reported by ASan: - - READ of size 4 thread T0 - #0 in FreeGlyph xserver/render/glyph.c:252 - #1 in ProcRenderAddGlyphs xserver/render/render.c:1174 - #2 in Dispatch xserver/dix/dispatch.c:546 - #3 in dix_main xserver/dix/main.c:271 - #4 in main xserver/dix/stubmain.c:34 - #5 in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58 - #6 in __libc_start_main_impl ../csu/libc-start.c:360 - #7 (/usr/bin/Xwayland+0x44fe4) - Address is located 0 bytes inside of 64-byte region - freed by thread T0 here: - #0 in __interceptor_free libsanitizer/asan/asan_malloc_linux.cpp:52 - #1 in _dixFreeObjectWithPrivates xserver/dix/privates.c:538 - #2 in AddGlyph xserver/render/glyph.c:295 - #3 in ProcRenderAddGlyphs xserver/render/render.c:1173 - #4 in Dispatch xserver/dix/dispatch.c:546 - #5 in dix_main xserver/dix/main.c:271 - #6 in main xserver/dix/stubmain.c:34 - #7 in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58 - previously allocated by thread T0 here: - #0 in __interceptor_malloc libsanitizer/asan/asan_malloc_linux.cpp:69 - #1 in AllocateGlyph xserver/render/glyph.c:355 - #2 in ProcRenderAddGlyphs xserver/render/render.c:1085 - #3 in Dispatch xserver/dix/dispatch.c:546 - #4 in dix_main xserver/dix/main.c:271 - #5 in main xserver/dix/stubmain.c:34 - #6 in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58 - SUMMARY: AddressSanitizer: heap-use-after-free xserver/render/glyph.c:252 in FreeGlyph - -To avoid that, make sure not to free the given glyph in AddGlyph(). - -v2: Simplify the test using the boolean returned from AddGlyph() (Michel) -v3: Simplify even more by not freeing the glyph in AddGlyph() (Peter) - -Fixes: bdca6c3d1 - render: fix refcounting of glyphs during ProcRenderAddGlyphs -Closes: https://gitlab.freedesktop.org/xorg/xserver/-/issues/1659 -Signed-off-by: Olivier Fourdan -Part-of: ---- - render/glyph.c | 2 -- - 1 file changed, 2 deletions(-) - -diff --git a/render/glyph.c b/render/glyph.c -index 13991f8a1..5fa7f3b5b 100644 ---- a/render/glyph.c -+++ b/render/glyph.c -@@ -291,8 +291,6 @@ AddGlyph(GlyphSetPtr glyphSet, GlyphPtr glyph, Glyph id) - gr = FindGlyphRef(&globalGlyphs[glyphSet->fdepth], signature, - TRUE, glyph->sha1); - if (gr->glyph && gr->glyph != DeletedGlyph && gr->glyph != glyph) { -- FreeGlyphPicture(glyph); -- dixFreeObjectWithPrivates(glyph, PRIVATE_GLYPH); - glyph = gr->glyph; - } - else if (gr->glyph != glyph) { --- -2.44.0 - diff --git a/0001-render-Fix-build-with-gcc-12.patch b/0001-render-Fix-build-with-gcc-12.patch deleted file mode 100644 index 22f2e5a..0000000 --- a/0001-render-Fix-build-with-gcc-12.patch +++ /dev/null @@ -1,90 +0,0 @@ -From 53173fdab492f0f638f6616fcf01af0b9ea6338d Mon Sep 17 00:00:00 2001 -From: Olivier Fourdan -Date: Thu, 20 Jan 2022 10:20:38 +0100 -Subject: [PATCH xserver] render: Fix build with gcc 12 -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -The xserver fails to compile with the latest gcc 12: - - render/picture.c: In function ‘CreateSolidPicture’: - render/picture.c:874:26: error: array subscript ‘union _SourcePict[0]’ is partly outside array bounds of ‘unsigned char[16]’ [-Werror=array-bounds] - 874 | pPicture->pSourcePict->type = SourcePictTypeSolidFill; - | ^~ - render/picture.c:868:45: note: object of size 16 allocated by ‘malloc’ - 868 | pPicture->pSourcePict = (SourcePictPtr) malloc(sizeof(PictSolidFill)); - | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - render/picture.c: In function ‘CreateLinearGradientPicture’: - render/picture.c:906:26: error: array subscript ‘union _SourcePict[0]’ is partly outside array bounds of ‘unsigned char[32]’ [-Werror=array-bounds] - 906 | pPicture->pSourcePict->linear.type = SourcePictTypeLinear; - | ^~ - render/picture.c:899:45: note: object of size 32 allocated by ‘malloc’ - 899 | pPicture->pSourcePict = (SourcePictPtr) malloc(sizeof(PictLinearGradient)); - | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - render/picture.c: In function ‘CreateConicalGradientPicture’: - render/picture.c:989:26: error: array subscript ‘union _SourcePict[0]’ is partly outside array bounds of ‘unsigned char[32]’ [-Werror=array-bounds] - 989 | pPicture->pSourcePict->conical.type = SourcePictTypeConical; - | ^~ - render/picture.c:982:45: note: object of size 32 allocated by ‘malloc’ - 982 | pPicture->pSourcePict = (SourcePictPtr) malloc(sizeof(PictConicalGradient)); - | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - cc1: some warnings being treated as errors - ninja: build stopped: subcommand failed. - -This is because gcc 12 has become stricter and raises a warning now. - -Fix the warning/error by allocating enough memory to store the union -struct. - -Signed-off-by: Olivier Fourdan -Acked-by: Michel Dänzer -Closes: https://gitlab.freedesktop.org/xorg/xserver/-/issues/1256 -(cherry picked from commit c6b0dcb82d4db07a2f32c09a8c09c85a5f57248e) ---- - render/picture.c | 8 ++++---- - 1 file changed, 4 insertions(+), 4 deletions(-) - -diff --git a/render/picture.c b/render/picture.c -index afa0d258f..2be4b1954 100644 ---- a/render/picture.c -+++ b/render/picture.c -@@ -865,7 +865,7 @@ CreateSolidPicture(Picture pid, xRenderColor * color, int *error) - } - - pPicture->id = pid; -- pPicture->pSourcePict = (SourcePictPtr) malloc(sizeof(PictSolidFill)); -+ pPicture->pSourcePict = (SourcePictPtr) malloc(sizeof(SourcePict)); - if (!pPicture->pSourcePict) { - *error = BadAlloc; - free(pPicture); -@@ -896,7 +896,7 @@ CreateLinearGradientPicture(Picture pid, xPointFixed * p1, xPointFixed * p2, - } - - pPicture->id = pid; -- pPicture->pSourcePict = (SourcePictPtr) malloc(sizeof(PictLinearGradient)); -+ pPicture->pSourcePict = (SourcePictPtr) malloc(sizeof(SourcePict)); - if (!pPicture->pSourcePict) { - *error = BadAlloc; - free(pPicture); -@@ -936,7 +936,7 @@ CreateRadialGradientPicture(Picture pid, xPointFixed * inner, - } - - pPicture->id = pid; -- pPicture->pSourcePict = (SourcePictPtr) malloc(sizeof(PictRadialGradient)); -+ pPicture->pSourcePict = (SourcePictPtr) malloc(sizeof(SourcePict)); - if (!pPicture->pSourcePict) { - *error = BadAlloc; - free(pPicture); -@@ -979,7 +979,7 @@ CreateConicalGradientPicture(Picture pid, xPointFixed * center, xFixed angle, - } - - pPicture->id = pid; -- pPicture->pSourcePict = (SourcePictPtr) malloc(sizeof(PictConicalGradient)); -+ pPicture->pSourcePict = (SourcePictPtr) malloc(sizeof(SourcePict)); - if (!pPicture->pSourcePict) { - *error = BadAlloc; - free(pPicture); --- -2.34.1 - diff --git a/0001-xf86-Accept-devices-with-the-simpledrm-driver.patch b/0001-xf86-Accept-devices-with-the-simpledrm-driver.patch deleted file mode 100644 index 3dc5796..0000000 --- a/0001-xf86-Accept-devices-with-the-simpledrm-driver.patch +++ /dev/null @@ -1,34 +0,0 @@ -From b9218fadf3c09d83566549279d68886d8258f79c Mon Sep 17 00:00:00 2001 -From: nerdopolis -Date: Thu, 30 Sep 2021 08:51:18 -0400 -Subject: [PATCH] xf86: Accept devices with the 'simpledrm' driver. - -SimpleDRM 'devices' are a fallback device, and do not have a busid -so they are getting skipped. This will allow simpledrm to work -with the modesetting driver ---- - hw/xfree86/common/xf86platformBus.c | 7 ++++++- - 1 file changed, 6 insertions(+), 1 deletion(-) - -diff --git a/hw/xfree86/common/xf86platformBus.c b/hw/xfree86/common/xf86platformBus.c -index 0e0a995ac..45028f7a6 100644 ---- a/hw/xfree86/common/xf86platformBus.c -+++ b/hw/xfree86/common/xf86platformBus.c -@@ -557,8 +557,13 @@ xf86platformProbeDev(DriverPtr drvp) - } - else { - /* for non-seat0 servers assume first device is the master */ -- if (ServerIsNotSeat0()) -+ if (ServerIsNotSeat0()) { - break; -+ } else { -+ /* Accept the device if the driver is simpledrm */ -+ if (strcmp(xf86_platform_devices[j].attribs->driver, "simpledrm") == 0) -+ break; -+ } - - if (xf86IsPrimaryPlatform(&xf86_platform_devices[j])) - break; --- -2.35.1 - diff --git a/0001-xkb-fix-some-possible-memleaks-in-XkbGetKbdByName.patch b/0001-xkb-fix-some-possible-memleaks-in-XkbGetKbdByName.patch deleted file mode 100644 index 6e5ebb5..0000000 --- a/0001-xkb-fix-some-possible-memleaks-in-XkbGetKbdByName.patch +++ /dev/null @@ -1,59 +0,0 @@ -From 18f91b950e22c2a342a4fbc55e9ddf7534a707d2 Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Wed, 13 Jul 2022 11:23:09 +1000 -Subject: [PATCH xserver] xkb: fix some possible memleaks in XkbGetKbdByName - -GetComponentByName returns an allocated string, so let's free that if we -fail somewhere. - -Signed-off-by: Peter Hutterer ---- - xkb/xkb.c | 26 ++++++++++++++++++++------ - 1 file changed, 20 insertions(+), 6 deletions(-) - -diff --git a/xkb/xkb.c b/xkb/xkb.c -index 4692895db..b79a269e3 100644 ---- a/xkb/xkb.c -+++ b/xkb/xkb.c -@@ -5935,18 +5935,32 @@ ProcXkbGetKbdByName(ClientPtr client) - xkb = dev->key->xkbInfo->desc; - status = Success; - str = (unsigned char *) &stuff[1]; -- if (GetComponentSpec(&str, TRUE, &status)) /* keymap, unsupported */ -- return BadMatch; -+ { -+ char *keymap = GetComponentSpec(&str, TRUE, &status); /* keymap, unsupported */ -+ if (keymap) { -+ free(keymap); -+ return BadMatch; -+ } -+ } - names.keycodes = GetComponentSpec(&str, TRUE, &status); - names.types = GetComponentSpec(&str, TRUE, &status); - names.compat = GetComponentSpec(&str, TRUE, &status); - names.symbols = GetComponentSpec(&str, TRUE, &status); - names.geometry = GetComponentSpec(&str, TRUE, &status); -- if (status != Success) -+ if (status == Success) { -+ len = str - ((unsigned char *) stuff); -+ if ((XkbPaddedSize(len) / 4) != stuff->length) -+ status = BadLength; -+ } -+ -+ if (status != Success) { -+ free(names.keycodes); -+ free(names.types); -+ free(names.compat); -+ free(names.symbols); -+ free(names.geometry); - return status; -- len = str - ((unsigned char *) stuff); -- if ((XkbPaddedSize(len) / 4) != stuff->length) -- return BadLength; -+ } - - CHK_MASK_LEGAL(0x01, stuff->want, XkbGBN_AllComponentsMask); - CHK_MASK_LEGAL(0x02, stuff->need, XkbGBN_AllComponentsMask); --- -2.38.1 - diff --git a/0001-xkb-proof-GetCountedString-against-request-length-at.patch b/0001-xkb-proof-GetCountedString-against-request-length-at.patch deleted file mode 100644 index d358a32..0000000 --- a/0001-xkb-proof-GetCountedString-against-request-length-at.patch +++ /dev/null @@ -1,35 +0,0 @@ -From 11beef0b7f1ed290348e45618e5fa0d2bffcb72e Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Tue, 5 Jul 2022 12:06:20 +1000 -Subject: [PATCH xserver] xkb: proof GetCountedString against request length - attacks - -GetCountedString did a check for the whole string to be within the -request buffer but not for the initial 2 bytes that contain the length -field. A swapped client could send a malformed request to trigger a -swaps() on those bytes, writing into random memory. - -Signed-off-by: Peter Hutterer ---- - xkb/xkb.c | 5 +++++ - 1 file changed, 5 insertions(+) - -diff --git a/xkb/xkb.c b/xkb/xkb.c -index f42f59ef3..1841cff26 100644 ---- a/xkb/xkb.c -+++ b/xkb/xkb.c -@@ -5137,6 +5137,11 @@ _GetCountedString(char **wire_inout, ClientPtr client, char **str) - CARD16 len; - - wire = *wire_inout; -+ -+ if (client->req_len < -+ bytes_to_int32(wire + 2 - (char *) client->requestBuffer)) -+ return BadValue; -+ - len = *(CARD16 *) wire; - if (client->swapped) { - swaps(&len); --- -2.38.1 - diff --git a/0001-xkb-switch-to-array-index-loops-to-moving-pointers.patch b/0001-xkb-switch-to-array-index-loops-to-moving-pointers.patch deleted file mode 100644 index a4efb7a..0000000 --- a/0001-xkb-switch-to-array-index-loops-to-moving-pointers.patch +++ /dev/null @@ -1,76 +0,0 @@ -From f1070c01d616c5f21f939d5ebc533738779451ac Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Tue, 5 Jul 2022 12:40:47 +1000 -Subject: [PATCH xserver 1/3] xkb: switch to array index loops to moving - pointers - -Most similar loops here use a pointer that advances with each loop -iteration, let's do the same here for consistency. - -No functional changes. - -Signed-off-by: Peter Hutterer -Reviewed-by: Olivier Fourdan ---- - xkb/xkb.c | 20 ++++++++++---------- - 1 file changed, 10 insertions(+), 10 deletions(-) - -diff --git a/xkb/xkb.c b/xkb/xkb.c -index a29262c24..64e52611e 100644 ---- a/xkb/xkb.c -+++ b/xkb/xkb.c -@@ -5368,16 +5368,16 @@ _CheckSetSections(XkbGeometryPtr geom, - row->left = rWire->left; - row->vertical = rWire->vertical; - kWire = (xkbKeyWireDesc *) &rWire[1]; -- for (k = 0; k < rWire->nKeys; k++) { -+ for (k = 0; k < rWire->nKeys; k++, kWire++) { - XkbKeyPtr key; - - key = XkbAddGeomKey(row); - if (!key) - return BadAlloc; -- memcpy(key->name.name, kWire[k].name, XkbKeyNameLength); -- key->gap = kWire[k].gap; -- key->shape_ndx = kWire[k].shapeNdx; -- key->color_ndx = kWire[k].colorNdx; -+ memcpy(key->name.name, kWire->name, XkbKeyNameLength); -+ key->gap = kWire->gap; -+ key->shape_ndx = kWire->shapeNdx; -+ key->color_ndx = kWire->colorNdx; - if (key->shape_ndx >= geom->num_shapes) { - client->errorValue = _XkbErrCode3(0x10, key->shape_ndx, - geom->num_shapes); -@@ -5389,7 +5389,7 @@ _CheckSetSections(XkbGeometryPtr geom, - return BadMatch; - } - } -- rWire = (xkbRowWireDesc *) &kWire[rWire->nKeys]; -+ rWire = (xkbRowWireDesc *)kWire; - } - wire = (char *) rWire; - if (sWire->nDoodads > 0) { -@@ -5454,16 +5454,16 @@ _CheckSetShapes(XkbGeometryPtr geom, - return BadAlloc; - ol->corner_radius = olWire->cornerRadius; - ptWire = (xkbPointWireDesc *) &olWire[1]; -- for (p = 0, pt = ol->points; p < olWire->nPoints; p++, pt++) { -- pt->x = ptWire[p].x; -- pt->y = ptWire[p].y; -+ for (p = 0, pt = ol->points; p < olWire->nPoints; p++, pt++, ptWire++) { -+ pt->x = ptWire->x; -+ pt->y = ptWire->y; - if (client->swapped) { - swaps(&pt->x); - swaps(&pt->y); - } - } - ol->num_points = olWire->nPoints; -- olWire = (xkbOutlineWireDesc *) (&ptWire[olWire->nPoints]); -+ olWire = (xkbOutlineWireDesc *)ptWire; - } - if (shapeWire->primaryNdx != XkbNoShape) - shape->primary = &shape->outlines[shapeWire->primaryNdx]; --- -2.36.1 - diff --git a/0002-Xi-ProcXIPassiveGrabDevice-needs-to-use-unswapped-le.patch b/0002-Xi-ProcXIPassiveGrabDevice-needs-to-use-unswapped-le.patch deleted file mode 100644 index 4e061f7..0000000 --- a/0002-Xi-ProcXIPassiveGrabDevice-needs-to-use-unswapped-le.patch +++ /dev/null @@ -1,43 +0,0 @@ -From 3e77295f888c67fc7645db5d0c00926a29ffecee Mon Sep 17 00:00:00 2001 -From: Alan Coopersmith -Date: Fri, 22 Mar 2024 18:56:27 -0700 -Subject: [PATCH 2/4] Xi: ProcXIPassiveGrabDevice needs to use unswapped length - to send reply - -CVE-2024-31081 - -Fixes: d220d6907 ("Xi: add GrabButton and GrabKeysym code.") -Signed-off-by: Alan Coopersmith -Part-of: ---- - Xi/xipassivegrab.c | 5 ++++- - 1 file changed, 4 insertions(+), 1 deletion(-) - -diff --git a/Xi/xipassivegrab.c b/Xi/xipassivegrab.c -index c9ac2f855..896233bec 100644 ---- a/Xi/xipassivegrab.c -+++ b/Xi/xipassivegrab.c -@@ -93,6 +93,7 @@ ProcXIPassiveGrabDevice(ClientPtr client) - GrabParameters param; - void *tmp; - int mask_len; -+ uint32_t length; - - REQUEST(xXIPassiveGrabDeviceReq); - REQUEST_FIXED_SIZE(xXIPassiveGrabDeviceReq, -@@ -247,9 +248,11 @@ ProcXIPassiveGrabDevice(ClientPtr client) - } - } - -+ /* save the value before SRepXIPassiveGrabDevice swaps it */ -+ length = rep.length; - WriteReplyToClient(client, sizeof(rep), &rep); - if (rep.num_modifiers) -- WriteToClient(client, rep.length * 4, modifiers_failed); -+ WriteToClient(client, length * 4, modifiers_failed); - - out: - free(modifiers_failed); --- -2.44.0 - diff --git a/0002-Xi-return-an-error-from-XI-property-changes-if-verif.patch b/0002-Xi-return-an-error-from-XI-property-changes-if-verif.patch deleted file mode 100644 index 72bcadb..0000000 --- a/0002-Xi-return-an-error-from-XI-property-changes-if-verif.patch +++ /dev/null @@ -1,41 +0,0 @@ -From c5ff57676698f19ed3a1402aef58a15552e32d27 Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Tue, 29 Nov 2022 13:24:00 +1000 -Subject: [PATCH xserver 2/7] Xi: return an error from XI property changes if - verification failed - -Both ProcXChangeDeviceProperty and ProcXIChangeProperty checked the -property for validity but didn't actually return the potential error. - -Signed-off-by: Peter Hutterer -Acked-by: Olivier Fourdan ---- - Xi/xiproperty.c | 5 +++++ - 1 file changed, 5 insertions(+) - -diff --git a/Xi/xiproperty.c b/Xi/xiproperty.c -index a36f7d61df..68c362c628 100644 ---- a/Xi/xiproperty.c -+++ b/Xi/xiproperty.c -@@ -902,6 +902,8 @@ ProcXChangeDeviceProperty(ClientPtr client) - - rc = check_change_property(client, stuff->property, stuff->type, - stuff->format, stuff->mode, stuff->nUnits); -+ if (rc != Success) -+ return rc; - - len = stuff->nUnits; - if (len > (bytes_to_int32(0xffffffff - sizeof(xChangeDevicePropertyReq)))) -@@ -1141,6 +1143,9 @@ ProcXIChangeProperty(ClientPtr client) - - rc = check_change_property(client, stuff->property, stuff->type, - stuff->format, stuff->mode, stuff->num_items); -+ if (rc != Success) -+ return rc; -+ - len = stuff->num_items; - if (len > bytes_to_int32(0xffffffff - sizeof(xXIChangePropertyReq))) - return BadLength; --- -2.38.1 - diff --git a/0002-dix-Allocate-sufficient-xEvents-for-our-DeviceStateN.patch b/0002-dix-Allocate-sufficient-xEvents-for-our-DeviceStateN.patch deleted file mode 100644 index 21c5622..0000000 --- a/0002-dix-Allocate-sufficient-xEvents-for-our-DeviceStateN.patch +++ /dev/null @@ -1,84 +0,0 @@ -From ece23be888a93b741aa1209d1dbf64636109d6a5 Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Mon, 18 Dec 2023 14:27:50 +1000 -Subject: [PATCH 2/9] dix: Allocate sufficient xEvents for our - DeviceStateNotify - -If a device has both a button class and a key class and numButtons is -zero, we can get an OOB write due to event under-allocation. - -This function seems to assume a device has either keys or buttons, not -both. It has two virtually identical code paths, both of which assume -they're applying to the first event in the sequence. - -A device with both a key and button class triggered a logic bug - only -one xEvent was allocated but the deviceStateNotify pointer was pushed on -once per type. So effectively this logic code: - - int count = 1; - if (button && nbuttons > 32) count++; - if (key && nbuttons > 0) count++; - if (key && nkeys > 32) count++; // this is basically always true - // count is at 2 for our keys + zero button device - - ev = alloc(count * sizeof(xEvent)); - FixDeviceStateNotify(ev); - if (button) - FixDeviceStateNotify(ev++); - if (key) - FixDeviceStateNotify(ev++); // santa drops into the wrong chimney here - -If the device has more than 3 valuators, the OOB is pushed back - we're -off by one so it will happen when the last deviceValuator event is -written instead. - -Fix this by allocating the maximum number of events we may allocate. -Note that the current behavior is not protocol-correct anyway, this -patch fixes only the allocation issue. - -Note that this issue does not trigger if the device has at least one -button. While the server does not prevent a button class with zero -buttons, it is very unlikely. - -CVE-2024-0229, ZDI-CAN-22678 - -This vulnerability was discovered by: -Jan-Niklas Sohn working with Trend Micro Zero Day Initiative ---- - dix/enterleave.c | 6 +++--- - 1 file changed, 3 insertions(+), 3 deletions(-) - -diff --git a/dix/enterleave.c b/dix/enterleave.c -index ded8679d7..17964b00a 100644 ---- a/dix/enterleave.c -+++ b/dix/enterleave.c -@@ -675,7 +675,8 @@ static void - DeliverStateNotifyEvent(DeviceIntPtr dev, WindowPtr win) - { - int evcount = 1; -- deviceStateNotify *ev, *sev; -+ deviceStateNotify sev[6 + (MAX_VALUATORS + 2)/3]; -+ deviceStateNotify *ev; - deviceKeyStateNotify *kev; - deviceButtonStateNotify *bev; - -@@ -714,7 +715,7 @@ DeliverStateNotifyEvent(DeviceIntPtr dev, WindowPtr win) - } - } - -- sev = ev = xallocarray(evcount, sizeof(xEvent)); -+ ev = sev; - FixDeviceStateNotify(dev, ev, NULL, NULL, NULL, first); - - if (b != NULL) { -@@ -770,7 +771,6 @@ DeliverStateNotifyEvent(DeviceIntPtr dev, WindowPtr win) - - DeliverEventsToWindow(dev, win, (xEvent *) sev, evcount, - DeviceStateNotifyMask, NullGrab); -- free(sev); - } - - void --- -2.43.0 - diff --git a/0002-mi-reset-the-PointerWindows-reference-on-screen-swit.patch b/0002-mi-reset-the-PointerWindows-reference-on-screen-swit.patch deleted file mode 100644 index cbe9804..0000000 --- a/0002-mi-reset-the-PointerWindows-reference-on-screen-swit.patch +++ /dev/null @@ -1,99 +0,0 @@ -From 004f461c440cb6611eefb48fbbb4fa53a6d49f80 Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Thu, 5 Oct 2023 12:19:45 +1000 -Subject: [PATCH xserver 2/4] mi: reset the PointerWindows reference on screen - switch - -PointerWindows[] keeps a reference to the last window our sprite -entered - changes are usually handled by CheckMotion(). - -If we switch between screens via XWarpPointer our -dev->spriteInfo->sprite->win is set to the new screen's root window. -If there's another window at the cursor location CheckMotion() will -trigger the right enter/leave events later. If there is not, it skips -that process and we never trigger LeaveWindow() - PointerWindows[] for -the device still refers to the previous window. - -If that window is destroyed we have a dangling reference that will -eventually cause a use-after-free bug when checking the window hierarchy -later. - -To trigger this, we require: -- two protocol screens -- XWarpPointer to the other screen's root window -- XDestroyWindow before entering any other window - -This is a niche bug so we hack around it by making sure we reset the -PointerWindows[] entry so we cannot have a dangling pointer. This -doesn't handle Enter/Leave events correctly but the previous code didn't -either. - -CVE-2023-5380, ZDI-CAN-21608 - -This vulnerability was discovered by: -Sri working with Trend Micro Zero Day Initiative - -Signed-off-by: Peter Hutterer -Reviewed-by: Adam Jackson ---- - dix/enterleave.h | 2 -- - include/eventstr.h | 3 +++ - mi/mipointer.c | 17 +++++++++++++++-- - 3 files changed, 18 insertions(+), 4 deletions(-) - -diff --git a/dix/enterleave.h b/dix/enterleave.h -index 4b833d8a3b..e8af924c68 100644 ---- a/dix/enterleave.h -+++ b/dix/enterleave.h -@@ -58,8 +58,6 @@ extern void DeviceFocusEvent(DeviceIntPtr dev, - - extern void EnterWindow(DeviceIntPtr dev, WindowPtr win, int mode); - --extern void LeaveWindow(DeviceIntPtr dev); -- - extern void CoreFocusEvent(DeviceIntPtr kbd, - int type, int mode, int detail, WindowPtr pWin); - -diff --git a/include/eventstr.h b/include/eventstr.h -index bf3b95fe4a..2bae3b0767 100644 ---- a/include/eventstr.h -+++ b/include/eventstr.h -@@ -296,4 +296,7 @@ union _InternalEvent { - #endif - }; - -+extern void -+LeaveWindow(DeviceIntPtr dev); -+ - #endif -diff --git a/mi/mipointer.c b/mi/mipointer.c -index 75be1aeeb8..b12ae9be1d 100644 ---- a/mi/mipointer.c -+++ b/mi/mipointer.c -@@ -397,8 +397,21 @@ miPointerWarpCursor(DeviceIntPtr pDev, ScreenPtr pScreen, int x, int y) - #ifdef PANORAMIX - && noPanoramiXExtension - #endif -- ) -- UpdateSpriteForScreen(pDev, pScreen); -+ ) { -+ DeviceIntPtr master = GetMaster(pDev, MASTER_POINTER); -+ /* Hack for CVE-2023-5380: if we're moving -+ * screens PointerWindows[] keeps referring to the -+ * old window. If that gets destroyed we have a UAF -+ * bug later. Only happens when jumping from a window -+ * to the root window on the other screen. -+ * Enter/Leave events are incorrect for that case but -+ * too niche to fix. -+ */ -+ LeaveWindow(pDev); -+ if (master) -+ LeaveWindow(master); -+ UpdateSpriteForScreen(pDev, pScreen); -+ } - } - - /** --- -2.41.0 - diff --git a/0002-xkb-swap-XkbSetDeviceInfo-and-XkbSetDeviceInfoCheck.patch b/0002-xkb-swap-XkbSetDeviceInfo-and-XkbSetDeviceInfoCheck.patch deleted file mode 100644 index 8973a0e..0000000 --- a/0002-xkb-swap-XkbSetDeviceInfo-and-XkbSetDeviceInfoCheck.patch +++ /dev/null @@ -1,179 +0,0 @@ -From dd8caf39e9e15d8f302e54045dd08d8ebf1025dc Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Tue, 5 Jul 2022 09:50:41 +1000 -Subject: [PATCH xserver 2/3] xkb: swap XkbSetDeviceInfo and - XkbSetDeviceInfoCheck - -XKB often uses a FooCheck and Foo function pair, the former is supposed -to check all values in the request and error out on BadLength, -BadValue, etc. The latter is then called once we're confident the values -are good (they may still fail on an individual device, but that's a -different topic). - -In the case of XkbSetDeviceInfo, those functions were incorrectly -named, with XkbSetDeviceInfo ending up as the checker function and -XkbSetDeviceInfoCheck as the setter function. As a result, the setter -function was called before the checker function, accessing request -data and modifying device state before we ensured that the data is -valid. - -In particular, the setter function relied on values being already -byte-swapped. This in turn could lead to potential OOB memory access. - -Fix this by correctly naming the functions and moving the length checks -over to the checker function. These were added in 87c64fc5b0 to the -wrong function, probably due to the incorrect naming. - -Fixes ZDI-CAN 16070, CVE-2022-2320. - -This vulnerability was discovered by: -Jan-Niklas Sohn working with Trend Micro Zero Day Initiative - -Introduced in c06e27b2f6fd9f7b9f827623a48876a225264132 - -Signed-off-by: Peter Hutterer ---- - xkb/xkb.c | 46 +++++++++++++++++++++++++--------------------- - 1 file changed, 25 insertions(+), 21 deletions(-) - -diff --git a/xkb/xkb.c b/xkb/xkb.c -index 64e52611e..34b2c290b 100644 ---- a/xkb/xkb.c -+++ b/xkb/xkb.c -@@ -6550,7 +6550,8 @@ ProcXkbGetDeviceInfo(ClientPtr client) - static char * - CheckSetDeviceIndicators(char *wire, - DeviceIntPtr dev, -- int num, int *status_rtrn, ClientPtr client) -+ int num, int *status_rtrn, ClientPtr client, -+ xkbSetDeviceInfoReq * stuff) - { - xkbDeviceLedsWireDesc *ledWire; - int i; -@@ -6558,6 +6559,11 @@ CheckSetDeviceIndicators(char *wire, - - ledWire = (xkbDeviceLedsWireDesc *) wire; - for (i = 0; i < num; i++) { -+ if (!_XkbCheckRequestBounds(client, stuff, ledWire, ledWire + 1)) { -+ *status_rtrn = BadLength; -+ return (char *) ledWire; -+ } -+ - if (client->swapped) { - swaps(&ledWire->ledClass); - swaps(&ledWire->ledID); -@@ -6585,6 +6591,11 @@ CheckSetDeviceIndicators(char *wire, - atomWire = (CARD32 *) &ledWire[1]; - if (nNames > 0) { - for (n = 0; n < nNames; n++) { -+ if (!_XkbCheckRequestBounds(client, stuff, atomWire, atomWire + 1)) { -+ *status_rtrn = BadLength; -+ return (char *) atomWire; -+ } -+ - if (client->swapped) { - swapl(atomWire); - } -@@ -6596,6 +6607,10 @@ CheckSetDeviceIndicators(char *wire, - mapWire = (xkbIndicatorMapWireDesc *) atomWire; - if (nMaps > 0) { - for (n = 0; n < nMaps; n++) { -+ if (!_XkbCheckRequestBounds(client, stuff, mapWire, mapWire + 1)) { -+ *status_rtrn = BadLength; -+ return (char *) mapWire; -+ } - if (client->swapped) { - swaps(&mapWire->virtualMods); - swapl(&mapWire->ctrls); -@@ -6647,11 +6662,6 @@ SetDeviceIndicators(char *wire, - xkbIndicatorMapWireDesc *mapWire; - XkbSrvLedInfoPtr sli; - -- if (!_XkbCheckRequestBounds(client, stuff, ledWire, ledWire + 1)) { -- *status_rtrn = BadLength; -- return (char *) ledWire; -- } -- - namec = mapc = statec = 0; - sli = XkbFindSrvLedInfo(dev, ledWire->ledClass, ledWire->ledID, - XkbXI_IndicatorMapsMask); -@@ -6670,10 +6680,6 @@ SetDeviceIndicators(char *wire, - memset((char *) sli->names, 0, XkbNumIndicators * sizeof(Atom)); - for (n = 0, bit = 1; n < XkbNumIndicators; n++, bit <<= 1) { - if (ledWire->namesPresent & bit) { -- if (!_XkbCheckRequestBounds(client, stuff, atomWire, atomWire + 1)) { -- *status_rtrn = BadLength; -- return (char *) atomWire; -- } - sli->names[n] = (Atom) *atomWire; - if (sli->names[n] == None) - ledWire->namesPresent &= ~bit; -@@ -6691,10 +6697,6 @@ SetDeviceIndicators(char *wire, - if (ledWire->mapsPresent) { - for (n = 0, bit = 1; n < XkbNumIndicators; n++, bit <<= 1) { - if (ledWire->mapsPresent & bit) { -- if (!_XkbCheckRequestBounds(client, stuff, mapWire, mapWire + 1)) { -- *status_rtrn = BadLength; -- return (char *) mapWire; -- } - sli->maps[n].flags = mapWire->flags; - sli->maps[n].which_groups = mapWire->whichGroups; - sli->maps[n].groups = mapWire->groups; -@@ -6730,13 +6732,17 @@ SetDeviceIndicators(char *wire, - } - - static int --_XkbSetDeviceInfo(ClientPtr client, DeviceIntPtr dev, -+_XkbSetDeviceInfoCheck(ClientPtr client, DeviceIntPtr dev, - xkbSetDeviceInfoReq * stuff) - { - char *wire; - - wire = (char *) &stuff[1]; - if (stuff->change & XkbXI_ButtonActionsMask) { -+ int sz = stuff->nBtns * SIZEOF(xkbActionWireDesc); -+ if (!_XkbCheckRequestBounds(client, stuff, wire, (char *) wire + sz)) -+ return BadLength; -+ - if (!dev->button) { - client->errorValue = _XkbErrCode2(XkbErr_BadClass, ButtonClass); - return XkbKeyboardErrorCode; -@@ -6747,13 +6753,13 @@ _XkbSetDeviceInfo(ClientPtr client, DeviceIntPtr dev, - dev->button->numButtons); - return BadMatch; - } -- wire += (stuff->nBtns * SIZEOF(xkbActionWireDesc)); -+ wire += sz; - } - if (stuff->change & XkbXI_IndicatorsMask) { - int status = Success; - - wire = CheckSetDeviceIndicators(wire, dev, stuff->nDeviceLedFBs, -- &status, client); -+ &status, client, stuff); - if (status != Success) - return status; - } -@@ -6764,8 +6770,8 @@ _XkbSetDeviceInfo(ClientPtr client, DeviceIntPtr dev, - } - - static int --_XkbSetDeviceInfoCheck(ClientPtr client, DeviceIntPtr dev, -- xkbSetDeviceInfoReq * stuff) -+_XkbSetDeviceInfo(ClientPtr client, DeviceIntPtr dev, -+ xkbSetDeviceInfoReq * stuff) - { - char *wire; - xkbExtensionDeviceNotify ed; -@@ -6789,8 +6795,6 @@ _XkbSetDeviceInfoCheck(ClientPtr client, DeviceIntPtr dev, - if (stuff->firstBtn + stuff->nBtns > nBtns) - return BadValue; - sz = stuff->nBtns * SIZEOF(xkbActionWireDesc); -- if (!_XkbCheckRequestBounds(client, stuff, wire, (char *) wire + sz)) -- return BadLength; - memcpy((char *) &acts[stuff->firstBtn], (char *) wire, sz); - wire += sz; - ed.reason |= XkbXI_ButtonActionsMask; --- -2.36.1 - diff --git a/0003-Xi-avoid-integer-truncation-in-length-check-of-ProcX.patch b/0003-Xi-avoid-integer-truncation-in-length-check-of-ProcX.patch deleted file mode 100644 index d3c6541..0000000 --- a/0003-Xi-avoid-integer-truncation-in-length-check-of-ProcX.patch +++ /dev/null @@ -1,71 +0,0 @@ -From f9c435822c852659e3926502829f1b13ce6efc37 Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Tue, 29 Nov 2022 13:26:57 +1000 -Subject: [PATCH xserver 3/7] Xi: avoid integer truncation in length check of - ProcXIChangeProperty - -This fixes an OOB read and the resulting information disclosure. - -Length calculation for the request was clipped to a 32-bit integer. With -the correct stuff->num_items value the expected request size was -truncated, passing the REQUEST_FIXED_SIZE check. - -The server then proceeded with reading at least stuff->num_items bytes -(depending on stuff->format) from the request and stuffing whatever it -finds into the property. In the process it would also allocate at least -stuff->num_items bytes, i.e. 4GB. - -The same bug exists in ProcChangeProperty and ProcXChangeDeviceProperty, -so let's fix that too. - -CVE-2022-46344, ZDI-CAN 19405 - -This vulnerability was discovered by: -Jan-Niklas Sohn working with Trend Micro Zero Day Initiative - -Signed-off-by: Peter Hutterer -Acked-by: Olivier Fourdan ---- - Xi/xiproperty.c | 4 ++-- - dix/property.c | 3 ++- - 2 files changed, 4 insertions(+), 3 deletions(-) - -diff --git a/Xi/xiproperty.c b/Xi/xiproperty.c -index 68c362c628..066ba21fba 100644 ---- a/Xi/xiproperty.c -+++ b/Xi/xiproperty.c -@@ -890,7 +890,7 @@ ProcXChangeDeviceProperty(ClientPtr client) - REQUEST(xChangeDevicePropertyReq); - DeviceIntPtr dev; - unsigned long len; -- int totalSize; -+ uint64_t totalSize; - int rc; - - REQUEST_AT_LEAST_SIZE(xChangeDevicePropertyReq); -@@ -1130,7 +1130,7 @@ ProcXIChangeProperty(ClientPtr client) - { - int rc; - DeviceIntPtr dev; -- int totalSize; -+ uint64_t totalSize; - unsigned long len; - - REQUEST(xXIChangePropertyReq); -diff --git a/dix/property.c b/dix/property.c -index 94ef5a0ec0..acce94b2c6 100644 ---- a/dix/property.c -+++ b/dix/property.c -@@ -205,7 +205,8 @@ ProcChangeProperty(ClientPtr client) - WindowPtr pWin; - char format, mode; - unsigned long len; -- int sizeInBytes, totalSize, err; -+ int sizeInBytes, err; -+ uint64_t totalSize; - - REQUEST(xChangePropertyReq); - --- -2.38.1 - diff --git a/0003-Xquartz-ProcAppleDRICreatePixmap-needs-to-use-unswap.patch b/0003-Xquartz-ProcAppleDRICreatePixmap-needs-to-use-unswap.patch deleted file mode 100644 index df0a498..0000000 --- a/0003-Xquartz-ProcAppleDRICreatePixmap-needs-to-use-unswap.patch +++ /dev/null @@ -1,47 +0,0 @@ -From 6c684d035c06fd41c727f0ef0744517580864cef Mon Sep 17 00:00:00 2001 -From: Alan Coopersmith -Date: Fri, 22 Mar 2024 19:07:34 -0700 -Subject: [PATCH 3/4] Xquartz: ProcAppleDRICreatePixmap needs to use unswapped - length to send reply - -CVE-2024-31082 - -Fixes: 14205ade0 ("XQuartz: appledri: Fix byte swapping in replies") -Signed-off-by: Alan Coopersmith -Part-of: ---- - hw/xquartz/xpr/appledri.c | 4 +++- - 1 file changed, 3 insertions(+), 1 deletion(-) - -diff --git a/hw/xquartz/xpr/appledri.c b/hw/xquartz/xpr/appledri.c -index 77574655b..40422b61a 100644 ---- a/hw/xquartz/xpr/appledri.c -+++ b/hw/xquartz/xpr/appledri.c -@@ -272,6 +272,7 @@ ProcAppleDRICreatePixmap(ClientPtr client) - xAppleDRICreatePixmapReply rep; - int width, height, pitch, bpp; - void *ptr; -+ CARD32 stringLength; - - REQUEST_SIZE_MATCH(xAppleDRICreatePixmapReq); - -@@ -307,6 +308,7 @@ ProcAppleDRICreatePixmap(ClientPtr client) - if (sizeof(rep) != sz_xAppleDRICreatePixmapReply) - ErrorF("error sizeof(rep) is %zu\n", sizeof(rep)); - -+ stringLength = rep.stringLength; /* save unswapped value */ - if (client->swapped) { - swaps(&rep.sequenceNumber); - swapl(&rep.length); -@@ -319,7 +321,7 @@ ProcAppleDRICreatePixmap(ClientPtr client) - } - - WriteToClient(client, sizeof(rep), &rep); -- WriteToClient(client, rep.stringLength, path); -+ WriteToClient(client, stringLength, path); - - return Success; - } --- -2.44.0 - diff --git a/0003-dix-fix-DeviceStateNotify-event-calculation.patch b/0003-dix-fix-DeviceStateNotify-event-calculation.patch deleted file mode 100644 index 2fe2f8e..0000000 --- a/0003-dix-fix-DeviceStateNotify-event-calculation.patch +++ /dev/null @@ -1,217 +0,0 @@ -From 219c54b8a3337456ce5270ded6a67bcde53553d5 Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Mon, 18 Dec 2023 12:26:20 +1000 -Subject: [PATCH 3/9] dix: fix DeviceStateNotify event calculation - -The previous code only made sense if one considers buttons and keys to -be mutually exclusive on a device. That is not necessarily true, causing -a number of issues. - -This function allocates and fills in the number of xEvents we need to -send the device state down the wire. This is split across multiple -32-byte devices including one deviceStateNotify event and optional -deviceKeyStateNotify, deviceButtonStateNotify and (possibly multiple) -deviceValuator events. - -The previous behavior would instead compose a sequence -of [state, buttonstate, state, keystate, valuator...]. This is not -protocol correct, and on top of that made the code extremely convoluted. - -Fix this by streamlining: add both button and key into the deviceStateNotify -and then append the key state and button state, followed by the -valuators. Finally, the deviceValuator events contain up to 6 valuators -per event but we only ever sent through 3 at a time. Let's double that -troughput. - -CVE-2024-0229, ZDI-CAN-22678 - -This vulnerability was discovered by: -Jan-Niklas Sohn working with Trend Micro Zero Day Initiative ---- - dix/enterleave.c | 121 ++++++++++++++++++++--------------------------- - 1 file changed, 52 insertions(+), 69 deletions(-) - -diff --git a/dix/enterleave.c b/dix/enterleave.c -index 17964b00a..7b7ba1098 100644 ---- a/dix/enterleave.c -+++ b/dix/enterleave.c -@@ -615,9 +615,15 @@ FixDeviceValuator(DeviceIntPtr dev, deviceValuator * ev, ValuatorClassPtr v, - - ev->type = DeviceValuator; - ev->deviceid = dev->id; -- ev->num_valuators = nval < 3 ? nval : 3; -+ ev->num_valuators = nval < 6 ? nval : 6; - ev->first_valuator = first; - switch (ev->num_valuators) { -+ case 6: -+ ev->valuator2 = v->axisVal[first + 5]; -+ case 5: -+ ev->valuator2 = v->axisVal[first + 4]; -+ case 4: -+ ev->valuator2 = v->axisVal[first + 3]; - case 3: - ev->valuator2 = v->axisVal[first + 2]; - case 2: -@@ -626,7 +632,6 @@ FixDeviceValuator(DeviceIntPtr dev, deviceValuator * ev, ValuatorClassPtr v, - ev->valuator0 = v->axisVal[first]; - break; - } -- first += ev->num_valuators; - } - - static void -@@ -646,7 +651,7 @@ FixDeviceStateNotify(DeviceIntPtr dev, deviceStateNotify * ev, KeyClassPtr k, - ev->num_buttons = b->numButtons; - memcpy((char *) ev->buttons, (char *) b->down, 4); - } -- else if (k) { -+ if (k) { - ev->classes_reported |= (1 << KeyClass); - ev->num_keys = k->xkbInfo->desc->max_key_code - - k->xkbInfo->desc->min_key_code; -@@ -670,15 +675,26 @@ FixDeviceStateNotify(DeviceIntPtr dev, deviceStateNotify * ev, KeyClassPtr k, - } - } - -- -+/** -+ * The device state notify event is split across multiple 32-byte events. -+ * The first one contains the first 32 button state bits, the first 32 -+ * key state bits, and the first 3 valuator values. -+ * -+ * If a device has more than that, the server sends out: -+ * - one deviceButtonStateNotify for buttons 32 and above -+ * - one deviceKeyStateNotify for keys 32 and above -+ * - one deviceValuator event per 6 valuators above valuator 4 -+ * -+ * All events but the last one have the deviceid binary ORed with MORE_EVENTS, -+ */ - static void - DeliverStateNotifyEvent(DeviceIntPtr dev, WindowPtr win) - { -+ /* deviceStateNotify, deviceKeyStateNotify, deviceButtonStateNotify -+ * and one deviceValuator for each 6 valuators */ -+ deviceStateNotify sev[3 + (MAX_VALUATORS + 6)/6]; - int evcount = 1; -- deviceStateNotify sev[6 + (MAX_VALUATORS + 2)/3]; -- deviceStateNotify *ev; -- deviceKeyStateNotify *kev; -- deviceButtonStateNotify *bev; -+ deviceStateNotify *ev = sev; - - KeyClassPtr k; - ButtonClassPtr b; -@@ -691,82 +707,49 @@ DeliverStateNotifyEvent(DeviceIntPtr dev, WindowPtr win) - - if ((b = dev->button) != NULL) { - nbuttons = b->numButtons; -- if (nbuttons > 32) -+ if (nbuttons > 32) /* first 32 are encoded in deviceStateNotify */ - evcount++; - } - if ((k = dev->key) != NULL) { - nkeys = k->xkbInfo->desc->max_key_code - k->xkbInfo->desc->min_key_code; -- if (nkeys > 32) -+ if (nkeys > 32) /* first 32 are encoded in deviceStateNotify */ - evcount++; -- if (nbuttons > 0) { -- evcount++; -- } - } - if ((v = dev->valuator) != NULL) { - nval = v->numAxes; -- -- if (nval > 3) -- evcount++; -- if (nval > 6) { -- if (!(k && b)) -- evcount++; -- if (nval > 9) -- evcount += ((nval - 7) / 3); -- } -+ /* first three are encoded in deviceStateNotify, then -+ * it's 6 per deviceValuator event */ -+ evcount += ((nval - 3) + 6)/6; - } - -- ev = sev; -- FixDeviceStateNotify(dev, ev, NULL, NULL, NULL, first); -- -- if (b != NULL) { -- FixDeviceStateNotify(dev, ev++, NULL, b, v, first); -- first += 3; -- nval -= 3; -- if (nbuttons > 32) { -- (ev - 1)->deviceid |= MORE_EVENTS; -- bev = (deviceButtonStateNotify *) ev++; -- bev->type = DeviceButtonStateNotify; -- bev->deviceid = dev->id; -- memcpy((char *) &bev->buttons[4], (char *) &b->down[4], -- DOWN_LENGTH - 4); -- } -- if (nval > 0) { -- (ev - 1)->deviceid |= MORE_EVENTS; -- FixDeviceValuator(dev, (deviceValuator *) ev++, v, first); -- first += 3; -- nval -= 3; -- } -+ BUG_RETURN(evcount <= ARRAY_SIZE(sev)); -+ -+ FixDeviceStateNotify(dev, ev, k, b, v, first); -+ -+ if (b != NULL && nbuttons > 32) { -+ deviceButtonStateNotify *bev = (deviceButtonStateNotify *) ++ev; -+ (ev - 1)->deviceid |= MORE_EVENTS; -+ bev->type = DeviceButtonStateNotify; -+ bev->deviceid = dev->id; -+ memcpy((char *) &bev->buttons[4], (char *) &b->down[4], -+ DOWN_LENGTH - 4); - } - -- if (k != NULL) { -- FixDeviceStateNotify(dev, ev++, k, NULL, v, first); -- first += 3; -- nval -= 3; -- if (nkeys > 32) { -- (ev - 1)->deviceid |= MORE_EVENTS; -- kev = (deviceKeyStateNotify *) ev++; -- kev->type = DeviceKeyStateNotify; -- kev->deviceid = dev->id; -- memmove((char *) &kev->keys[0], (char *) &k->down[4], 28); -- } -- if (nval > 0) { -- (ev - 1)->deviceid |= MORE_EVENTS; -- FixDeviceValuator(dev, (deviceValuator *) ev++, v, first); -- first += 3; -- nval -= 3; -- } -+ if (k != NULL && nkeys > 32) { -+ deviceKeyStateNotify *kev = (deviceKeyStateNotify *) ++ev; -+ (ev - 1)->deviceid |= MORE_EVENTS; -+ kev->type = DeviceKeyStateNotify; -+ kev->deviceid = dev->id; -+ memmove((char *) &kev->keys[0], (char *) &k->down[4], 28); - } - -+ first = 3; -+ nval -= 3; - while (nval > 0) { -- FixDeviceStateNotify(dev, ev++, NULL, NULL, v, first); -- first += 3; -- nval -= 3; -- if (nval > 0) { -- (ev - 1)->deviceid |= MORE_EVENTS; -- FixDeviceValuator(dev, (deviceValuator *) ev++, v, first); -- first += 3; -- nval -= 3; -- } -+ ev->deviceid |= MORE_EVENTS; -+ FixDeviceValuator(dev, (deviceValuator *) ++ev, v, first); -+ first += 6; -+ nval -= 6; - } - - DeliverEventsToWindow(dev, win, (xEvent *) sev, evcount, --- -2.43.0 - diff --git a/0003-xkb-add-request-length-validation-for-XkbSetGeometry.patch b/0003-xkb-add-request-length-validation-for-XkbSetGeometry.patch deleted file mode 100644 index dca4d7c..0000000 --- a/0003-xkb-add-request-length-validation-for-XkbSetGeometry.patch +++ /dev/null @@ -1,182 +0,0 @@ -From 6907b6ea2b4ce949cb07271f5b678d5966d9df42 Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Tue, 5 Jul 2022 11:11:06 +1000 -Subject: [PATCH xserver 3/3] xkb: add request length validation for - XkbSetGeometry - -No validation of the various fields on that report were done, so a -malicious client could send a short request that claims it had N -sections, or rows, or keys, and the server would process the request for -N sections, running out of bounds of the actual request data. - -Fix this by adding size checks to ensure our data is valid. - -ZDI-CAN 16062, CVE-2022-2319. - -This vulnerability was discovered by: -Jan-Niklas Sohn working with Trend Micro Zero Day Initiative - -Signed-off-by: Peter Hutterer ---- - xkb/xkb.c | 43 ++++++++++++++++++++++++++++++++++++++----- - 1 file changed, 38 insertions(+), 5 deletions(-) - -diff --git a/xkb/xkb.c b/xkb/xkb.c -index 34b2c290b..4692895db 100644 ---- a/xkb/xkb.c -+++ b/xkb/xkb.c -@@ -5156,7 +5156,7 @@ _GetCountedString(char **wire_inout, ClientPtr client, char **str) - } - - static Status --_CheckSetDoodad(char **wire_inout, -+_CheckSetDoodad(char **wire_inout, xkbSetGeometryReq *req, - XkbGeometryPtr geom, XkbSectionPtr section, ClientPtr client) - { - char *wire; -@@ -5167,6 +5167,9 @@ _CheckSetDoodad(char **wire_inout, - Status status; - - dWire = (xkbDoodadWireDesc *) (*wire_inout); -+ if (!_XkbCheckRequestBounds(client, req, dWire, dWire + 1)) -+ return BadLength; -+ - any = dWire->any; - wire = (char *) &dWire[1]; - if (client->swapped) { -@@ -5269,7 +5272,7 @@ _CheckSetDoodad(char **wire_inout, - } - - static Status --_CheckSetOverlay(char **wire_inout, -+_CheckSetOverlay(char **wire_inout, xkbSetGeometryReq *req, - XkbGeometryPtr geom, XkbSectionPtr section, ClientPtr client) - { - register int r; -@@ -5280,6 +5283,9 @@ _CheckSetOverlay(char **wire_inout, - - wire = *wire_inout; - olWire = (xkbOverlayWireDesc *) wire; -+ if (!_XkbCheckRequestBounds(client, req, olWire, olWire + 1)) -+ return BadLength; -+ - if (client->swapped) { - swapl(&olWire->name); - } -@@ -5291,6 +5297,9 @@ _CheckSetOverlay(char **wire_inout, - xkbOverlayKeyWireDesc *kWire; - XkbOverlayRowPtr row; - -+ if (!_XkbCheckRequestBounds(client, req, rWire, rWire + 1)) -+ return BadLength; -+ - if (rWire->rowUnder > section->num_rows) { - client->errorValue = _XkbErrCode4(0x20, r, section->num_rows, - rWire->rowUnder); -@@ -5299,6 +5308,9 @@ _CheckSetOverlay(char **wire_inout, - row = XkbAddGeomOverlayRow(ol, rWire->rowUnder, rWire->nKeys); - kWire = (xkbOverlayKeyWireDesc *) &rWire[1]; - for (k = 0; k < rWire->nKeys; k++, kWire++) { -+ if (!_XkbCheckRequestBounds(client, req, kWire, kWire + 1)) -+ return BadLength; -+ - if (XkbAddGeomOverlayKey(ol, row, - (char *) kWire->over, - (char *) kWire->under) == NULL) { -@@ -5332,6 +5344,9 @@ _CheckSetSections(XkbGeometryPtr geom, - register int r; - xkbRowWireDesc *rWire; - -+ if (!_XkbCheckRequestBounds(client, req, sWire, sWire + 1)) -+ return BadLength; -+ - if (client->swapped) { - swapl(&sWire->name); - swaps(&sWire->top); -@@ -5357,6 +5372,9 @@ _CheckSetSections(XkbGeometryPtr geom, - XkbRowPtr row; - xkbKeyWireDesc *kWire; - -+ if (!_XkbCheckRequestBounds(client, req, rWire, rWire + 1)) -+ return BadLength; -+ - if (client->swapped) { - swaps(&rWire->top); - swaps(&rWire->left); -@@ -5371,6 +5389,9 @@ _CheckSetSections(XkbGeometryPtr geom, - for (k = 0; k < rWire->nKeys; k++, kWire++) { - XkbKeyPtr key; - -+ if (!_XkbCheckRequestBounds(client, req, kWire, kWire + 1)) -+ return BadLength; -+ - key = XkbAddGeomKey(row); - if (!key) - return BadAlloc; -@@ -5396,7 +5417,7 @@ _CheckSetSections(XkbGeometryPtr geom, - register int d; - - for (d = 0; d < sWire->nDoodads; d++) { -- status = _CheckSetDoodad(&wire, geom, section, client); -+ status = _CheckSetDoodad(&wire, req, geom, section, client); - if (status != Success) - return status; - } -@@ -5405,7 +5426,7 @@ _CheckSetSections(XkbGeometryPtr geom, - register int o; - - for (o = 0; o < sWire->nOverlays; o++) { -- status = _CheckSetOverlay(&wire, geom, section, client); -+ status = _CheckSetOverlay(&wire, req, geom, section, client); - if (status != Success) - return status; - } -@@ -5439,6 +5460,9 @@ _CheckSetShapes(XkbGeometryPtr geom, - xkbOutlineWireDesc *olWire; - XkbOutlinePtr ol; - -+ if (!_XkbCheckRequestBounds(client, req, shapeWire, shapeWire + 1)) -+ return BadLength; -+ - shape = - XkbAddGeomShape(geom, shapeWire->name, shapeWire->nOutlines); - if (!shape) -@@ -5449,12 +5473,18 @@ _CheckSetShapes(XkbGeometryPtr geom, - XkbPointPtr pt; - xkbPointWireDesc *ptWire; - -+ if (!_XkbCheckRequestBounds(client, req, olWire, olWire + 1)) -+ return BadLength; -+ - ol = XkbAddGeomOutline(shape, olWire->nPoints); - if (!ol) - return BadAlloc; - ol->corner_radius = olWire->cornerRadius; - ptWire = (xkbPointWireDesc *) &olWire[1]; - for (p = 0, pt = ol->points; p < olWire->nPoints; p++, pt++, ptWire++) { -+ if (!_XkbCheckRequestBounds(client, req, ptWire, ptWire + 1)) -+ return BadLength; -+ - pt->x = ptWire->x; - pt->y = ptWire->y; - if (client->swapped) { -@@ -5560,12 +5590,15 @@ _CheckSetGeom(XkbGeometryPtr geom, xkbSetGeometryReq * req, ClientPtr client) - return status; - - for (i = 0; i < req->nDoodads; i++) { -- status = _CheckSetDoodad(&wire, geom, NULL, client); -+ status = _CheckSetDoodad(&wire, req, geom, NULL, client); - if (status != Success) - return status; - } - - for (i = 0; i < req->nKeyAliases; i++) { -+ if (!_XkbCheckRequestBounds(client, req, wire, wire + XkbKeyNameLength)) -+ return BadLength; -+ - if (XkbAddGeomKeyAlias(geom, &wire[XkbKeyNameLength], wire) == NULL) - return BadAlloc; - wire += 2 * XkbKeyNameLength; --- -2.36.1 - diff --git a/0004-Xi-disallow-passive-grabs-with-a-detail-255.patch b/0004-Xi-disallow-passive-grabs-with-a-detail-255.patch deleted file mode 100644 index 5b189ea..0000000 --- a/0004-Xi-disallow-passive-grabs-with-a-detail-255.patch +++ /dev/null @@ -1,82 +0,0 @@ -From 0dab0b527ac5c4fe0272ea679522bd87238a733b Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Tue, 29 Nov 2022 13:55:32 +1000 -Subject: [PATCH xserver 4/7] Xi: disallow passive grabs with a detail > 255 - -The XKB protocol effectively prevents us from ever using keycodes above -255. For buttons it's theoretically possible but realistically too niche -to worry about. For all other passive grabs, the detail must be zero -anyway. - -This fixes an OOB write: - -ProcXIPassiveUngrabDevice() calls DeletePassiveGrabFromList with a -temporary grab struct which contains tempGrab->detail.exact = stuff->detail. -For matching existing grabs, DeleteDetailFromMask is called with the -stuff->detail value. This function creates a new mask with the one bit -representing stuff->detail cleared. - -However, the array size for the new mask is 8 * sizeof(CARD32) bits, -thus any detail above 255 results in an OOB array write. - -CVE-2022-46341, ZDI-CAN 19381 - -This vulnerability was discovered by: -Jan-Niklas Sohn working with Trend Micro Zero Day Initiative - -Signed-off-by: Peter Hutterer -Acked-by: Olivier Fourdan ---- - Xi/xipassivegrab.c | 22 ++++++++++++++-------- - 1 file changed, 14 insertions(+), 8 deletions(-) - -diff --git a/Xi/xipassivegrab.c b/Xi/xipassivegrab.c -index 2769fb7c94..c9ac2f8553 100644 ---- a/Xi/xipassivegrab.c -+++ b/Xi/xipassivegrab.c -@@ -137,6 +137,12 @@ ProcXIPassiveGrabDevice(ClientPtr client) - return BadValue; - } - -+ /* XI2 allows 32-bit keycodes but thanks to XKB we can never -+ * implement this. Just return an error for all keycodes that -+ * cannot work anyway, same for buttons > 255. */ -+ if (stuff->detail > 255) -+ return XIAlreadyGrabbed; -+ - if (XICheckInvalidMaskBits(client, (unsigned char *) &stuff[1], - stuff->mask_len * 4) != Success) - return BadValue; -@@ -207,14 +213,8 @@ ProcXIPassiveGrabDevice(ClientPtr client) - ¶m, XI2, &mask); - break; - case XIGrabtypeKeycode: -- /* XI2 allows 32-bit keycodes but thanks to XKB we can never -- * implement this. Just return an error for all keycodes that -- * cannot work anyway */ -- if (stuff->detail > 255) -- status = XIAlreadyGrabbed; -- else -- status = GrabKey(client, dev, mod_dev, stuff->detail, -- ¶m, XI2, &mask); -+ status = GrabKey(client, dev, mod_dev, stuff->detail, -+ ¶m, XI2, &mask); - break; - case XIGrabtypeEnter: - case XIGrabtypeFocusIn: -@@ -334,6 +334,12 @@ ProcXIPassiveUngrabDevice(ClientPtr client) - return BadValue; - } - -+ /* We don't allow passive grabs for details > 255 anyway */ -+ if (stuff->detail > 255) { -+ client->errorValue = stuff->detail; -+ return BadValue; -+ } -+ - rc = dixLookupWindow(&win, stuff->grab_window, client, DixSetAttrAccess); - if (rc != Success) - return rc; --- -2.38.1 - diff --git a/0004-Xi-when-creating-a-new-ButtonClass-set-the-number-of.patch b/0004-Xi-when-creating-a-new-ButtonClass-set-the-number-of.patch deleted file mode 100644 index dbe90ce..0000000 --- a/0004-Xi-when-creating-a-new-ButtonClass-set-the-number-of.patch +++ /dev/null @@ -1,37 +0,0 @@ -From df3c65706eb169d5938df0052059f3e0d5981b74 Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Thu, 21 Dec 2023 13:48:10 +1000 -Subject: [PATCH 4/9] Xi: when creating a new ButtonClass, set the number of - buttons - -There's a racy sequence where a master device may copy the button class -from the slave, without ever initializing numButtons. This leads to a -device with zero buttons but a button class which is invalid. - -Let's copy the numButtons value from the source - by definition if we -don't have a button class yet we do not have any other slave devices -with more than this number of buttons anyway. - -CVE-2024-0229, ZDI-CAN-22678 - -This vulnerability was discovered by: -Jan-Niklas Sohn working with Trend Micro Zero Day Initiative ---- - Xi/exevents.c | 1 + - 1 file changed, 1 insertion(+) - -diff --git a/Xi/exevents.c b/Xi/exevents.c -index 54ea11a93..e16171468 100644 ---- a/Xi/exevents.c -+++ b/Xi/exevents.c -@@ -605,6 +605,7 @@ DeepCopyPointerClasses(DeviceIntPtr from, DeviceIntPtr to) - to->button = calloc(1, sizeof(ButtonClassRec)); - if (!to->button) - FatalError("[Xi] no memory for class shift.\n"); -+ to->button->numButtons = from->button->numButtons; - } - else - classes->button = NULL; --- -2.43.0 - diff --git a/0004-render-fix-refcounting-of-glyphs-during-ProcRenderAd.patch b/0004-render-fix-refcounting-of-glyphs-during-ProcRenderAd.patch deleted file mode 100644 index dcbf337..0000000 --- a/0004-render-fix-refcounting-of-glyphs-during-ProcRenderAd.patch +++ /dev/null @@ -1,112 +0,0 @@ -From bdca6c3d1f5057eeb31609b1280fc93237b00c77 Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Tue, 30 Jan 2024 13:13:35 +1000 -Subject: [PATCH 4/4] render: fix refcounting of glyphs during - ProcRenderAddGlyphs - -Previously, AllocateGlyph would return a new glyph with refcount=0 and a -re-used glyph would end up not changing the refcount at all. The -resulting glyph_new array would thus have multiple entries pointing to -the same non-refcounted glyphs. - -AddGlyph may free a glyph, resulting in a UAF when the same glyph -pointer is then later used. - -Fix this by returning a refcount of 1 for a new glyph and always -incrementing the refcount for a re-used glyph, followed by dropping that -refcount back down again when we're done with it. - -CVE-2024-31083, ZDI-CAN-22880 - -This vulnerability was discovered by: -Jan-Niklas Sohn working with Trend Micro Zero Day Initiative - -Part-of: ---- - render/glyph.c | 5 +++-- - render/glyphstr_priv.h | 1 + - render/render.c | 15 +++++++++++---- - 3 files changed, 15 insertions(+), 6 deletions(-) - -diff --git a/render/glyph.c b/render/glyph.c -index 850ea8440..13991f8a1 100644 ---- a/render/glyph.c -+++ b/render/glyph.c -@@ -245,10 +245,11 @@ FreeGlyphPicture(GlyphPtr glyph) - } - } - --static void -+void - FreeGlyph(GlyphPtr glyph, int format) - { - CheckDuplicates(&globalGlyphs[format], "FreeGlyph"); -+ BUG_RETURN(glyph->refcnt == 0); - if (--glyph->refcnt == 0) { - GlyphRefPtr gr; - int i; -@@ -354,7 +355,7 @@ AllocateGlyph(xGlyphInfo * gi, int fdepth) - glyph = (GlyphPtr) malloc(size); - if (!glyph) - return 0; -- glyph->refcnt = 0; -+ glyph->refcnt = 1; - glyph->size = size + sizeof(xGlyphInfo); - glyph->info = *gi; - dixInitPrivates(glyph, (char *) glyph + head_size, PRIVATE_GLYPH); -diff --git a/render/glyphstr.h b/render/glyphstr.h -index 2f51bd244..3b1d806d1 100644 ---- a/render/glyphstr.h -+++ b/render/glyphstr.h -@@ -108,6 +108,7 @@ extern Bool - extern GlyphPtr FindGlyph(GlyphSetPtr glyphSet, Glyph id); - - extern GlyphPtr AllocateGlyph(xGlyphInfo * gi, int format); -+extern void FreeGlyph(GlyphPtr glyph, int format); - - extern Bool - ResizeGlyphSet(GlyphSetPtr glyphSet, CARD32 change); -diff --git a/render/render.c b/render/render.c -index 29c5055c6..fe5e37dd9 100644 ---- a/render/render.c -+++ b/render/render.c -@@ -1076,6 +1076,7 @@ ProcRenderAddGlyphs(ClientPtr client) - - if (glyph_new->glyph && glyph_new->glyph != DeletedGlyph) { - glyph_new->found = TRUE; -+ ++glyph_new->glyph->refcnt; - } - else { - GlyphPtr glyph; -@@ -1168,8 +1169,10 @@ ProcRenderAddGlyphs(ClientPtr client) - err = BadAlloc; - goto bail; - } -- for (i = 0; i < nglyphs; i++) -+ for (i = 0; i < nglyphs; i++) { - AddGlyph(glyphSet, glyphs[i].glyph, glyphs[i].id); -+ FreeGlyph(glyphs[i].glyph, glyphSet->fdepth); -+ } - - if (glyphsBase != glyphsLocal) - free(glyphsBase); -@@ -1179,9 +1182,13 @@ ProcRenderAddGlyphs(ClientPtr client) - FreePicture((void *) pSrc, 0); - if (pSrcPix) - FreeScratchPixmapHeader(pSrcPix); -- for (i = 0; i < nglyphs; i++) -- if (glyphs[i].glyph && !glyphs[i].found) -- free(glyphs[i].glyph); -+ for (i = 0; i < nglyphs; i++) { -+ if (glyphs[i].glyph) { -+ --glyphs[i].glyph->refcnt; -+ if (!glyphs[i].found) -+ free(glyphs[i].glyph); -+ } -+ } - if (glyphsBase != glyphsLocal) - free(glyphsBase); - return err; --- -2.44.0 - diff --git a/0005-Xext-free-the-screen-saver-resource-when-replacing-i.patch b/0005-Xext-free-the-screen-saver-resource-when-replacing-i.patch deleted file mode 100644 index dc2a9d9..0000000 --- a/0005-Xext-free-the-screen-saver-resource-when-replacing-i.patch +++ /dev/null @@ -1,48 +0,0 @@ -From 94f6fe99d87cf6ba0adadd95c595158c345b7d29 Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Tue, 29 Nov 2022 14:53:07 +1000 -Subject: [PATCH xserver 5/7] Xext: free the screen saver resource when - replacing it - -This fixes a use-after-free bug: - -When a client first calls ScreenSaverSetAttributes(), a struct -ScreenSaverAttrRec is allocated and added to the client's -resources. - -When the same client calls ScreenSaverSetAttributes() again, a new -struct ScreenSaverAttrRec is allocated, replacing the old struct. The -old struct was freed but not removed from the clients resources. - -Later, when the client is destroyed the resource system invokes -ScreenSaverFreeAttr and attempts to clean up the already freed struct. - -Fix this by letting the resource system free the old attrs instead. - -CVE-2022-46343, ZDI-CAN 19404 - -This vulnerability was discovered by: -Jan-Niklas Sohn working with Trend Micro Zero Day Initiative - -Signed-off-by: Peter Hutterer -Acked-by: Olivier Fourdan ---- - Xext/saver.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/Xext/saver.c b/Xext/saver.c -index f813ba08d1..fd6153c313 100644 ---- a/Xext/saver.c -+++ b/Xext/saver.c -@@ -1051,7 +1051,7 @@ ScreenSaverSetAttributes(ClientPtr client) - pVlist++; - } - if (pPriv->attr) -- FreeScreenAttr(pPriv->attr); -+ FreeResource(pPriv->attr->resource, AttrType); - pPriv->attr = pAttr; - pAttr->resource = FakeClientID(client->index); - if (!AddResource(pAttr->resource, AttrType, (void *) pAttr)) --- -2.38.1 - diff --git a/0005-Xi-flush-hierarchy-events-after-adding-removing-mast.patch b/0005-Xi-flush-hierarchy-events-after-adding-removing-mast.patch deleted file mode 100644 index 6a21b3c..0000000 --- a/0005-Xi-flush-hierarchy-events-after-adding-removing-mast.patch +++ /dev/null @@ -1,109 +0,0 @@ -From 4a5e9b1895627d40d26045bd0b7ef3dce503cbd1 Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Thu, 4 Jan 2024 10:01:24 +1000 -Subject: [PATCH 5/9] Xi: flush hierarchy events after adding/removing master - devices - -The `XISendDeviceHierarchyEvent()` function allocates space to store up -to `MAXDEVICES` (256) `xXIHierarchyInfo` structures in `info`. - -If a device with a given ID was removed and a new device with the same -ID added both in the same operation, the single device ID will lead to -two info structures being written to `info`. - -Since this case can occur for every device ID at once, a total of two -times `MAXDEVICES` info structures might be written to the allocation. - -To avoid it, once one add/remove master is processed, send out the -device hierarchy event for the current state and continue. That event -thus only ever has exactly one of either added/removed in it (and -optionally slave attached/detached). - -CVE-2024-21885, ZDI-CAN-22744 - -This vulnerability was discovered by: -Jan-Niklas Sohn working with Trend Micro Zero Day Initiative ---- - Xi/xichangehierarchy.c | 27 ++++++++++++++++++++++----- - 1 file changed, 22 insertions(+), 5 deletions(-) - -diff --git a/Xi/xichangehierarchy.c b/Xi/xichangehierarchy.c -index d2d985848..72d00451e 100644 ---- a/Xi/xichangehierarchy.c -+++ b/Xi/xichangehierarchy.c -@@ -416,6 +416,11 @@ ProcXIChangeHierarchy(ClientPtr client) - size_t len; /* length of data remaining in request */ - int rc = Success; - int flags[MAXDEVICES] = { 0 }; -+ enum { -+ NO_CHANGE, -+ FLUSH, -+ CHANGED, -+ } changes = NO_CHANGE; - - REQUEST(xXIChangeHierarchyReq); - REQUEST_AT_LEAST_SIZE(xXIChangeHierarchyReq); -@@ -465,8 +470,9 @@ ProcXIChangeHierarchy(ClientPtr client) - rc = add_master(client, c, flags); - if (rc != Success) - goto unwind; -- } -+ changes = FLUSH; - break; -+ } - case XIRemoveMaster: - { - xXIRemoveMasterInfo *r = (xXIRemoveMasterInfo *) any; -@@ -475,8 +481,9 @@ ProcXIChangeHierarchy(ClientPtr client) - rc = remove_master(client, r, flags); - if (rc != Success) - goto unwind; -- } -+ changes = FLUSH; - break; -+ } - case XIDetachSlave: - { - xXIDetachSlaveInfo *c = (xXIDetachSlaveInfo *) any; -@@ -485,8 +492,9 @@ ProcXIChangeHierarchy(ClientPtr client) - rc = detach_slave(client, c, flags); - if (rc != Success) - goto unwind; -- } -+ changes = CHANGED; - break; -+ } - case XIAttachSlave: - { - xXIAttachSlaveInfo *c = (xXIAttachSlaveInfo *) any; -@@ -495,16 +503,25 @@ ProcXIChangeHierarchy(ClientPtr client) - rc = attach_slave(client, c, flags); - if (rc != Success) - goto unwind; -+ changes = CHANGED; -+ break; - } -+ default: - break; - } - -+ if (changes == FLUSH) { -+ XISendDeviceHierarchyEvent(flags); -+ memset(flags, 0, sizeof(flags)); -+ changes = NO_CHANGE; -+ } -+ - len -= any->length * 4; - any = (xXIAnyHierarchyChangeInfo *) ((char *) any + any->length * 4); - } - - unwind: -- -- XISendDeviceHierarchyEvent(flags); -+ if (changes != NO_CHANGE) -+ XISendDeviceHierarchyEvent(flags); - return rc; - } --- -2.43.0 - diff --git a/0006-Xext-free-the-XvRTVideoNotify-when-turning-off-from-.patch b/0006-Xext-free-the-XvRTVideoNotify-when-turning-off-from-.patch deleted file mode 100644 index ba8b8fa..0000000 --- a/0006-Xext-free-the-XvRTVideoNotify-when-turning-off-from-.patch +++ /dev/null @@ -1,74 +0,0 @@ -From a42635ee3c01f71a49052d83a372933504c9db04 Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Wed, 30 Nov 2022 11:20:40 +1000 -Subject: [PATCH xserver 6/7] Xext: free the XvRTVideoNotify when turning off - from the same client - -This fixes a use-after-free bug: - -When a client first calls XvdiSelectVideoNotify() on a drawable with a -TRUE onoff argument, a struct XvVideoNotifyRec is allocated. This struct -is added twice to the resources: - - as the drawable's XvRTVideoNotifyList. This happens only once per - drawable, subsequent calls append to this list. - - as the client's XvRTVideoNotify. This happens for every client. - -The struct keeps the ClientPtr around once it has been added for a -client. The idea, presumably, is that if the client disconnects we can remove -all structs from the drawable's list that match the client (by resetting -the ClientPtr to NULL), but if the drawable is destroyed we can remove -and free the whole list. - -However, if the same client then calls XvdiSelectVideoNotify() on the -same drawable with a FALSE onoff argument, only the ClientPtr on the -existing struct was set to NULL. The struct itself remained in the -client's resources. - -If the drawable is now destroyed, the resource system invokes -XvdiDestroyVideoNotifyList which frees the whole list for this drawable -- including our struct. This function however does not free the resource -for the client since our ClientPtr is NULL. - -Later, when the client is destroyed and the resource system invokes -XvdiDestroyVideoNotify, we unconditionally set the ClientPtr to NULL. On -a struct that has been freed previously. This is generally frowned upon. - -Fix this by calling FreeResource() on the second call instead of merely -setting the ClientPtr to NULL. This removes the struct from the client -resources (but not from the list), ensuring that it won't be accessed -again when the client quits. - -Note that the assignment tpn->client = NULL; is superfluous since the -XvdiDestroyVideoNotify function will do this anyway. But it's left for -clarity and to match a similar invocation in XvdiSelectPortNotify. - -CVE-2022-46342, ZDI-CAN 19400 - -This vulnerability was discovered by: -Jan-Niklas Sohn working with Trend Micro Zero Day Initiative - -Signed-off-by: Peter Hutterer -Acked-by: Olivier Fourdan ---- - Xext/xvmain.c | 4 +++- - 1 file changed, 3 insertions(+), 1 deletion(-) - -diff --git a/Xext/xvmain.c b/Xext/xvmain.c -index f627471938..2a08f8744a 100644 ---- a/Xext/xvmain.c -+++ b/Xext/xvmain.c -@@ -811,8 +811,10 @@ XvdiSelectVideoNotify(ClientPtr client, DrawablePtr pDraw, BOOL onoff) - tpn = pn; - while (tpn) { - if (tpn->client == client) { -- if (!onoff) -+ if (!onoff) { - tpn->client = NULL; -+ FreeResource(tpn->id, XvRTVideoNotify); -+ } - return Success; - } - if (!tpn->client) --- -2.38.1 - diff --git a/0006-Xi-do-not-keep-linked-list-pointer-during-recursion.patch b/0006-Xi-do-not-keep-linked-list-pointer-during-recursion.patch deleted file mode 100644 index 3174635..0000000 --- a/0006-Xi-do-not-keep-linked-list-pointer-during-recursion.patch +++ /dev/null @@ -1,70 +0,0 @@ -From bc1fdbe46559dd947674375946bbef54dd0ce36b Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Jos=C3=A9=20Exp=C3=B3sito?= -Date: Fri, 22 Dec 2023 18:28:31 +0100 -Subject: [PATCH 6/9] Xi: do not keep linked list pointer during recursion - -The `DisableDevice()` function is called whenever an enabled device -is disabled and it moves the device from the `inputInfo.devices` linked -list to the `inputInfo.off_devices` linked list. - -However, its link/unlink operation has an issue during the recursive -call to `DisableDevice()` due to the `prev` pointer pointing to a -removed device. - -This issue leads to a length mismatch between the total number of -devices and the number of device in the list, leading to a heap -overflow and, possibly, to local privilege escalation. - -Simplify the code that checked whether the device passed to -`DisableDevice()` was in `inputInfo.devices` or not and find the -previous device after the recursion. - -CVE-2024-21886, ZDI-CAN-22840 - -This vulnerability was discovered by: -Jan-Niklas Sohn working with Trend Micro Zero Day Initiative ---- - dix/devices.c | 15 ++++++++++++--- - 1 file changed, 12 insertions(+), 3 deletions(-) - -diff --git a/dix/devices.c b/dix/devices.c -index dca98c8d1..389d28a23 100644 ---- a/dix/devices.c -+++ b/dix/devices.c -@@ -453,14 +453,20 @@ DisableDevice(DeviceIntPtr dev, BOOL sendevent) - { - DeviceIntPtr *prev, other; - BOOL enabled; -+ BOOL dev_in_devices_list = FALSE; - int flags[MAXDEVICES] = { 0 }; - - if (!dev->enabled) - return TRUE; - -- for (prev = &inputInfo.devices; -- *prev && (*prev != dev); prev = &(*prev)->next); -- if (*prev != dev) -+ for (other = inputInfo.devices; other; other = other->next) { -+ if (other == dev) { -+ dev_in_devices_list = TRUE; -+ break; -+ } -+ } -+ -+ if (!dev_in_devices_list) - return FALSE; - - TouchEndPhysicallyActiveTouches(dev); -@@ -511,6 +517,9 @@ DisableDevice(DeviceIntPtr dev, BOOL sendevent) - LeaveWindow(dev); - SetFocusOut(dev); - -+ for (prev = &inputInfo.devices; -+ *prev && (*prev != dev); prev = &(*prev)->next); -+ - *prev = dev->next; - dev->next = inputInfo.off_devices; - inputInfo.off_devices = dev; --- -2.43.0 - diff --git a/0007-dix-when-disabling-a-master-float-disabled-slaved-de.patch b/0007-dix-when-disabling-a-master-float-disabled-slaved-de.patch deleted file mode 100644 index 32a326a..0000000 --- a/0007-dix-when-disabling-a-master-float-disabled-slaved-de.patch +++ /dev/null @@ -1,53 +0,0 @@ -From 26769aa71fcbe0a8403b7fb13b7c9010cc07c3a8 Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Fri, 5 Jan 2024 09:40:27 +1000 -Subject: [PATCH 7/9] dix: when disabling a master, float disabled slaved - devices too - -Disabling a master device floats all slave devices but we didn't do this -to already-disabled slave devices. As a result those devices kept their -reference to the master device resulting in access to already freed -memory if the master device was removed before the corresponding slave -device. - -And to match this behavior, also forcibly reset that pointer during -CloseDownDevices(). - -Related to CVE-2024-21886, ZDI-CAN-22840 ---- - dix/devices.c | 12 ++++++++++++ - 1 file changed, 12 insertions(+) - -diff --git a/dix/devices.c b/dix/devices.c -index 389d28a23..84a6406d1 100644 ---- a/dix/devices.c -+++ b/dix/devices.c -@@ -483,6 +483,13 @@ DisableDevice(DeviceIntPtr dev, BOOL sendevent) - flags[other->id] |= XISlaveDetached; - } - } -+ -+ for (other = inputInfo.off_devices; other; other = other->next) { -+ if (!IsMaster(other) && GetMaster(other, MASTER_ATTACHED) == dev) { -+ AttachDevice(NULL, other, NULL); -+ flags[other->id] |= XISlaveDetached; -+ } -+ } - } - else { - for (other = inputInfo.devices; other; other = other->next) { -@@ -1088,6 +1095,11 @@ CloseDownDevices(void) - dev->master = NULL; - } - -+ for (dev = inputInfo.off_devices; dev; dev = dev->next) { -+ if (!IsMaster(dev) && !IsFloating(dev)) -+ dev->master = NULL; -+ } -+ - CloseDeviceList(&inputInfo.devices); - CloseDeviceList(&inputInfo.off_devices); - --- -2.43.0 - diff --git a/0007-xkb-reset-the-radio_groups-pointer-to-NULL-after-fre.patch b/0007-xkb-reset-the-radio_groups-pointer-to-NULL-after-fre.patch deleted file mode 100644 index c6b2352..0000000 --- a/0007-xkb-reset-the-radio_groups-pointer-to-NULL-after-fre.patch +++ /dev/null @@ -1,36 +0,0 @@ -From 774260dbae1fa505cd2848c786baed9a8db5179d Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Mon, 5 Dec 2022 15:55:54 +1000 -Subject: [PATCH xserver 7/7] xkb: reset the radio_groups pointer to NULL after - freeing it - -Unlike other elements of the keymap, this pointer was freed but not -reset. On a subsequent XkbGetKbdByName request, the server may access -already freed memory. - -CVE-2022-46283, ZDI-CAN-19530 - -This vulnerability was discovered by: -Jan-Niklas Sohn working with Trend Micro Zero Day Initiative - -Signed-off-by: Peter Hutterer -Acked-by: Olivier Fourdan ---- - xkb/xkbUtils.c | 1 + - 1 file changed, 1 insertion(+) - -diff --git a/xkb/xkbUtils.c b/xkb/xkbUtils.c -index dd089c2046..3f5791a183 100644 ---- a/xkb/xkbUtils.c -+++ b/xkb/xkbUtils.c -@@ -1326,6 +1326,7 @@ _XkbCopyNames(XkbDescPtr src, XkbDescPtr dst) - } - else { - free(dst->names->radio_groups); -+ dst->names->radio_groups = NULL; - } - dst->names->num_rg = src->names->num_rg; - --- -2.38.1 - diff --git a/0008-Xext-fix-invalid-event-type-mask-in-XTestSwapFakeInp.patch b/0008-Xext-fix-invalid-event-type-mask-in-XTestSwapFakeInp.patch deleted file mode 100644 index c84d387..0000000 --- a/0008-Xext-fix-invalid-event-type-mask-in-XTestSwapFakeInp.patch +++ /dev/null @@ -1,35 +0,0 @@ -From bb1711b7fba42f2a0c7d1c09beee241a1b2bcc30 Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Mon, 19 Dec 2022 10:06:45 +1000 -Subject: [PATCH xserver] Xext: fix invalid event type mask in - XTestSwapFakeInput - -In commit b320ca0 the mask was inadvertently changed from octal 0177 to -hexadecimal 0x177. - -Fixes commit b320ca0ffe4c0c872eeb3a93d9bde21f765c7c63 - Xtest: disallow GenericEvents in XTestSwapFakeInput - -Found by Stuart Cassoff - -Signed-off-by: Peter Hutterer ---- - Xext/xtest.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/Xext/xtest.c b/Xext/xtest.c -index 2985a4ce6e..dde5c4cf9d 100644 ---- a/Xext/xtest.c -+++ b/Xext/xtest.c -@@ -502,7 +502,7 @@ XTestSwapFakeInput(ClientPtr client, xReq * req) - - nev = ((req->length << 2) - sizeof(xReq)) / sizeof(xEvent); - for (ev = (xEvent *) &req[1]; --nev >= 0; ev++) { -- int evtype = ev->u.u.type & 0x177; -+ int evtype = ev->u.u.type & 0177; - /* Swap event */ - proc = EventSwapVector[evtype]; - /* no swapping proc; invalid event type? */ --- -2.38.1 - diff --git a/0008-glx-Call-XACE-hooks-on-the-GLX-buffer.patch b/0008-glx-Call-XACE-hooks-on-the-GLX-buffer.patch deleted file mode 100644 index 0e9e4a0..0000000 --- a/0008-glx-Call-XACE-hooks-on-the-GLX-buffer.patch +++ /dev/null @@ -1,60 +0,0 @@ -From e5e8586a12a3ec915673edffa10dc8fe5e15dac3 Mon Sep 17 00:00:00 2001 -From: Olivier Fourdan -Date: Wed, 6 Dec 2023 12:09:41 +0100 -Subject: [PATCH 8/9] glx: Call XACE hooks on the GLX buffer - -The XSELINUX code will label resources at creation by checking the -access mode. When the access mode is DixCreateAccess, it will call the -function to label the new resource SELinuxLabelResource(). - -However, GLX buffers do not go through the XACE hooks when created, -hence leaving the resource actually unlabeled. - -When, later, the client tries to create another resource using that -drawable (like a GC for example), the XSELINUX code would try to use -the security ID of that object which has never been labeled, get a NULL -pointer and crash when checking whether the requested permissions are -granted for subject security ID. - -To avoid the issue, make sure to call the XACE hooks when creating the -GLX buffers. - -Credit goes to Donn Seeley for providing the patch. - -CVE-2024-0408 - -Signed-off-by: Olivier Fourdan -Acked-by: Peter Hutterer ---- - glx/glxcmds.c | 8 ++++++++ - 1 file changed, 8 insertions(+) - -diff --git a/glx/glxcmds.c b/glx/glxcmds.c -index fc26a2e34..1e46d0c72 100644 ---- a/glx/glxcmds.c -+++ b/glx/glxcmds.c -@@ -48,6 +48,7 @@ - #include "indirect_util.h" - #include "protocol-versions.h" - #include "glxvndabi.h" -+#include "xace.h" - - static char GLXServerVendorName[] = "SGI"; - -@@ -1392,6 +1393,13 @@ DoCreatePbuffer(ClientPtr client, int screenNum, XID fbconfigId, - if (!pPixmap) - return BadAlloc; - -+ err = XaceHook(XACE_RESOURCE_ACCESS, client, glxDrawableId, RT_PIXMAP, -+ pPixmap, RT_NONE, NULL, DixCreateAccess); -+ if (err != Success) { -+ (*pGlxScreen->pScreen->DestroyPixmap) (pPixmap); -+ return err; -+ } -+ - /* Assign the pixmap the same id as the pbuffer and add it as a - * resource so it and the DRI2 drawable will be reclaimed when the - * pbuffer is destroyed. */ --- -2.43.0 - diff --git a/0009-ephyr-xwayland-Use-the-proper-private-key-for-cursor.patch b/0009-ephyr-xwayland-Use-the-proper-private-key-for-cursor.patch deleted file mode 100644 index 5fa80fd..0000000 --- a/0009-ephyr-xwayland-Use-the-proper-private-key-for-cursor.patch +++ /dev/null @@ -1,56 +0,0 @@ -From 2ef0f1116c65d5cb06d7b6d83f8a1aea702c94f7 Mon Sep 17 00:00:00 2001 -From: Olivier Fourdan -Date: Wed, 6 Dec 2023 11:51:56 +0100 -Subject: [PATCH 9/9] ephyr,xwayland: Use the proper private key for cursor - -The cursor in DIX is actually split in two parts, the cursor itself and -the cursor bits, each with their own devPrivates. - -The cursor itself includes the cursor bits, meaning that the cursor bits -devPrivates in within structure of the cursor. - -Both Xephyr and Xwayland were using the private key for the cursor bits -to store the data for the cursor, and when using XSELINUX which comes -with its own special devPrivates, the data stored in that cursor bits' -devPrivates would interfere with the XSELINUX devPrivates data and the -SELINUX security ID would point to some other unrelated data, causing a -crash in the XSELINUX code when trying to (re)use the security ID. - -CVE-2024-0409 - -Signed-off-by: Olivier Fourdan -Reviewed-by: Peter Hutterer ---- - hw/kdrive/ephyr/ephyrcursor.c | 2 +- - hw/xwayland/xwayland-cursor.c | 2 +- - 2 files changed, 2 insertions(+), 2 deletions(-) - -diff --git a/hw/kdrive/ephyr/ephyrcursor.c b/hw/kdrive/ephyr/ephyrcursor.c -index f991899c5..3f192d034 100644 ---- a/hw/kdrive/ephyr/ephyrcursor.c -+++ b/hw/kdrive/ephyr/ephyrcursor.c -@@ -246,7 +246,7 @@ miPointerSpriteFuncRec EphyrPointerSpriteFuncs = { - Bool - ephyrCursorInit(ScreenPtr screen) - { -- if (!dixRegisterPrivateKey(&ephyrCursorPrivateKey, PRIVATE_CURSOR_BITS, -+ if (!dixRegisterPrivateKey(&ephyrCursorPrivateKey, PRIVATE_CURSOR, - sizeof(ephyrCursorRec))) - return FALSE; - -diff --git a/hw/xwayland/xwayland-cursor.c b/hw/xwayland/xwayland-cursor.c -index e3c1aaa50..bd94b0cfb 100644 ---- a/hw/xwayland/xwayland-cursor.c -+++ b/hw/xwayland/xwayland-cursor.c -@@ -431,7 +431,7 @@ static miPointerScreenFuncRec xwl_pointer_screen_funcs = { - Bool - xwl_screen_init_cursor(struct xwl_screen *xwl_screen) - { -- if (!dixRegisterPrivateKey(&xwl_cursor_private_key, PRIVATE_CURSOR_BITS, 0)) -+ if (!dixRegisterPrivateKey(&xwl_cursor_private_key, PRIVATE_CURSOR, 0)) - return FALSE; - - return miPointerInitialize(xwl_screen->screen, --- -2.43.0 - diff --git a/xorg-x11-server-fb-access-wrapper.patch b/xorg-x11-server-fb-access-wrapper.patch deleted file mode 100644 index 7bb0e23..0000000 --- a/xorg-x11-server-fb-access-wrapper.patch +++ /dev/null @@ -1,31 +0,0 @@ -fb: Declare wfbFinishScreenInit, wfbScreenInit for !FB_ACCESS_WRAPPER - -xorg-x11-drv-nouveau wfbScreenInit without defining FB_ACCESS_WRAPPER -(which has other unintended side effects). Presently, this compiles -and links because compilers still support implicit function -declarations, but this is going to change fairly soon. This seems to -be the most straightforward change to keep the driver building. - -Submitted upstream: - - - -diff -ur xorg-server-1.20.14.orig/fb/fb.h xorg-server-1.20.14/fb/fb.h ---- xorg-server-1.20.14.orig/fb/fb.h 2021-12-15 20:01:24.000000000 +0100 -+++ xorg-server-1.20.14/fb/fb.h 2023-04-13 13:59:47.325341537 +0200 -@@ -1027,7 +1027,6 @@ - int dpiy, int width, /* pixel width of frame buffer */ - int bpp); /* bits per pixel of frame buffer */ - --#ifdef FB_ACCESS_WRAPPER - extern _X_EXPORT Bool - wfbFinishScreenInit(ScreenPtr pScreen, - void *pbits, -@@ -1049,7 +1048,6 @@ - int width, - int bpp, - SetupWrapProcPtr setupWrap, FinishWrapProcPtr finishWrap); --#endif - - extern _X_EXPORT Bool - fbFinishScreenInit(ScreenPtr pScreen, From fefea377b3789bdcdd7345092505e59bdde84cc3 Mon Sep 17 00:00:00 2001 From: Simone Caronni Date: Thu, 26 Sep 2024 22:12:11 +0200 Subject: [PATCH 50/74] Spec file update - Drop support for building snapshots. - Drop custom cflags. - Trim changelog. --- Makefile | 30 --- commitid | 1 - gitignore | 306 ------------------------- import.log | 6 - make-git-snapshot.sh | 17 -- xorg-x11-server.spec | 372 +------------------------------ xserver-sdk-abi-requires.git | 14 -- xserver-sdk-abi-requires.release | 19 -- 8 files changed, 10 insertions(+), 755 deletions(-) delete mode 100644 Makefile delete mode 100644 commitid delete mode 100644 gitignore delete mode 100644 import.log delete mode 100755 make-git-snapshot.sh delete mode 100755 xserver-sdk-abi-requires.git delete mode 100755 xserver-sdk-abi-requires.release diff --git a/Makefile b/Makefile deleted file mode 100644 index 4041668..0000000 --- a/Makefile +++ /dev/null @@ -1,30 +0,0 @@ -# Makefile for source rpm: xorg-x11-server -# $Id$ -NAME := xorg-x11-server -SPECFILE = $(firstword $(wildcard *.spec)) - -define find-makefile-common -for d in common ../common ../../common ; do if [ -f $$d/Makefile.common ] ; then if [ -f $$d/CVS/Root -a -w $$d/Makefile.common ] ; then cd $$d ; cvs -Q update ; fi ; echo "$$d/Makefile.common" ; break ; fi ; done -endef - -MAKEFILE_COMMON := $(shell $(find-makefile-common)) - -ifeq ($(MAKEFILE_COMMON),) -# attempt a checkout -define checkout-makefile-common -test -f CVS/Root && { cvs -Q -d $$(cat CVS/Root) checkout common && echo "common/Makefile.common" ; } || { echo "ERROR: I can't figure out how to checkout the 'common' module." ; exit -1 ; } >&2 -endef - -MAKEFILE_COMMON := $(shell $(checkout-makefile-common)) -endif - -include $(MAKEFILE_COMMON) - -ifeq ($(MAKECMDGOALS),me a sandwich) -.PHONY :: me a sandwich -me a: - @: - -sandwich: - @[ `id -u` -ne 0 ] && echo "What? Make it yourself." || echo Okay. -endif diff --git a/commitid b/commitid deleted file mode 100644 index 7420e41..0000000 --- a/commitid +++ /dev/null @@ -1 +0,0 @@ -d13cb974426f7f1110b0bdb08c4ebb46ff8975f7 diff --git a/gitignore b/gitignore deleted file mode 100644 index 524cfc6..0000000 --- a/gitignore +++ /dev/null @@ -1,306 +0,0 @@ -Makefile -Makefile.in -.deps -.libs -.msg -*.lo -*.la -*.a -*.o -*~ -.*sw? -*.pbxuser -*.mode1v3 -obj* -build* -local -aclocal.m4 -autom4te.cache -compile -config.guess -config.log -config.status -config.sub -configure -configure.lineno -depcomp -install-sh -libtool -ltmain.sh -missing -TAGS -tags -ylwrap -xorg-server.pc -stamp-h? -do-not-use-config.h -do-not-use-config.h.in -afb/afbbltC.c -afb/afbbltCI.c -afb/afbbltG.c -afb/afbbltO.c -afb/afbbltX.c -afb/afbseg.c -afb/afbtileC.c -afb/afbtileG.c -cfb/cfb8lineCO.c -cfb/cfb8lineCP.c -cfb/cfb8lineG.c -cfb/cfb8lineX.c -cfb/cfb8segC.c -cfb/cfb8segCS.c -cfb/cfb8segX.c -cfb/cfb8setG.c -cfb/cfbbltC.c -cfb/cfbbltG.c -cfb/cfbbltO.c -cfb/cfbbltX.c -cfb/cfbfillarcC.c -cfb/cfbfillarcG.c -cfb/cfbglrop8.c -cfb/cfbply1rctC.c -cfb/cfbply1rctG.c -cfb/cfbseg.c -cfb/cfbsolidC.c -cfb/cfbsolidG.c -cfb/cfbsolidX.c -cfb/cfbtile32C.c -cfb/cfbtile32G.c -cfb/cfbtileoddC.c -cfb/cfbtileoddG.c -cfb/cfbzerarcC.c -cfb/cfbzerarcG.c -cfb/cfbzerarcX.c -cfb32/cfb8lineCO.c -cfb32/cfb8lineCP.c -cfb32/cfb8lineG.c -cfb32/cfb8lineX.c -cfb32/cfb8segC.c -cfb32/cfb8segCS.c -cfb32/cfb8segX.c -cfb32/cfb8setG.c -cfb32/cfbbltC.c -cfb32/cfbbltG.c -cfb32/cfbbltO.c -cfb32/cfbbltX.c -cfb32/cfbfillarcC.c -cfb32/cfbfillarcG.c -cfb32/cfbply1rctC.c -cfb32/cfbply1rctG.c -cfb32/cfbseg.c -cfb32/cfbsolidC.c -cfb32/cfbsolidG.c -cfb32/cfbsolidX.c -cfb32/cfbtile32C.c -cfb32/cfbtile32G.c -cfb32/cfbtileoddC.c -cfb32/cfbtileoddG.c -cfb32/cfbzerarcC.c -cfb32/cfbzerarcG.c -cfb32/cfbzerarcX.c -doc/Xserver.1x -doc/Xserver.man -hw/dmx/Xdmx -hw/dmx/Xdmx.1x -hw/dmx/config/dmxtodmx -hw/dmx/config/dmxtodmx.1x -hw/dmx/config/parser.c -hw/dmx/config/parser.h -hw/dmx/config/scanner.c -hw/dmx/config/vdltodmx -hw/dmx/config/vdltodmx.1x -hw/dmx/config/xdmxconfig -hw/dmx/config/xdmxconfig.1x -hw/dmx/examples/dmxaddinput -hw/dmx/examples/dmxaddscreen -hw/dmx/examples/dmxreconfig -hw/dmx/examples/dmxresize -hw/dmx/examples/dmxrminput -hw/dmx/examples/dmxrmscreen -hw/dmx/examples/dmxwininfo -hw/dmx/examples/ev -hw/dmx/examples/evi -hw/dmx/examples/res -hw/dmx/examples/xbell -hw/dmx/examples/xdmx -hw/dmx/examples/xinput -hw/dmx/examples/xled -hw/dmx/examples/xtest -hw/kdrive/ati/Xati -hw/kdrive/chips/Xchips -hw/kdrive/ephyr/Xephyr -hw/kdrive/epson/Xepson -hw/kdrive/fake/Xfake -hw/kdrive/fbdev/Xfbdev -hw/kdrive/i810/Xi810 -hw/kdrive/mach64/Xmach64 -hw/kdrive/mga/Xmga -hw/kdrive/neomagic/Xneomagic -hw/kdrive/nvidia/Xnvidia -hw/kdrive/pm2/Xpm2 -hw/kdrive/r128/Xr128 -hw/kdrive/sdl/Xsdl -hw/kdrive/sis300/Xsis -hw/kdrive/smi/Xsmi -hw/kdrive/vesa/Xvesa -hw/kdrive/via/Xvia -hw/vfb/Xvfb -hw/vfb/Xvfb.1x -hw/vfb/Xvfb.man -hw/xfree86/Xorg -hw/xfree86/common/xf86Build.h -hw/xfree86/common/xf86DefModeSet.c -hw/xfree86/doc/man/Xorg.1x -hw/xfree86/doc/man/Xorg.man -hw/xfree86/doc/man/xorg.conf.5x -hw/xfree86/doc/man/xorg.conf.man -hw/xfree86/exa/exa.4 -hw/xfree86/exa/exa.4x -hw/xfree86/exa/exa.man -hw/xfree86/fbdevhw/fbdevhw.4x -hw/xfree86/fbdevhw/fbdevhw.man -hw/xfree86/getconfig/cfg.man -hw/xfree86/getconfig/getconfig.1x -hw/xfree86/getconfig/getconfig.5x -hw/xfree86/getconfig/getconfig.man -hw/xfree86/os-support/xorgos.c -hw/xfree86/osandcommon.c -hw/xfree86/ramdac/xf86BitOrder.c -hw/xfree86/scanpci/xf86PciData.c -hw/xfree86/scanpci/xf86PciIds.h -hw/xfree86/utils/cvt/cvt -hw/xfree86/utils/cvt/cvt.man -hw/xfree86/utils/gtf/gtf -hw/xfree86/utils/gtf/gtf.1x -hw/xfree86/utils/gtf/gtf.man -hw/xfree86/utils/ioport/inb -hw/xfree86/utils/ioport/inl -hw/xfree86/utils/ioport/inw -hw/xfree86/utils/ioport/ioport -hw/xfree86/utils/ioport/outb -hw/xfree86/utils/ioport/outl -hw/xfree86/utils/ioport/outw -hw/xfree86/utils/pcitweak/pcitweak -hw/xfree86/utils/pcitweak/pcitweak.1x -hw/xfree86/utils/pcitweak/pcitweak.man -hw/xfree86/utils/scanpci/scanpci -hw/xfree86/utils/scanpci/scanpci.1x -hw/xfree86/utils/scanpci/scanpci.man -hw/xfree86/utils/xorgcfg/XOrgCfg -hw/xfree86/utils/xorgcfg/xorgcfg -hw/xfree86/utils/xorgcfg/xorgcfg.1x -hw/xfree86/utils/xorgcfg/xorgcfg.man -hw/xfree86/utils/xorgconfig/xorgconfig -hw/xfree86/utils/xorgconfig/xorgconfig.1x -hw/xfree86/utils/xorgconfig/xorgconfig.man -hw/xfree86/xaa/l-xaaBitmap.c -hw/xfree86/xaa/l-xaaStipple.c -hw/xfree86/xaa/l-xaaTEGlyph.c -hw/xfree86/xaa/l3-xaaBitmap.c -hw/xfree86/xaa/l3-xaaStipple.c -hw/xfree86/xaa/lf-xaaBitmap.c -hw/xfree86/xaa/lf-xaaStipple.c -hw/xfree86/xaa/lf-xaaTEGlyph.c -hw/xfree86/xaa/lf3-xaaBitmap.c -hw/xfree86/xaa/lf3-xaaStipple.c -hw/xfree86/xaa/m-xaaBitmap.c -hw/xfree86/xaa/m-xaaStipple.c -hw/xfree86/xaa/m-xaaTEGlyph.c -hw/xfree86/xaa/m3-xaaBitmap.c -hw/xfree86/xaa/m3-xaaStipple.c -hw/xfree86/xaa/mf-xaaBitmap.c -hw/xfree86/xaa/mf-xaaStipple.c -hw/xfree86/xaa/mf-xaaTEGlyph.c -hw/xfree86/xaa/mf3-xaaBitmap.c -hw/xfree86/xaa/mf3-xaaStipple.c -hw/xfree86/xaa/s-xaaDashLine.c -hw/xfree86/xaa/s-xaaLine.c -hw/xfree86/xf1bpp/maskbits.c -hw/xfree86/xf1bpp/mfbbitblt.c -hw/xfree86/xf1bpp/mfbbltC.c -hw/xfree86/xf1bpp/mfbbltCI.c -hw/xfree86/xf1bpp/mfbbltG.c -hw/xfree86/xf1bpp/mfbbltO.c -hw/xfree86/xf1bpp/mfbbltX.c -hw/xfree86/xf1bpp/mfbbres.c -hw/xfree86/xf1bpp/mfbbresd.c -hw/xfree86/xf1bpp/mfbclip.c -hw/xfree86/xf1bpp/mfbcmap.c -hw/xfree86/xf1bpp/mfbfillarc.c -hw/xfree86/xf1bpp/mfbfillrct.c -hw/xfree86/xf1bpp/mfbfillsp.c -hw/xfree86/xf1bpp/mfbfont.c -hw/xfree86/xf1bpp/mfbgc.c -hw/xfree86/xf1bpp/mfbgetsp.c -hw/xfree86/xf1bpp/mfbigbblak.c -hw/xfree86/xf1bpp/mfbigbwht.c -hw/xfree86/xf1bpp/mfbhrzvert.c -hw/xfree86/xf1bpp/mfbimage.c -hw/xfree86/xf1bpp/mfbline.c -hw/xfree86/xf1bpp/mfbmisc.c -hw/xfree86/xf1bpp/mfbpablack.c -hw/xfree86/xf1bpp/mfbpainv.c -hw/xfree86/xf1bpp/mfbpawhite.c -hw/xfree86/xf1bpp/mfbpgbblak.c -hw/xfree86/xf1bpp/mfbpgbinv.c -hw/xfree86/xf1bpp/mfbpgbwht.c -hw/xfree86/xf1bpp/mfbpixmap.c -hw/xfree86/xf1bpp/mfbplyblack.c -hw/xfree86/xf1bpp/mfbplyinv.c -hw/xfree86/xf1bpp/mfbplywhite.c -hw/xfree86/xf1bpp/mfbpntwin.c -hw/xfree86/xf1bpp/mfbpolypnt.c -hw/xfree86/xf1bpp/mfbpushpxl.c -hw/xfree86/xf1bpp/mfbscrclse.c -hw/xfree86/xf1bpp/mfbscrinit.c -hw/xfree86/xf1bpp/mfbseg.c -hw/xfree86/xf1bpp/mfbsetsp.c -hw/xfree86/xf1bpp/mfbteblack.c -hw/xfree86/xf1bpp/mfbtewhite.c -hw/xfree86/xf1bpp/mfbtileC.c -hw/xfree86/xf1bpp/mfbtileG.c -hw/xfree86/xf1bpp/mfbwindow.c -hw/xfree86/xf1bpp/mfbzerarc.c -hw/xfree86/xf4bpp/mfbseg.c -hw/xfree86/xf8_32bpp/cfbgc32.c -hw/xfree86/xf8_32bpp/cfbgc8.c -hw/xfree86/xorg.c -hw/xfree86/xorg.conf.example -hw/xfree86/xorg.conf.example.pre -hw/xnest/Xnest -hw/xnest/Xnest.1x -hw/xnest/Xnest.man -hw/xprint/Xprt -hw/xprint/config/C/print/Xprinters.ghostscript -hw/xprint/doc/Xprt.1x -hw/xprint/doc/Xprt.man -hw/xprint/dpmsstubs-wrapper.c -hw/xprint/miinitext-wrapper.c -include/dix-config.h -include/kdrive-config.h -include/xgl-config.h -include/xkb-config.h -include/xorg-config.h -include/xorg-server.h -include/xwin-config.h -mfb/mfbbltC.c -mfb/mfbbltCI.c -mfb/mfbbltG.c -mfb/mfbbltO.c -mfb/mfbbltX.c -mfb/mfbigbblak.c -mfb/mfbigbwht.c -mfb/mfbpablack.c -mfb/mfbpainv.c -mfb/mfbpawhite.c -mfb/mfbpgbblak.c -mfb/mfbpgbinv.c -mfb/mfbpgbwht.c -mfb/mfbplyblack.c -mfb/mfbplyinv.c -mfb/mfbplywhite.c -mfb/mfbseg.c -mfb/mfbteblack.c -mfb/mfbtewhite.c -mfb/mfbtileC.c -mfb/mfbtileG.c diff --git a/import.log b/import.log deleted file mode 100644 index 782e371..0000000 --- a/import.log +++ /dev/null @@ -1,6 +0,0 @@ -xorg-x11-server-1_5_0-1_fc10:HEAD:xorg-x11-server-1.5.0-1.fc10.src.rpm:1220485219 -xorg-x11-server-1_5_1-1_fc10:HEAD:xorg-x11-server-1.5.1-1.fc10.src.rpm:1222198557 -xorg-x11-server-1_5_2-1_fc10:HEAD:xorg-x11-server-1.5.2-1.fc10.src.rpm:1223667007 -xorg-x11-server-1_5_3-1_fc10:HEAD:xorg-x11-server-1.5.3-1.fc10.src.rpm:1225918317 -xorg-x11-server-1_6_0-1_fc11:HEAD:xorg-x11-server-1.6.0-1.fc11.src.rpm:1235594175 -xorg-x11-server-1_6_1-1_fc11:HEAD:xorg-x11-server-1.6.1-1.fc11.src.rpm:1239742477 diff --git a/make-git-snapshot.sh b/make-git-snapshot.sh deleted file mode 100755 index 0d9b2ad..0000000 --- a/make-git-snapshot.sh +++ /dev/null @@ -1,17 +0,0 @@ -#!/bin/sh - -DIRNAME=xorg-server-$( date +%Y%m%d ) - -rm -rf $DIRNAME -git clone git://git.freedesktop.org/git/xorg/xserver $DIRNAME -cd $DIRNAME -if [ -z "$1" ]; then - git log | head -1 -else - git checkout $1 -fi -git log | head -1 | awk '{ print $2 }' > ../commitid -git repack -a -d -cd .. -tar cf - $DIRNAME | xz -c9 > $DIRNAME.tar.xz -rm -rf $DIRNAME diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 01c5b1f..3f514a5 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -1,21 +1,7 @@ -# This package is an experiment in active integration of upstream SCM with -# Fedora packaging. It works something like this: -# -# The "pristine" source is actually a git repo (with no working checkout). -# The first step of %%prep is to check it out and switch to a "fedora" branch. -# If you need to add a patch to the server, just do it like a normal git -# operation, dump it with git-format-patch to a file in the standard naming -# format, and add a PatchN: line. If you want to push something upstream, -# check out the master branch, pull, cherry-pick, and push. - # X.org requires lazy relocations to work. %undefine _hardened_build %undefine _strict_symbol_defs_build -#global gitdate 20161026 -%global stable_abi 1 - -%if !0%{?gitdate} || %{stable_abi} # Released ABI versions. Have to keep these manually in sync with the # source because rpm is a terrible language. %global ansic_major 0 @@ -26,43 +12,18 @@ %global xinput_minor 4 %global extension_major 10 %global extension_minor 0 -%endif - -%if 0%{?gitdate} -# For git snapshots, use date for major and a serial number for minor -%global minor_serial 0 -%global git_ansic_major %{gitdate} -%global git_ansic_minor %{minor_serial} -%global git_videodrv_major %{gitdate} -%global git_videodrv_minor %{minor_serial} -%global git_xinput_major %{gitdate} -%global git_xinput_minor %{minor_serial} -%global git_extension_major %{gitdate} -%global git_extension_minor %{minor_serial} -%endif %global pkgname xorg-server Summary: X.Org X11 X server Name: xorg-x11-server Version: 21.1.13 -Release: 1%{?gitdate:.%{gitdate}}%{?dist} +Release: 2%{?dist} URL: http://www.x.org # SPDX License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant -#VCS: git:git://git.freedesktop.org/git/xorg/xserver -%if 0%{?gitdate} -# git snapshot. to recreate, run: -# ./make-git-snapshot.sh `cat commitid` -Source0: xorg-server-%{gitdate}.tar.xz -#Source0: http://www.x.org/pub/individual/xserver/%{pkgname}-%{version}.tar.bz2 -Source1: make-git-snapshot.sh -Source2: commitid -%else Source0: https://www.x.org/pub/individual/xserver/%{pkgname}-%{version}.tar.xz -Source1: gitignore -%endif Source10: xserver.pamd @@ -70,8 +31,7 @@ Source10: xserver.pamd Source20: http://svn.exactcode.de/t2/trunk/package/xorg/xorg-server/xvfb-run.sh # for requires generation in drivers -Source30: xserver-sdk-abi-requires.release -Source31: xserver-sdk-abi-requires.git +Source30: xserver-sdk-abi-requires # maintainer convenience script Source40: driver-abi-rebuild.sh @@ -80,24 +40,17 @@ Source40: driver-abi-rebuild.sh Patch1: 06_use-intel-only-on-pre-gen4.diff # Default to xf86-video-modesetting on GeForce 8 and newer Patch2: 0001-xfree86-use-modesetting-driver-by-default-on-GeForce.patch - # Default to va_gl on intel i965 as we use the modesetting drv there # va_gl should probably just be the default everywhere ? Patch3: 0001-xf86-dri2-Use-va_gl-as-vdpau_driver-for-Intel-i965-G.patch - # because the display-managers are not ready yet, do not upstream Patch6: 0001-Fedora-hack-Make-the-suid-root-wrapper-always-start-.patch - # Not sure anyone else cares about this so let's keep this Fedora-only for now # Upstream PR for the meson.build equivalent is here, so we can drop this patch # when we start building with meson. # https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/1001` Patch7: 0001-configure.ac-search-for-the-fontrootdir-ourselves.patch - -# Backports from current stable "server-21.1-branch": -# - -# Fix compilation error on i686 +# Fix compilation error on i686 (21.1.14+) # https://gitlab.freedesktop.org/xorg/xserver/-/commit/8407181c7dfe14086d99697af0b86120320ab73e Patch1024: 0001-ephyr-Fix-incompatible-pointer-type-build-error.patch @@ -183,18 +136,10 @@ Provides: Xserver # HdG: This should be moved to the wrapper package once the wrapper gets # its own sub-package: Provides: xorg-x11-server-wrapper = %{version}-%{release} -%if !0%{?gitdate} || %{stable_abi} Provides: xserver-abi(ansic-%{ansic_major}) = %{ansic_minor} Provides: xserver-abi(videodrv-%{videodrv_major}) = %{videodrv_minor} Provides: xserver-abi(xinput-%{xinput_major}) = %{xinput_minor} Provides: xserver-abi(extension-%{extension_major}) = %{extension_minor} -%endif -%if 0%{?gitdate} -Provides: xserver-abi(ansic-%{git_ansic_major}) = %{git_ansic_minor} -Provides: xserver-abi(videodrv-%{git_videodrv_major}) = %{git_videodrv_minor} -Provides: xserver-abi(xinput-%{git_xinput_major}) = %{git_xinput_minor} -Provides: xserver-abi(extension-%{git_extension_major}) = %{git_extension_minor} -%endif Obsoletes: xorg-x11-glamor < %{version}-%{release} Provides: xorg-x11-glamor = %{version}-%{release} Obsoletes: xorg-x11-drv-modesetting < %{version}-%{release} @@ -290,16 +235,8 @@ Xserver source code needed to build VNC server (Xvnc) %prep -%autosetup -N -n %{pkgname}-%{?gitdate:%{gitdate}}%{!?gitdate:%{version}} -rm -rf .git -cp %{SOURCE1} .gitignore -%global _default_patch_flags -f -# ick -#%%global __scm git -#%%{expand:%%__scm_setup_git -q} -%autopatch -p1 +%autosetup -p1 -n %{pkgname}-%{version} -%if 0%{?stable_abi} # check the ABI in the source against what we expect. getmajor() { grep -i ^#define.ABI.$1_VERSION hw/xfree86/common/xf86Module.h | @@ -320,14 +257,8 @@ test `getminor xinput` == %{xinput_minor} test `getmajor extension` == %{extension_major} test `getminor extension` == %{extension_minor} -%endif - %build -export CFLAGS="$RPM_OPT_FLAGS -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1" -export CXXFLAGS="$RPM_OPT_FLAGS -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1" -export LDFLAGS="$RPM_LD_FLAGS -specs=/usr/lib/rpm/redhat/redhat-hardened-ld" - %if !0%{?rhel} %ifarch %{ix86} x86_64 %global int10_arch 1 @@ -381,13 +312,7 @@ install -m 644 %{SOURCE10} $RPM_BUILD_ROOT%{_sysconfdir}/pam.d/xserver # relies on it more or less. mkdir -p $RPM_BUILD_ROOT%{_sysconfdir}/X11/xorg.conf.d -%if %{stable_abi} install -m 755 %{SOURCE30} $RPM_BUILD_ROOT%{_bindir}/xserver-sdk-abi-requires -%else -sed -e s/@MAJOR@/%{gitdate}/g -e s/@MINOR@/%{minor_serial}/g %{SOURCE31} > \ - $RPM_BUILD_ROOT%{_bindir}/xserver-sdk-abi-requires -chmod 755 $RPM_BUILD_ROOT%{_bindir}/xserver-sdk-abi-requires -%endif install -m 0755 %{SOURCE20} $RPM_BUILD_ROOT%{_bindir}/xvfb-run @@ -502,6 +427,12 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Thu Sep 26 2024 Simone Caronni - 21.1.13-2 +- Drop support for building snapshots. If they need to be built, there are + anyway more simpler ways. +- Trim changelog. +- Drop custom compileri/linker flags that are part of the standard already. + * Mon Sep 02 2024 Sérgio Basto - 21.1.13-1 - Update X11-server to 21.1.13 and ABI numbers of videodrv and xinput - DMX DDX was dropped @@ -626,286 +557,3 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete * Sat Jan 22 2022 Fedora Release Engineering - 1.20.14-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild - -* Fri Dec 17 2021 Olivier - 1.20.14-1 -- xserver 1.20.14 - CVE-2021-4008/ZDI-CAN-14192 (#2026059, #2032941) - CVE-2021-4009/ZDI-CAN-14950 (#2026072, #2032943) - CVE-2021-4010/ZDI-CAN-14951 (#2026073, #2032944) - CVE-2021-4011/ZDI-CAN-14952 (#2026074, #2032945) - -* Tue Sep 14 2021 Sahana Prasad - 1.20.11-3 -- Rebuilt with OpenSSL 3.0.0 - -* Fri Jul 23 2021 Fedora Release Engineering - 1.20.11-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild - -* Wed Apr 14 2021 Olivier Fourdan - 1.20.11-1 -- xserver 1.20.11 (CVE-2021-3472 / ZDI-CAN-1259) - -* Wed Feb 03 2021 Peter Hutterer 1.20.10-5 -- Drop BuildRequires for flex-devel (#1871101) - -* Mon Feb 1 2021 Olivier Fourdan - 1.20.10-4 -- Remove Xwayland from the xserver builds - -* Thu Jan 28 2021 Fedora Release Engineering - 1.20.10-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild - -* Tue Jan 19 2021 Adam Jackson - 1.20.10-2 -- Disable int10 and vbe on RHEL -- Disable DRI1 -- Stop overriding the vendor name - -* Wed Dec 2 2020 Olivier Fourdan - 1.20.10-1 -- xserver 1.20.10 (CVE-2020-14360, CVE-2020-25712) - -* Thu Nov 5 10:35:09 AEST 2020 Peter Hutterer - 1.20.9-3 -- Add BuildRequires for make - -* Wed Nov 04 2020 Peter Hutterer 1.20.9-2 -- Drop BuildRequires to git-core only - -* Thu Oct 8 2020 Olivier Fourdan - 1.20.9-1 -- xserver 1.20.9 + all current fixes from upstream - -* Wed Aug 12 2020 Adam Jackson - 1.20.8-4 -- Enable XC-SECURITY - -* Fri Jul 31 2020 Adam Jackson - 1.20.8-3 -- Fix information disclosure bug in pixmap allocation (CVE-2020-14347) - -* Wed Jul 29 2020 Fedora Release Engineering - 1.20.8-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild - -* Mon Mar 30 2020 Olivier Fourdan - 1.20.8-1 -- xserver 1.20.8 -- Backport latest Xwayland randr resolution change emulation support - patches. - -* Wed Mar 18 2020 Olivier Fourdan - 1.20.7-2 -- Fix a crash on closing a window using Present found upstream: - https://gitlab.freedesktop.org/xorg/xserver/issues/1000 - -* Fri Mar 13 2020 Olivier Fourdan - 1.20.7-1 -- xserver 1.20.7 -- backport from stable "xserver-1.20-branch" up to commit ad7364d8d - (for mutter fullscreen unredirect on Wayland) -- Update videodrv minor ABI as 1.20.7 changed the minor ABI version - (backward compatible, API addition in glamor) -- Rebase Xwayland randr resolution change emulation support patches - -* Fri Jan 31 2020 Fedora Release Engineering - 1.20.6-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild - -* Mon Nov 25 2019 Olivier Fourdan - 1.20.6-1 -- xserver 1.20.6 - -* Mon Nov 4 2019 Hans de Goede - 1.20.5-9 -- Fix building with new libglvnd-1.2.0 (E)GL headers and pkgconfig files - -* Mon Nov 4 2019 Hans de Goede - 1.20.5-8 -- Backport Xwayland randr resolution change emulation support - -* Thu Aug 29 2019 Olivier Fourdan 1.20.5-7 -- Pick latest fixes from xserver stable branch upstream (rhbz#1729925) - -* Sat Jul 27 2019 Fedora Release Engineering - 1.20.5-6 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild - -* Mon Jul 8 2019 Olivier Fourdan 1.20.5-5 -- Do not include on ARM with glibc to avoid compilation failure. -- Do not force vbe and int10 sdk headers as this enables int10 which does - not build on ARM without - -* Mon Jul 8 2019 Olivier Fourdan 1.20.5-4 -- Fix regression causing screen tearing with upstream xserver 1.20.5 - (rhbz#1726419) - -* Fri Jun 28 2019 Olivier Fourdan 1.20.5-3 -- Remove atomic downstream patches causing regressions (#1714981, #1723715) -- Xwayland crashes (#1708119, #1691745) -- Cursor issue with tablet on Xwayland -- Xorg/modesetting issue with flipping pixmaps with Present (#1645553) - -* Thu Jun 06 2019 Peter Hutterer 1.20.5-2 -- Return AlreadyGrabbed for keycodes > 255 (#1697804) - -* Thu May 30 2019 Adam Jackson - 1.20.5-1 -- xserver 1.20.5 - -* Tue Apr 23 2019 Adam Jackson - 1.20.4-4 -- Fix some non-atomic modesetting calls to be atomic - -* Wed Mar 27 2019 Peter Hutterer 1.20.4-3 -- Fix a Qt scrolling bug, don't reset the valuator on slave switch - -* Thu Mar 21 2019 Adam Jackson - 1.20.4-2 -- Backport an Xwayland crash fix in the Present code - -* Tue Feb 26 2019 Adam Jackson - 1.20.4-1 -- xserver 1.20.4 - -* Sun Feb 03 2019 Fedora Release Engineering - 1.20.3-4 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild - -* Fri Jan 11 2019 Olivier Fourdan - 1.20.3-3 -- More Xwayland/Present fixes from upstream (rhbz#1609181, rhbz#1661748) - -* Thu Dec 06 2018 Olivier Fourdan - 1.20.3-2 -- Xwayland/Present fixes from master upstream - -* Thu Nov 01 2018 Adam Jackson - 1.20.3-1 -- xserver 1.20.3 - -* Mon Oct 15 2018 Adam Jackson - 1.20.2-1 -- xserver 1.20.2 - -* Thu Oct 4 2018 Hans de Goede - 1.20.1-4 -- Rebase patch to use va_gl as vdpau driver on i965 GPUs, re-fix rhbz#1413733 - -* Thu Sep 13 2018 Dave Airlie - 1.20.1-3 -- Build with PIE enabled (this doesn't enable bind now) - -* Mon Sep 10 2018 Olivier Fourdan - 1.20.1-2 -- Include patches from upstream to fix Xwayland crashes - -* Thu Aug 09 2018 Adam Jackson - 1.20.1-1 -- xserver 1.20.1 - -* Sat Jul 14 2018 Fedora Release Engineering - 1.20.0-5 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild - -* Tue Jun 12 2018 Adam Jackson - 1.20.0-4 -- Xorg and Xwayland Requires: libEGL - -* Fri Jun 01 2018 Adam Williamson - 1.20.0-3 -- Backport fixes for RHBZ#1579067 - -* Wed May 16 2018 Adam Jackson - 1.20.0-2 -- Xorg Requires: xorg-x11-drv-libinput - -* Thu May 10 2018 Adam Jackson - 1.20.0-1 -- xserver 1.20 - -* Wed Apr 25 2018 Adam Jackson - 1.19.99.905-2 -- Fix xvfb-run's default depth to be 24 - -* Tue Apr 24 2018 Adam Jackson - 1.19.99.905-1 -- xserver 1.20 RC5 - -* Thu Apr 12 2018 Olivier Fourdan - 1.19.99.904-2 -- Re-fix "use type instead of which in xvfb-run (rhbz#1443357)" which - was overridden inadvertently - -* Tue Apr 10 2018 Adam Jackson - 1.19.99.904-1 -- xserver 1.20 RC4 - -* Mon Apr 02 2018 Adam Jackson - 1.19.99.903-1 -- xserver 1.20 RC3 - -* Tue Feb 13 2018 Olivier Fourdan 1.19.6-5 -- xwayland: avoid race condition on new keymap -- xwayland: Keep separate variables for pointer and tablet foci (rhbz#1519961) -- xvfb-run now support command line option “--auto-display” - -* Fri Feb 09 2018 Fedora Release Engineering - 1.19.6-4 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild - -* Tue Jan 30 2018 Olivier Fourdan 1.19.6-3 -- Avoid generating a core file when the Wayland compositor is gone. - -* Thu Jan 11 2018 Peter Hutterer 1.19.6-2 -- Fix handling of devices with ID_INPUT=null - -* Wed Dec 20 2017 Adam Jackson - 1.19.6-1 -- xserver 1.19.6 - -* Thu Oct 12 2017 Adam Jackson - 1.19.5-1 -- xserver 1.19.5 - -* Thu Oct 05 2017 Olivier Fourdan - 1.19.4-1 -- xserver-1.19.4 -- Backport tablet support for Xwayland - -* Fri Sep 08 2017 Troy Dawson - 1.19.3-9 -- Cleanup spec file conditionals - -* Thu Aug 03 2017 Fedora Release Engineering - 1.19.3-8 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild - -* Thu Jul 27 2017 Fedora Release Engineering - 1.19.3-7 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild - -* Sun Jul 2 2017 Ville Skyttä - 1.19.3-6 -- Use type instead of which in xvfb-run (rhbz#1443357) - -* Thu May 04 2017 Orion Poplawski - 1.19.3-5 -- Enable full build for s390/x - -* Mon Apr 24 2017 Ben Skeggs - 1.19.3-4 -- Default to xf86-video-modesetting on GeForce 8 and newer - -* Fri Apr 07 2017 Adam Jackson - 1.19.3-3 -- Inoculate against a versioning bug with libdrm 2.4.78 - -* Thu Mar 23 2017 Hans de Goede - 1.19.3-2 -- Use va_gl as vdpau driver on i965 GPUs (rhbz#1413733) - -* Wed Mar 15 2017 Adam Jackson - 1.19.3-1 -- xserver 1.19.3 - -* Thu Mar 02 2017 Adam Jackson - 1.19.2-1 -- xserver 1.19.2 - -* Sat Feb 11 2017 Fedora Release Engineering - 1.19.1-4 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild - -* Wed Feb 01 2017 Peter Hutterer 1.19.1-3 -- Fix a few input thread lock issues causing intel crashes (#1384486) - -* Mon Jan 16 2017 Adam Jackson - 1.19.1-2 -- Limit the intel driver only on F26 and up - -* Wed Jan 11 2017 Adam Jackson - 1.19.1-1 -- xserver 1.19.1 - -* Tue Jan 10 2017 Hans de Goede - 1.19.0-4 -- Follow Debian and only default to the intel ddx on gen4 or older intel GPUs - -* Tue Dec 20 2016 Hans de Goede - 1.19.0-3 -- Add one more patch for better integration with the nvidia binary driver - -* Thu Dec 15 2016 Hans de Goede - 1.19.0-2 -- Add some patches for better integration with the nvidia binary driver -- Add a patch from upstream fixing a crash (rhbz#1389886) - -* Wed Nov 23 2016 Olivier Fourdan 1.19.0-1 -- xserver 1.19.0 -- Fix use after free of cursors in Xwayland (rhbz#1385258) -- Fix an issue where some monitors would show only black, or - partially black when secondary GPU outputs are used - -* Tue Nov 15 2016 Peter Hutterer 1.19.0-0.8.rc2 -- Update device barriers for new master devices (#1384432) - -* Thu Nov 3 2016 Hans de Goede - 1.19.0-0.7.rc2 -- Update to 1.19.0-rc2 -- Fix (hopefully) various crashes in FlushAllOutput() (rhbz#1382444) -- Fix Xwayland crashing in glamor on non glamor capable hw (rhbz#1390018) - -* Tue Nov 1 2016 Ben Crocker - 1.19.0-0.6.20161028 -- Fix Config record allocation during startup: if xorg.conf.d directory -- was absent, a segfault resulted. - -* Mon Oct 31 2016 Adam Jackson - 1.19.0-0.5.20161026 -- Use %%autopatch instead of doing our own custom git-am trick - -* Fri Oct 28 2016 Hans de Goede - 1.19.0-0.4.20161026 -- Add missing Requires: libXfont2-devel to -devel sub-package (rhbz#1389711) - -* Wed Oct 26 2016 Hans de Goede - 1.19.0-0.3.20161026 -- Sync with upstream git, bringing in a bunch if bug-fixes -- Add some extra fixes which are pending upstream -- This also adds PointerWarping emulation to Xwayland, which should improve - compatiblity with many games diff --git a/xserver-sdk-abi-requires.git b/xserver-sdk-abi-requires.git deleted file mode 100755 index c033061..0000000 --- a/xserver-sdk-abi-requires.git +++ /dev/null @@ -1,14 +0,0 @@ -#!/bin/sh -# -# The X server provides capabilities of the form: -# -# Provides: xserver-abi(ansic-0) = 4 -# -# for an ABI version of 0.4. The major number is encoded into the name so -# that major number changes force upgrades. If we didn't, then -# -# Requires: xserver-abi(ansic) >= 0.4 -# -# would also match 1.0, which is wrong since major numbers mean an ABI break. - -echo "xserver-abi($1-@MAJOR@) >= @MINOR@" diff --git a/xserver-sdk-abi-requires.release b/xserver-sdk-abi-requires.release deleted file mode 100755 index 30d77bf..0000000 --- a/xserver-sdk-abi-requires.release +++ /dev/null @@ -1,19 +0,0 @@ -#!/bin/sh -# -# The X server provides capabilities of the form: -# -# Provides: xserver-abi(ansic-0) = 4 -# -# for an ABI version of 0.4. The major number is encoded into the name so -# that major number changes force upgrades. If we didn't, then -# -# Requires: xserver-abi(ansic) >= 0.4 -# -# would also match 1.0, which is wrong since major numbers mean an ABI break. - -ver=$(pkg-config --variable abi_$1 xorg-server) - -major=$(echo $ver | cut -f 1 -d .) -minor=$(echo $ver | cut -f 2 -d .) - -echo "xserver-abi($1-$major) >= $minor" From 2cdddcc3e1afaa0943ffb27d160cf9689fdf8c22 Mon Sep 17 00:00:00 2001 From: Simone Caronni Date: Thu, 26 Sep 2024 22:16:51 +0200 Subject: [PATCH 51/74] Clean up .gitignore --- .gitignore | 36 +----------------------------------- 1 file changed, 1 insertion(+), 35 deletions(-) diff --git a/.gitignore b/.gitignore index 89c66cc..29790d0 100644 --- a/.gitignore +++ b/.gitignore @@ -1,37 +1,3 @@ -xorg-server-1.9.1.tar.bz2 -/xorg-server-20101125.tar.xz -/xorg-server-20101201.tar.xz -/xorg-server-1.10.0.tar.bz2 -/xorg-server-20110418.tar.xz -/xorg-server-20110510.tar.xz -/xorg-server-20110818.tar.xz -/xorg-server-1.11.0.tar.bz2 -/xorg-server-1.11.1.tar.bz2 -/xorg-server-20111109.tar.xz -/xorg-server-20120103.tar.xz -/xorg-server-20120124.tar.xz -/xorg-server-20120215.tar.xz -/xorg-server-1.12.0.tar.bz2 -/xorg-server-1.12.1.tar.bz2 -/xorg-server-1.12.2.tar.bz2 -/xorg-server-1.12.3.tar.bz2 -/xorg-server-20120717.tar.xz -/xorg-server-20120726.tar.xz -/xorg-server-20120808.tar.xz -/xorg-server-20120822.tar.xz -/xorg-server-1.13.0.tar.bz2 -/xorg-server-1.13.1.tar.bz2 -/xorg-server-20130109.tar.xz -/xorg-server-20130215.tar.xz -/xorg-server-1.14.0.tar.bz2 -/xorg-server-1.14.1.tar.bz2 -/xorg-server-1.14.1.901.tar.bz2 -/xorg-server-1.14.2.tar.bz2 -/xorg-server-1.14.3.tar.bz2 -/xorg-server-1.14.99.3.tar.bz2 -/xorg-server-1.14.99.901.tar.bz2 -/xorg-server-1.14.99.902.tar.bz2 *.bz2 *.xz -/xorg-x11-server-1.15.0-1.fc21.src.rpm -/xorg-server-1.20.14.tar.gz +*.gz From 00592f1f261d593556a7ee396e4889b8a3300b53 Mon Sep 17 00:00:00 2001 From: Simone Caronni Date: Fri, 27 Sep 2024 09:40:24 +0200 Subject: [PATCH 52/74] Switch to meson for building --- ...search-for-the-fontrootdir-ourselves.patch | 72 --------- xorg-x11-server.spec | 140 +++++++++--------- 2 files changed, 72 insertions(+), 140 deletions(-) delete mode 100644 0001-configure.ac-search-for-the-fontrootdir-ourselves.patch diff --git a/0001-configure.ac-search-for-the-fontrootdir-ourselves.patch b/0001-configure.ac-search-for-the-fontrootdir-ourselves.patch deleted file mode 100644 index 3e29358..0000000 --- a/0001-configure.ac-search-for-the-fontrootdir-ourselves.patch +++ /dev/null @@ -1,72 +0,0 @@ -From e67e988730346c63d2f0cdf2531ed36b0c7ad5a6 Mon Sep 17 00:00:00 2001 -From: Peter Hutterer -Date: Wed, 23 Nov 2022 14:50:29 +1000 -Subject: [PATCH xserver] configure.ac: search for the fontrootdir ourselves - -This replaces the use of font-utils' .m4 macro set with a copy of the -only one we actually want: the bit for the fontrootpath. - -We don't need configure options for every single subfont directory, so -let's hardcode those in the default font path. Like meson does upstream -too. - -With this patch we no longer require the font-utils dependency. - -Signed-off-by: Peter Hutterer ---- - configure.ac | 28 +++++++++++++++++----------- - 1 file changed, 17 insertions(+), 11 deletions(-) - -diff --git a/configure.ac b/configure.ac -index 0909cc5b4d..2349320888 100644 ---- a/configure.ac -+++ b/configure.ac -@@ -49,9 +49,6 @@ XORG_WITH_XSLTPROC - XORG_ENABLE_UNIT_TESTS - XORG_LD_WRAP([optional]) - --m4_ifndef([XORG_FONT_MACROS_VERSION], [m4_fatal([must install font-util 1.1 or later before running autoconf/autogen])]) --XORG_FONT_MACROS_VERSION(1.1) -- - dnl this gets generated by autoheader, and thus contains all the defines. we - dnl don't ever actually use it, internally. - AC_CONFIG_HEADERS(include/do-not-use-config.h) -@@ -450,18 +447,27 @@ AC_MSG_RESULT([$FALLBACK_INPUT_DRIVER]) - AC_DEFINE_UNQUOTED(FALLBACK_INPUT_DRIVER, ["$FALLBACK_INPUT_DRIVER"], [ Fallback input driver ]) - - dnl Determine font path --XORG_FONTROOTDIR --XORG_FONTSUBDIR(FONTMISCDIR, fontmiscdir, misc) --XORG_FONTSUBDIR(FONTOTFDIR, fontotfdir, OTF) --XORG_FONTSUBDIR(FONTTTFDIR, fontttfdir, TTF) --XORG_FONTSUBDIR(FONTTYPE1DIR, fonttype1dir, Type1) --XORG_FONTSUBDIR(FONT75DPIDIR, font75dpidir, 75dpi) --XORG_FONTSUBDIR(FONT100DPIDIR, font100dpidir, 100dpi) -+dnl This is a copy of XORG_FONTROOTDIR from font-utils so we can drop the dependency -+AC_MSG_CHECKING([for root directory for font files]) -+AC_ARG_WITH(fontrootdir, -+ AS_HELP_STRING([--with-fontrootdir=DIR], -+ [Path to root directory for font files]), -+ [FONTROOTDIR="$withval"]) -+# if --with-fontrootdir not specified... -+if test "x${FONTROOTDIR}" = "x"; then -+ FONTROOTDIR=`$PKG_CONFIG --variable=fontrootdir fontutil` -+fi -+# ...and if pkg-config didn't find fontdir in fontutil.pc... -+if test "x${FONTROOTDIR}" = "x"; then -+ FONTROOTDIR="${datadir}/fonts/X11" -+fi -+AC_SUBST(FONTROOTDIR) -+AC_MSG_RESULT([${FONTROOTDIR}]) - - dnl Uses --with-default-font-path if set, otherwise uses standard - dnl subdirectories of FONTROOTDIR. Some distros set the default font path to - dnl "catalogue:/etc/X11/fontpath.d,built-ins" --DEFAULT_FONT_PATH="${FONTMISCDIR}/,${FONTTTFDIR}/,${FONTOTFDIR}/,${FONTTYPE1DIR}/,${FONT100DPIDIR}/,${FONT75DPIDIR}/" -+DEFAULT_FONT_PATH="${FONTROOTDIR}/misc,${FONTROOTDIR}/OTF,${FONTROOTDIR}/TTF,${FONTROOTDIR}/Type1,${FONTROOTDIR}/75dpi,${FONTROOTDIR}/100dpi" - case $host_os in - darwin*) DEFAULT_FONT_PATH="${DEFAULT_FONT_PATH},/Library/Fonts,/System/Library/Fonts" ;; - esac --- -2.38.1 - diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 3f514a5..9a7799b 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -18,7 +18,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 21.1.13 -Release: 2%{?dist} +Release: 3%{?dist} URL: http://www.x.org # SPDX License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant @@ -45,24 +45,15 @@ Patch2: 0001-xfree86-use-modesetting-driver-by-default-on-GeForce.patch Patch3: 0001-xf86-dri2-Use-va_gl-as-vdpau_driver-for-Intel-i965-G.patch # because the display-managers are not ready yet, do not upstream Patch6: 0001-Fedora-hack-Make-the-suid-root-wrapper-always-start-.patch -# Not sure anyone else cares about this so let's keep this Fedora-only for now -# Upstream PR for the meson.build equivalent is here, so we can drop this patch -# when we start building with meson. -# https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/1001` -Patch7: 0001-configure.ac-search-for-the-fontrootdir-ourselves.patch # Fix compilation error on i686 (21.1.14+) # https://gitlab.freedesktop.org/xorg/xserver/-/commit/8407181c7dfe14086d99697af0b86120320ab73e Patch1024: 0001-ephyr-Fix-incompatible-pointer-type-build-error.patch -## Add new patches above; Fedora-specific patches below - - +BuildRequires: gcc BuildRequires: make +BuildRequires: meson BuildRequires: systemtap-sdt-devel BuildRequires: git-core -BuildRequires: automake -BuildRequires: autoconf -BuildRequires: libtool BuildRequires: pkgconfig BuildRequires: xorg-x11-util-macros >= 1.17 @@ -102,12 +93,9 @@ BuildRequires: kernel-headers BuildRequires: audit-libs-devel BuildRequires: libselinux-devel >= 2.0.86-1 BuildRequires: libudev-devel -# libunwind is Exclusive for the following arches -%ifarch aarch64 %{arm} hppa ia64 mips ppc ppc64 %{ix86} x86_64 %if !0%{?rhel} BuildRequires: libunwind-devel %endif -%endif BuildRequires: pkgconfig(xcb-aux) BuildRequires: pkgconfig(xcb-image) @@ -258,52 +246,71 @@ test `getmajor extension` == %{extension_major} test `getminor extension` == %{extension_minor} %build +%meson \ + -D agp=auto \ + -D builder_string="Build ID: %{name} %{version}-%{release}" \ + -D default_font_path="catalogue:/etc/X11/fontpath.d,built-ins" \ + -D devel-docs=false \ + -D dga=true \ + -D docs-pdf=false \ + -D docs=false \ + -D dpms=true \ + -D dri1=false \ + -D dri2=true \ + -D dri3=%{?!rhel:true}%{?rhel:false} \ + -D drm=true \ + -D dtrace=false \ + -D fallback_input_driver=libinput \ + -D glamor=true \ + -D glx=true \ + -D hal=false \ + -D input_thread=true \ + -D int10=%{?!rhel:auto}%{?rhel:false} \ + -D ipv6=true \ + -D libunwind=%{?!rhel:true}%{?rhel:false} \ + -D linux_acpi=false \ + -D linux_apm=false \ + -D listen_local=true \ + -D listen_tcp=false \ + -D listen_unix=true \ + -D log_dir="%{_localstatedir}/log" \ + -D mitshm=auto \ + -D module_dir="%{_libdir}/xorg/modules" \ + -D pciaccess=true \ + -D screensaver=true \ + -D secure-rpc=false \ + -D sha1=libcrypto \ + -D suid_wrapper=true \ + -D systemd_logind=true \ + -D udev_kms=true \ + -D udev=true \ + -D vgahw=true \ + -D xace=true \ + -D xcsecurity=true \ + -D xdm-auth-1=true \ + -D xdmcp=true \ + -D xephyr=true \ + -D xf86bigfont=false \ + -D xf86-input-inputtest=true \ + -D xinerama=true \ + -D xkb_output_dir="%{_localstatedir}/lib/xkb" \ + -D xnest=true \ + -D xorg=true \ + -D xpbproxy=false \ + -D xquartz=false \ + -D xres=true \ + -D xselinux=true \ + -D xvfb=true \ + -D xvmc=true \ + -D xv=true \ + -D xwin=false -%if !0%{?rhel} -%ifarch %{ix86} x86_64 -%global int10_arch 1 -%endif -%endif - -%if %{undefined int10_arch} -%global no_int10 --disable-vbe --disable-int10-module -%endif - -%global kdrive --enable-kdrive --enable-xephyr --disable-xfake --disable-xfbdev -%global xservers --enable-xvfb --enable-xnest %{kdrive} --enable-xorg -%global default_font_path "catalogue:/etc/X11/fontpath.d,built-ins" -%global dri_flags --disable-dri --enable-dri2 %{?!rhel:--enable-dri3} --enable-suid-wrapper --enable-glamor - -autoreconf -f -v --install || exit 1 - -%configure %{xservers} \ - --enable-dependency-tracking \ - --disable-static \ - --with-pic \ - %{?no_int10} \ - --with-default-font-path=%{default_font_path} \ - --with-module-dir=%{_libdir}/xorg/modules \ - --with-builderstring="Build ID: %{name} %{version}-%{release}" \ - --with-os-name="$(hostname -s) $(uname -r)" \ - --with-xkb-output=%{_localstatedir}/lib/xkb \ - --without-dtrace \ - --disable-linux-acpi --disable-linux-apm \ - --enable-xselinux --enable-record --enable-present \ - --enable-xcsecurity \ - --enable-config-udev \ - --disable-unit-tests \ - --enable-dmx \ - --disable-xwayland \ - %{dri_flags} \ - ${CONFIGURE} - -make V=1 %{?_smp_mflags} - +%meson_build %install -%make_install +%meson_install -mkdir -p $RPM_BUILD_ROOT%{_libdir}/xorg/modules/{drivers,input} +install -D -m 0644 -p xkb/README.compiled $RPM_BUILD_ROOT%{_localstatedir}/lib/xkb/README.compiled mkdir -p $RPM_BUILD_ROOT%{_sysconfdir}/pam.d install -m 644 %{SOURCE10} $RPM_BUILD_ROOT%{_sysconfdir}/pam.d/xserver @@ -331,7 +338,7 @@ cp {,%{inst_srcdir}/}hw/xfree86/Xorg.sh.in cp xkb/README.compiled %{inst_srcdir}/xkb cp hw/xfree86/xorgconf.cpp %{inst_srcdir}/hw/xfree86 -find . -type f | egrep '.*\.(c|h|am|ac|inc|m4|h.in|pc.in|man.pre|pl|txt)$' | +find . -type f -not -path "./%{_vpath_builddir}/*" | egrep '.*\.(c|h|am|ac|inc|m4|h.in|pc.in|man.pre|pl|txt)$' | xargs tar cf - | (cd %{inst_srcdir} && tar xf -) find %{inst_srcdir}/hw/xfree86 -name \*.c -delete @@ -352,19 +359,14 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %dir %{_localstatedir}/lib/xkb %{_localstatedir}/lib/xkb/README.compiled -%if 1 -%global Xorgperms %attr(4755, root, root) -%else -# disable until module loading is audited -%global Xorgperms %attr(0711,root,root) %caps(cap_sys_admin,cap_sys_rawio,cap_dac_override=pe) -%endif - %files Xorg %config %attr(0644,root,root) %{_sysconfdir}/pam.d/xserver %{_bindir}/X %{_bindir}/Xorg %{_libexecdir}/Xorg -%{Xorgperms} %{_libexecdir}/Xorg.wrap +# Disable until module loading is audited +# %attr(0711,root,root) %caps(cap_sys_admin,cap_sys_rawio,cap_dac_override=pe) +%attr(4755, root, root) %{_libexecdir}/Xorg.wrap %{_bindir}/gtf %dir %{_libdir}/xorg %dir %{_libdir}/xorg/modules @@ -382,9 +384,8 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %{_libdir}/xorg/modules/libshadowfb.so %{_libdir}/xorg/modules/libvgahw.so %{_libdir}/xorg/modules/libwfb.so -%if %{defined int10_arch} +%if !0%{?rhel} %{_libdir}/xorg/modules/libint10.so -#%%{_libdir}/xorg/modules/libvbe.so %endif %{_mandir}/man1/gtf.1* %{_mandir}/man1/Xorg.1* @@ -427,6 +428,9 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog +* Fri Sep 27 2024 Simone Caronni - 21.1.13-3 +- Switch to meson, drop no longer required patch. + * Thu Sep 26 2024 Simone Caronni - 21.1.13-2 - Drop support for building snapshots. If they need to be built, there are anyway more simpler ways. From 73f289de65aa3a37cfd7ae8e25fc62f5c5656b86 Mon Sep 17 00:00:00 2001 From: Simone Caronni Date: Fri, 27 Sep 2024 09:56:22 +0200 Subject: [PATCH 53/74] Drop Obsoletes/Provides that have been removed in ~2014 --- xorg-x11-server.spec | 9 +-------- 1 file changed, 1 insertion(+), 8 deletions(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 9a7799b..a20123b 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -128,12 +128,6 @@ Provides: xserver-abi(ansic-%{ansic_major}) = %{ansic_minor} Provides: xserver-abi(videodrv-%{videodrv_major}) = %{videodrv_minor} Provides: xserver-abi(xinput-%{xinput_major}) = %{xinput_minor} Provides: xserver-abi(extension-%{extension_major}) = %{extension_minor} -Obsoletes: xorg-x11-glamor < %{version}-%{release} -Provides: xorg-x11-glamor = %{version}-%{release} -Obsoletes: xorg-x11-drv-modesetting < %{version}-%{release} -Provides: xorg-x11-drv-modesetting = %{version}-%{release} -# Dropped from F25 -Obsoletes: xorg-x11-drv-vmmouse < 13.1.0-4 # Dropped from xorg-x11-server-21.1 # https://gitlab.freedesktop.org/xorg/xserver/-/commit/b3b81c8c2090cd49410960a021baf0d27fdd2ab3 Obsoletes: xorg-x11-server-Xdmx < 1.20.15 @@ -204,8 +198,6 @@ Requires: xorg-x11-proto-devel Requires: libXfont2-devel Requires: pkgconfig pixman-devel libpciaccess-devel Provides: xorg-x11-server-static -Obsoletes: xorg-x11-glamor-devel < %{version}-%{release} -Provides: xorg-x11-glamor-devel = %{version}-%{release} %description devel The SDK package provides the developmental files which are necessary for @@ -430,6 +422,7 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %changelog * Fri Sep 27 2024 Simone Caronni - 21.1.13-3 - Switch to meson, drop no longer required patch. +- Drop Obsoletes/Provides that have been removed in ~2014. * Thu Sep 26 2024 Simone Caronni - 21.1.13-2 - Drop support for building snapshots. If they need to be built, there are From ddd6374980bc5a93c2e88976557107943b664c87 Mon Sep 17 00:00:00 2001 From: Simone Caronni Date: Fri, 27 Sep 2024 10:53:34 +0200 Subject: [PATCH 54/74] Add build depdendencies as they are searched by meson --- xorg-x11-server.spec | 119 ++++++++++++++++++++++++------------------- 1 file changed, 67 insertions(+), 52 deletions(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index a20123b..abc926b 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -49,60 +49,74 @@ Patch6: 0001-Fedora-hack-Make-the-suid-root-wrapper-always-start-.patch # https://gitlab.freedesktop.org/xorg/xserver/-/commit/8407181c7dfe14086d99697af0b86120320ab73e Patch1024: 0001-ephyr-Fix-incompatible-pointer-type-build-error.patch -BuildRequires: gcc -BuildRequires: make -BuildRequires: meson -BuildRequires: systemtap-sdt-devel -BuildRequires: git-core -BuildRequires: pkgconfig -BuildRequires: xorg-x11-util-macros >= 1.17 - -BuildRequires: xorg-x11-proto-devel >= 7.7-10 - -BuildRequires: dbus-devel -BuildRequires: libepoxy-devel -BuildRequires: systemd-devel -BuildRequires: xorg-x11-xtrans-devel >= 1.3.2 -BuildRequires: libXfont2-devel -BuildRequires: libXau-devel -BuildRequires: libxkbfile-devel -BuildRequires: libXres-devel -BuildRequires: libfontenc-devel -BuildRequires: libXtst-devel -BuildRequires: libXdmcp-devel -BuildRequires: libX11-devel -BuildRequires: libXext-devel -BuildRequires: libXinerama-devel -BuildRequires: libXi-devel - -BuildRequires: pkgconfig(epoxy) -BuildRequires: pkgconfig(xshmfence) >= 1.1 -BuildRequires: libXv-devel -BuildRequires: pixman-devel >= 0.30.0 -BuildRequires: libpciaccess-devel >= 0.13.1 -BuildRequires: openssl-devel -BuildRequires: bison -BuildRequires: flex -BuildRequires: mesa-libGL-devel >= 9.2 -BuildRequires: mesa-libEGL-devel -BuildRequires: mesa-libgbm-devel -# XXX silly... -BuildRequires: libdrm-devel >= 2.4.0 -BuildRequires: kernel-headers - -BuildRequires: audit-libs-devel -BuildRequires: libselinux-devel >= 2.0.86-1 -BuildRequires: libudev-devel +BuildRequires: bison +BuildRequires: flex +BuildRequires: gcc +BuildRequires: kernel-headers +BuildRequires: libXi-devel +BuildRequires: libXinerama-devel +BuildRequires: libXres-devel +BuildRequires: libXv-devel +BuildRequires: make +BuildRequires: mesa-libEGL-devel +BuildRequires: mesa-libGL-devel >= 9.2 +BuildRequires: meson +BuildRequires: pkgconfig +BuildRequires: pkgconfig(audit) +BuildRequires: pkgconfig(bigreqsproto) >= 1.1.0 +BuildRequires: pkgconfig(compositeproto) >= 0.4 +BuildRequires: pkgconfig(damageproto) >= 1.1 +BuildRequires: pkgconfig(dbus-1) >= 1.0 +BuildRequires: pkgconfig(dri2proto) >= 2.8 +BuildRequires: pkgconfig(dri3proto) >= 1.2 +BuildRequires: pkgconfig(epoxy) +BuildRequires: pkgconfig(epoxy) >= 1.5.4 +BuildRequires: pkgconfig(fixesproto) >= 6.0 +BuildRequires: pkgconfig(fontsproto) >= 2.1.3 +BuildRequires: pkgconfig(gbm) >= 10.2 +BuildRequires: pkgconfig(inputproto) >= 2.3.99.1 +BuildRequires: pkgconfig(kbproto) >= 1.0.3 +BuildRequires: pkgconfig(libdrm) >= 2.4.89 +BuildRequires: pkgconfig(libselinux) >= 2.0.86 +BuildRequires: pkgconfig(libsystemd) >= 209 +BuildRequires: pkgconfig(libudev) >= 143 %if !0%{?rhel} -BuildRequires: libunwind-devel +BuildRequires: pkgconfig(libunwind) %endif - -BuildRequires: pkgconfig(xcb-aux) -BuildRequires: pkgconfig(xcb-image) -BuildRequires: pkgconfig(xcb-icccm) -BuildRequires: pkgconfig(xcb-keysyms) -BuildRequires: pkgconfig(xcb-renderutil) -BuildRequires: pkgconfig(libxcvt) +BuildRequires: pkgconfig(libxcvt) +BuildRequires: pkgconfig(openssl) +BuildRequires: pkgconfig(pciaccess) >= 0.12.901 +BuildRequires: pkgconfig(pixman-1) +BuildRequires: pkgconfig(randrproto) >= 1.6.0 +BuildRequires: pkgconfig(recordproto) >= 1.13.99.1 +BuildRequires: pkgconfig(renderproto) >= 0.11 +BuildRequires: pkgconfig(resourceproto) >= 1.2.0 +BuildRequires: pkgconfig(scrnsaverproto) >= 1.1 +BuildRequires: pkgconfig(videoproto) +BuildRequires: pkgconfig(x11) +BuildRequires: pkgconfig(x11-xcb) +BuildRequires: pkgconfig(xau) +BuildRequires: pkgconfig(xcb-aux) +BuildRequires: pkgconfig(xcb-icccm) +BuildRequires: pkgconfig(xcb-image) +BuildRequires: pkgconfig(xcb-keysyms) +BuildRequires: pkgconfig(xcb-renderutil) +BuildRequires: pkgconfig(xcmiscproto) >= 1.2.0 +BuildRequires: pkgconfig(xdmcp) +BuildRequires: pkgconfig(xext) >= 1.0.99.4 +BuildRequires: pkgconfig(xextproto) >= 7.2.99.901 +BuildRequires: pkgconfig(xf86bigfontproto) >= 1.2.0 +BuildRequires: pkgconfig(xf86vidmodeproto) >= 2.2.99.1 +BuildRequires: pkgconfig(xfont2) >= 2.0 +BuildRequires: pkgconfig(xineramaproto) +BuildRequires: pkgconfig(xkbfile) +BuildRequires: pkgconfig(xproto) >= 7.0.31 +BuildRequires: pkgconfig(xshmfence) >= 1.1 +BuildRequires: pkgconfig(xtrans) >= 1.3.5 +BuildRequires: pkgconfig(xtrans) >= 1.3.5 +BuildRequires: systemtap-sdt-devel +BuildRequires: xorg-x11-util-macros >= 1.17 +BuildRequires: xorg-x11-xtrans-devel >= 1.3.2 %description X.Org X11 X server @@ -423,6 +437,7 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete * Fri Sep 27 2024 Simone Caronni - 21.1.13-3 - Switch to meson, drop no longer required patch. - Drop Obsoletes/Provides that have been removed in ~2014. +- Add build depdendencies as they are searched by meson. * Thu Sep 26 2024 Simone Caronni - 21.1.13-2 - Drop support for building snapshots. If they need to be built, there are From b8c1f8e99ca043ca5b20b342c77ec3b2fd8b9ac5 Mon Sep 17 00:00:00 2001 From: Simone Caronni Date: Fri, 27 Sep 2024 10:54:01 +0200 Subject: [PATCH 55/74] Format SPEC file --- xorg-x11-server.spec | 222 +++++++++++++++++++++---------------------- 1 file changed, 106 insertions(+), 116 deletions(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index abc926b..c206d12 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -2,8 +2,7 @@ %undefine _hardened_build %undefine _strict_symbol_defs_build -# Released ABI versions. Have to keep these manually in sync with the -# source because rpm is a terrible language. +# Released ABI versions: %global ansic_major 0 %global ansic_minor 4 %global videodrv_major 25 @@ -15,39 +14,36 @@ %global pkgname xorg-server -Summary: X.Org X11 X server -Name: xorg-x11-server -Version: 21.1.13 -Release: 3%{?dist} -URL: http://www.x.org +Summary: X.Org X11 X server +Name: xorg-x11-server +Version: 21.1.13 +Release: 3%{?dist} +URL: http://www.x.org # SPDX -License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant +License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant -Source0: https://www.x.org/pub/individual/xserver/%{pkgname}-%{version}.tar.xz +Source0: https://www.x.org/pub/individual/xserver/%{pkgname}-%{version}.tar.xz Source10: xserver.pamd - # "useful" xvfb-run script -Source20: http://svn.exactcode.de/t2/trunk/package/xorg/xorg-server/xvfb-run.sh - +Source20: http://svn.exactcode.de/t2/trunk/package/xorg/xorg-server/xvfb-run.sh # for requires generation in drivers -Source30: xserver-sdk-abi-requires - +Source30: xserver-sdk-abi-requires # maintainer convenience script -Source40: driver-abi-rebuild.sh +Source40: driver-abi-rebuild.sh # From Debian use intel ddx driver only for gen4 and older chipsets -Patch1: 06_use-intel-only-on-pre-gen4.diff +Patch0: 06_use-intel-only-on-pre-gen4.diff # Default to xf86-video-modesetting on GeForce 8 and newer -Patch2: 0001-xfree86-use-modesetting-driver-by-default-on-GeForce.patch +Patch1: 0001-xfree86-use-modesetting-driver-by-default-on-GeForce.patch # Default to va_gl on intel i965 as we use the modesetting drv there # va_gl should probably just be the default everywhere ? -Patch3: 0001-xf86-dri2-Use-va_gl-as-vdpau_driver-for-Intel-i965-G.patch +Patch2: 0001-xf86-dri2-Use-va_gl-as-vdpau_driver-for-Intel-i965-G.patch # because the display-managers are not ready yet, do not upstream -Patch6: 0001-Fedora-hack-Make-the-suid-root-wrapper-always-start-.patch +Patch3: 0001-Fedora-hack-Make-the-suid-root-wrapper-always-start-.patch # Fix compilation error on i686 (21.1.14+) # https://gitlab.freedesktop.org/xorg/xserver/-/commit/8407181c7dfe14086d99697af0b86120320ab73e -Patch1024: 0001-ephyr-Fix-incompatible-pointer-type-build-error.patch +Patch4: 0001-ephyr-Fix-incompatible-pointer-type-build-error.patch BuildRequires: bison BuildRequires: flex @@ -119,113 +115,110 @@ BuildRequires: xorg-x11-util-macros >= 1.17 BuildRequires: xorg-x11-xtrans-devel >= 1.3.2 %description -X.Org X11 X server +X.Org X11 X server. -%package common -Summary: Xorg server common files -Requires: pixman >= 0.30.0 -Requires: xkeyboard-config xkbcomp +%package common +Summary: Xorg server common files +Requires: pixman +Requires: xkbcomp +Requires: xkeyboard-config -%description common +%description common Common files shared among all X servers. -%package Xorg -Summary: Xorg X server -Provides: Xorg = %{version}-%{release} -Provides: Xserver +%package Xorg +Summary: Xorg X server +Requires: libEGL +Requires: system-setup-keyboard +Requires: xorg-x11-drv-libinput +Requires: xorg-x11-server-common >= %{version}-%{release} +Provides: Xorg = %{version}-%{release} +Provides: Xserver # HdG: This should be moved to the wrapper package once the wrapper gets # its own sub-package: -Provides: xorg-x11-server-wrapper = %{version}-%{release} -Provides: xserver-abi(ansic-%{ansic_major}) = %{ansic_minor} -Provides: xserver-abi(videodrv-%{videodrv_major}) = %{videodrv_minor} -Provides: xserver-abi(xinput-%{xinput_major}) = %{xinput_minor} -Provides: xserver-abi(extension-%{extension_major}) = %{extension_minor} +Provides: xorg-x11-server-wrapper = %{version}-%{release} +Provides: xserver-abi(ansic-%{ansic_major}) = %{ansic_minor} +Provides: xserver-abi(videodrv-%{videodrv_major}) = %{videodrv_minor} +Provides: xserver-abi(xinput-%{xinput_major}) = %{xinput_minor} +Provides: xserver-abi(extension-%{extension_major}) = %{extension_minor} # Dropped from xorg-x11-server-21.1 # https://gitlab.freedesktop.org/xorg/xserver/-/commit/b3b81c8c2090cd49410960a021baf0d27fdd2ab3 -Obsoletes: xorg-x11-server-Xdmx < 1.20.15 +Obsoletes: xorg-x11-server-Xdmx < 1.20.15 -Requires: xorg-x11-server-common >= %{version}-%{release} -Requires: system-setup-keyboard -Requires: xorg-x11-drv-libinput -Requires: libEGL - -%description Xorg -X.org X11 is an open source implementation of the X Window System. It -provides the basic low level functionality which full fledged -graphical user interfaces (GUIs) such as GNOME and KDE are designed -upon. +%description Xorg +X.org X11 is an open source implementation of the X Window System. It provides +the basic low level functionality which full fledged graphical user interfaces +(GUIs) such as GNOME and KDE are designed upon. -%package Xnest -Summary: A nested server -Requires: xorg-x11-server-common >= %{version}-%{release} -Provides: Xnest +%package Xnest +Summary: A nested server +Requires: xorg-x11-server-common >= %{version}-%{release} +Provides: Xnest -%description Xnest -Xnest is an X server which has been implemented as an ordinary -X application. It runs in a window just like other X applications, -but it is an X server itself in which you can run other software. It -is a very useful tool for developers who wish to test their -applications without running them on their real X server. +%description Xnest +Xnest is an X server which has been implemented as an ordinary X application. It +runs in a window just like other X applications, but it is an X server itself in +which you can run other software. It is a very useful tool for developers who +wish to test their applications without running them on their real X server. -%package Xvfb -Summary: A X Windows System virtual framebuffer X server +%package Xvfb +Summary: A X Windows System virtual framebuffer X server # xvfb-run is GPLv2, rest is MIT -License: MIT and GPLv2 -Requires: xorg-x11-server-common >= %{version}-%{release} +License: MIT and GPLv2 +Requires: xorg-x11-server-common >= %{version}-%{release} # required for xvfb-run -Requires: xorg-x11-xauth -Requires: util-linux -Provides: Xvfb +Requires: xorg-x11-xauth +Provides: Xvfb +Requires: util-linux -%description Xvfb -Xvfb (X Virtual Frame Buffer) is an X server that is able to run on -machines with no display hardware and no physical input devices. -Xvfb simulates a dumb framebuffer using virtual memory. Xvfb does -not open any devices, but behaves otherwise as an X display. Xvfb -is normally used for testing servers. +%description Xvfb +Xvfb (X Virtual Frame Buffer) is an X server that is able to run on machines +with no display hardware and no physical input devices. Xvfb simulates a dumb +framebuffer using virtual memory. Xvfb does not open any devices, but behaves +otherwise as an X display. Xvfb is normally used for testing servers. -%package Xephyr -Summary: A nested server -Requires: xorg-x11-server-common >= %{version}-%{release} -Provides: Xephyr +%package Xephyr +Summary: A nested server +Requires: xorg-x11-server-common >= %{version}-%{release} +Provides: Xephyr -%description Xephyr -Xephyr is an X server which has been implemented as an ordinary -X application. It runs in a window just like other X applications, -but it is an X server itself in which you can run other software. It -is a very useful tool for developers who wish to test their -applications without running them on their real X server. Unlike -Xnest, Xephyr renders to an X image rather than relaying the -X protocol, and therefore supports the newer X extensions like -Render and Composite. +%description Xephyr +Xephyr is an X server which has been implemented as an ordinary X application. +It runs in a window just like other X applications, but it is an X server itself +in which you can run other software. It is a very useful tool for developers who +wish to test their applications without running them on their real X server. +Unlike Xnest, Xephyr renders to an X image rather than relaying the X protocol, +and therefore supports the newer X extensions like Render and Composite. -%package devel -Summary: SDK for X server driver module development -Requires: xorg-x11-util-macros -Requires: xorg-x11-proto-devel -Requires: libXfont2-devel -Requires: pkgconfig pixman-devel libpciaccess-devel -Provides: xorg-x11-server-static +%package devel +Summary: SDK for X server driver module development +Requires: libpciaccess-devel +Requires: libXfont2-devel +Requires: xorg-x11-proto-devel +Requires: xorg-x11-util-macros +Requires: pixman-devel +Requires: pkgconfig +Provides: xorg-x11-server-static %description devel The SDK package provides the developmental files which are necessary for -developing X server driver modules, and for compiling driver modules -outside of the standard X11 source code tree. Developers writing video -drivers, input drivers, or other X modules should install this package. +developing X server driver modules, and for compiling driver modules outside of +the standard X11 source code tree. Developers writing video drivers, input +drivers, or other X modules should install this package. -%package source -Summary: Xserver source code required to build VNC server (Xvnc) -BuildArch: noarch +%package source +Summary: Xserver source code required to build VNC server (Xvnc) +BuildArch: noarch -%description source -Xserver source code needed to build VNC server (Xvnc) +%description source +Xserver source code needed to build VNC server (Xvnc). %prep @@ -316,18 +309,15 @@ test `getminor extension` == %{extension_minor} %install %meson_install -install -D -m 0644 -p xkb/README.compiled $RPM_BUILD_ROOT%{_localstatedir}/lib/xkb/README.compiled - -mkdir -p $RPM_BUILD_ROOT%{_sysconfdir}/pam.d -install -m 644 %{SOURCE10} $RPM_BUILD_ROOT%{_sysconfdir}/pam.d/xserver +install -D -m 0644 -p xkb/README.compiled %{buildroot}%{_localstatedir}/lib/xkb/README.compiled +install -D -m 0644 %{SOURCE10} %{buildroot}%{_sysconfdir}/pam.d/xserver # make sure the (empty) /etc/X11/xorg.conf.d is there, system-setup-keyboard # relies on it more or less. -mkdir -p $RPM_BUILD_ROOT%{_sysconfdir}/X11/xorg.conf.d +mkdir -p %{buildroot}%{_sysconfdir}/X11/xorg.conf.d -install -m 755 %{SOURCE30} $RPM_BUILD_ROOT%{_bindir}/xserver-sdk-abi-requires - -install -m 0755 %{SOURCE20} $RPM_BUILD_ROOT%{_bindir}/xvfb-run +install -D -m 0755 %{SOURCE30} %{buildroot}%{_bindir}/xserver-sdk-abi-requires +install -D -m 0755 %{SOURCE20} %{buildroot}%{_bindir}/xvfb-run # Make the source package %global xserver_source_dir %{_datadir}/xorg-x11-server-source @@ -350,10 +340,10 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete # Remove unwanted files/dirs { - find $RPM_BUILD_ROOT -type f -name '*.la' | xargs rm -f -- || : + find %{buildroot} -type f -name '*.la' | xargs rm -f -- || : # wtf %ifnarch %{ix86} x86_64 - rm -f $RPM_BUILD_ROOT%{_libdir}/xorg/modules/lib{int10,vbe}.so + rm -f %{buildroot}%{_libdir}/xorg/modules/lib{int10,vbe}.so %endif } @@ -367,13 +357,13 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %files Xorg %config %attr(0644,root,root) %{_sysconfdir}/pam.d/xserver +%{_bindir}/gtf %{_bindir}/X %{_bindir}/Xorg %{_libexecdir}/Xorg # Disable until module loading is audited # %attr(0711,root,root) %caps(cap_sys_admin,cap_sys_rawio,cap_dac_override=pe) %attr(4755, root, root) %{_libexecdir}/Xorg.wrap -%{_bindir}/gtf %dir %{_libdir}/xorg %dir %{_libdir}/xorg/modules %dir %{_libdir}/xorg/modules/drivers @@ -382,27 +372,27 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %{_libdir}/xorg/modules/extensions/libglx.so %dir %{_libdir}/xorg/modules/input %{_libdir}/xorg/modules/input/inputtest_drv.so -%{_libdir}/xorg/modules/libfbdevhw.so %{_libdir}/xorg/modules/libexa.so +%{_libdir}/xorg/modules/libfbdevhw.so #%%{_libdir}/xorg/modules/libfb.so %{_libdir}/xorg/modules/libglamoregl.so +%if !0%{?rhel} +%{_libdir}/xorg/modules/libint10.so +%endif %{_libdir}/xorg/modules/libshadow.so %{_libdir}/xorg/modules/libshadowfb.so %{_libdir}/xorg/modules/libvgahw.so %{_libdir}/xorg/modules/libwfb.so -%if !0%{?rhel} -%{_libdir}/xorg/modules/libint10.so -%endif %{_mandir}/man1/gtf.1* %{_mandir}/man1/Xorg.1* %{_mandir}/man1/Xorg.wrap.1* -%{_mandir}/man4/fbdevhw.4* %{_mandir}/man4/exa.4* -%{_mandir}/man4//inputtestdrv.4* +%{_mandir}/man4/fbdevhw.4* +%{_mandir}/man4/inputtestdrv.4* %{_mandir}/man4/modesetting.4* -%{_mandir}/man5/Xwrapper.config.5* %{_mandir}/man5/xorg.conf.5* %{_mandir}/man5/xorg.conf.d.5* +%{_mandir}/man5/Xwrapper.config.5* %dir %{_sysconfdir}/X11/xorg.conf.d %dir %{_datadir}/X11/xorg.conf.d %{_datadir}/X11/xorg.conf.d/10-quirks.conf @@ -422,7 +412,6 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %files devel %doc COPYING -#{_docdir}/xorg-server %{_bindir}/xserver-sdk-abi-requires %{_libdir}/pkgconfig/xorg-server.pc %dir %{_includedir}/xorg @@ -438,6 +427,7 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete - Switch to meson, drop no longer required patch. - Drop Obsoletes/Provides that have been removed in ~2014. - Add build depdendencies as they are searched by meson. +- Format SPEC file. * Thu Sep 26 2024 Simone Caronni - 21.1.13-2 - Drop support for building snapshots. If they need to be built, there are From 0bb198b86b42203bdb39600b6630a5be39fbba3e Mon Sep 17 00:00:00 2001 From: Simone Caronni Date: Fri, 27 Sep 2024 13:34:16 +0200 Subject: [PATCH 56/74] Adjust int10/unwind conditionals --- xorg-x11-server.spec | 23 ++++++++++++++--------- 1 file changed, 14 insertions(+), 9 deletions(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index c206d12..3ffc437 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -14,6 +14,12 @@ %global pkgname xorg-server +%ifarch %{ix86} x86_64 +%bcond int10 %[!0%{?rhel}] +%endif + +%bcond unwind %[!0%{?rhel}] + Summary: X.Org X11 X server Name: xorg-x11-server Version: 21.1.13 @@ -47,6 +53,7 @@ Patch4: 0001-ephyr-Fix-incompatible-pointer-type-build-error.patch BuildRequires: bison BuildRequires: flex +BuildRequires: gawk BuildRequires: gcc BuildRequires: kernel-headers BuildRequires: libXi-devel @@ -76,7 +83,7 @@ BuildRequires: pkgconfig(libdrm) >= 2.4.89 BuildRequires: pkgconfig(libselinux) >= 2.0.86 BuildRequires: pkgconfig(libsystemd) >= 209 BuildRequires: pkgconfig(libudev) >= 143 -%if !0%{?rhel} +%if %{with unwind} BuildRequires: pkgconfig(libunwind) %endif BuildRequires: pkgconfig(libxcvt) @@ -264,9 +271,9 @@ test `getminor extension` == %{extension_minor} -D glx=true \ -D hal=false \ -D input_thread=true \ - -D int10=%{?!rhel:auto}%{?rhel:false} \ + -D int10=%{!?with_int10:false}%{?with_int10:auto} \ -D ipv6=true \ - -D libunwind=%{?!rhel:true}%{?rhel:false} \ + -D libunwind=%{!?with_unwind:false}%{?with_unwind:true} \ -D linux_acpi=false \ -D linux_apm=false \ -D listen_local=true \ @@ -339,13 +346,11 @@ xargs tar cf - | (cd %{inst_srcdir} && tar xf -) find %{inst_srcdir}/hw/xfree86 -name \*.c -delete # Remove unwanted files/dirs -{ - find %{buildroot} -type f -name '*.la' | xargs rm -f -- || : +find %{buildroot} -type f -name '*.la' -delete # wtf -%ifnarch %{ix86} x86_64 - rm -f %{buildroot}%{_libdir}/xorg/modules/lib{int10,vbe}.so +%if %{without int10} +rm -f %{buildroot}%{_libdir}/xorg/modules/lib{int10,vbe}.so %endif -} %files common @@ -376,7 +381,7 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete %{_libdir}/xorg/modules/libfbdevhw.so #%%{_libdir}/xorg/modules/libfb.so %{_libdir}/xorg/modules/libglamoregl.so -%if !0%{?rhel} +%if %{with int10} %{_libdir}/xorg/modules/libint10.so %endif %{_libdir}/xorg/modules/libshadow.so From 51ae8aa675a59872cb22f739e0203fcda27b7b6d Mon Sep 17 00:00:00 2001 From: Simone Caronni Date: Sat, 28 Sep 2024 19:31:32 +0200 Subject: [PATCH 57/74] Remove all conditionals. Drop int10 everywhere and enable libunwind/dri3 on ELN. --- xorg-x11-server.spec | 27 ++++++++------------------- 1 file changed, 8 insertions(+), 19 deletions(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 3ffc437..9db53cb 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -14,16 +14,10 @@ %global pkgname xorg-server -%ifarch %{ix86} x86_64 -%bcond int10 %[!0%{?rhel}] -%endif - -%bcond unwind %[!0%{?rhel}] - Summary: X.Org X11 X server Name: xorg-x11-server Version: 21.1.13 -Release: 3%{?dist} +Release: 4%{?dist} URL: http://www.x.org # SPDX License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant @@ -83,9 +77,7 @@ BuildRequires: pkgconfig(libdrm) >= 2.4.89 BuildRequires: pkgconfig(libselinux) >= 2.0.86 BuildRequires: pkgconfig(libsystemd) >= 209 BuildRequires: pkgconfig(libudev) >= 143 -%if %{with unwind} BuildRequires: pkgconfig(libunwind) -%endif BuildRequires: pkgconfig(libxcvt) BuildRequires: pkgconfig(openssl) BuildRequires: pkgconfig(pciaccess) >= 0.12.901 @@ -263,7 +255,7 @@ test `getminor extension` == %{extension_minor} -D dpms=true \ -D dri1=false \ -D dri2=true \ - -D dri3=%{?!rhel:true}%{?rhel:false} \ + -D dri3=true \ -D drm=true \ -D dtrace=false \ -D fallback_input_driver=libinput \ @@ -271,9 +263,9 @@ test `getminor extension` == %{extension_minor} -D glx=true \ -D hal=false \ -D input_thread=true \ - -D int10=%{!?with_int10:false}%{?with_int10:auto} \ + -D int10=false \ -D ipv6=true \ - -D libunwind=%{!?with_unwind:false}%{?with_unwind:true} \ + -D libunwind=true \ -D linux_acpi=false \ -D linux_apm=false \ -D listen_local=true \ @@ -347,10 +339,6 @@ find %{inst_srcdir}/hw/xfree86 -name \*.c -delete # Remove unwanted files/dirs find %{buildroot} -type f -name '*.la' -delete -# wtf -%if %{without int10} -rm -f %{buildroot}%{_libdir}/xorg/modules/lib{int10,vbe}.so -%endif %files common @@ -381,9 +369,6 @@ rm -f %{buildroot}%{_libdir}/xorg/modules/lib{int10,vbe}.so %{_libdir}/xorg/modules/libfbdevhw.so #%%{_libdir}/xorg/modules/libfb.so %{_libdir}/xorg/modules/libglamoregl.so -%if %{with int10} -%{_libdir}/xorg/modules/libint10.so -%endif %{_libdir}/xorg/modules/libshadow.so %{_libdir}/xorg/modules/libshadowfb.so %{_libdir}/xorg/modules/libvgahw.so @@ -428,6 +413,10 @@ rm -f %{buildroot}%{_libdir}/xorg/modules/lib{int10,vbe}.so %changelog +* Sat Sep 28 2024 Simone Caronni - 21.1.13-4 +- Remove all conditionals. Drop int10 everywhere and enable libunwind/dri3 on + ELN. + * Fri Sep 27 2024 Simone Caronni - 21.1.13-3 - Switch to meson, drop no longer required patch. - Drop Obsoletes/Provides that have been removed in ~2014. From 083eae606156350e911d9ad663a9219a92dbe363 Mon Sep 17 00:00:00 2001 From: Simone Caronni Date: Mon, 30 Sep 2024 09:46:44 +0200 Subject: [PATCH 58/74] Obsolete vesa and fbdev drivers --- xorg-x11-server.spec | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 9db53cb..5804e84 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -17,7 +17,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 21.1.13 -Release: 4%{?dist} +Release: 5%{?dist} URL: http://www.x.org # SPDX License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant @@ -145,6 +145,10 @@ Provides: xserver-abi(extension-%{extension_major}) = %{extension_minor} # Dropped from xorg-x11-server-21.1 # https://gitlab.freedesktop.org/xorg/xserver/-/commit/b3b81c8c2090cd49410960a021baf0d27fdd2ab3 Obsoletes: xorg-x11-server-Xdmx < 1.20.15 +# Legacy fbdev devices have been replaced with simpledrm: +# https://fedoraproject.org/wiki/Changes/ReplaceFbdevDrivers +Obsoletes: xorg-x11-drv-fbdev < 0.5.0-19 +Obsoletes: xorg-x11-drv-vesa < 2.6.0-3 %description Xorg X.org X11 is an open source implementation of the X Window System. It provides @@ -413,6 +417,10 @@ find %{buildroot} -type f -name '*.la' -delete %changelog +* Mon Sep 30 2024 Simone Caronni - 21.1.13-5 +- After removal of int10/vbe, obsolete vesa and fbdev X drivers: + https://fedoraproject.org/wiki/Changes/ReplaceFbdevDrivers + * Sat Sep 28 2024 Simone Caronni - 21.1.13-4 - Remove all conditionals. Drop int10 everywhere and enable libunwind/dri3 on ELN. From db932d9182321cb6fa2896b8d9987f1b4dd187b4 Mon Sep 17 00:00:00 2001 From: Peter Robinson Date: Wed, 16 Oct 2024 10:16:17 +0100 Subject: [PATCH 59/74] Obsolete xorg-x11-drv-armsoc --- xorg-x11-server.spec | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 5804e84..72315c0 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -17,7 +17,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 21.1.13 -Release: 5%{?dist} +Release: 6%{?dist} URL: http://www.x.org # SPDX License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant @@ -149,6 +149,7 @@ Obsoletes: xorg-x11-server-Xdmx < 1.20.15 # https://fedoraproject.org/wiki/Changes/ReplaceFbdevDrivers Obsoletes: xorg-x11-drv-fbdev < 0.5.0-19 Obsoletes: xorg-x11-drv-vesa < 2.6.0-3 +Obsoletes: xorg-x11-drv-armsoc < 1.4.1-10 %description Xorg X.org X11 is an open source implementation of the X Window System. It provides @@ -417,6 +418,9 @@ find %{buildroot} -type f -name '*.la' -delete %changelog +* Wed Oct 16 2024 Peter Robinson +- Obsolete xorg-x11-drv-armsoc + * Mon Sep 30 2024 Simone Caronni - 21.1.13-5 - After removal of int10/vbe, obsolete vesa and fbdev X drivers: https://fedoraproject.org/wiki/Changes/ReplaceFbdevDrivers From d53e48508bdc6bf7812d2264fa3cfd6b4163db56 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jos=C3=A9=20Exp=C3=B3sito?= Date: Tue, 29 Oct 2024 18:18:29 +0100 Subject: [PATCH 60/74] Update to v21.1.14 --- ...ncompatible-pointer-type-build-error.patch | 54 ------------------- sources | 2 +- xorg-x11-server.spec | 10 ++-- 3 files changed, 6 insertions(+), 60 deletions(-) delete mode 100644 0001-ephyr-Fix-incompatible-pointer-type-build-error.patch diff --git a/0001-ephyr-Fix-incompatible-pointer-type-build-error.patch b/0001-ephyr-Fix-incompatible-pointer-type-build-error.patch deleted file mode 100644 index 345e660..0000000 --- a/0001-ephyr-Fix-incompatible-pointer-type-build-error.patch +++ /dev/null @@ -1,54 +0,0 @@ -From e89edec497bac581ca9b614fb00c25365580f045 Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Jos=C3=A9=20Exp=C3=B3sito?= -Date: Fri, 19 Jan 2024 13:05:51 +0100 -Subject: [PATCH] ephyr: Fix incompatible pointer type build error -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Fix a compilation error on 32 bits architectures with gcc 14: - - ephyr_glamor_xv.c: In function ‘ephyr_glamor_xv_init’: - ephyr_glamor_xv.c:154:31: error: assignment to ‘SetPortAttributeFuncPtr’ {aka ‘int (*)(struct _KdScreenInfo *, long unsigned int, int, void *)’} from incompatible pointer type ‘int (*)(KdScreenInfo *, Atom, INT32, void *)’ {aka ‘int (*)(struct _KdScreenInfo *, long unsigned int, long int, void *)’} [-Wincompatible-pointer-types] - 154 | adaptor->SetPortAttribute = ephyr_glamor_xv_set_port_attribute; - | ^ - ephyr_glamor_xv.c:155:31: error: assignment to ‘GetPortAttributeFuncPtr’ {aka ‘int (*)(struct _KdScreenInfo *, long unsigned int, int *, void *)’} from incompatible pointer type ‘int (*)(KdScreenInfo *, Atom, INT32 *, void *)’ {aka ‘int (*)(struct _KdScreenInfo *, long unsigned int, long int *, void *)’} [-Wincompatible-pointer-types] - 155 | adaptor->GetPortAttribute = ephyr_glamor_xv_get_port_attribute; - | ^ - -Build error logs: -https://koji.fedoraproject.org/koji/taskinfo?taskID=111964273 - -Signed-off-by: José Expósito ---- - hw/kdrive/ephyr/ephyr_glamor_xv.c | 8 ++++---- - 1 file changed, 4 insertions(+), 4 deletions(-) - -diff --git a/hw/kdrive/ephyr/ephyr_glamor_xv.c b/hw/kdrive/ephyr/ephyr_glamor_xv.c -index 4dd15cf41..b5eae48c8 100644 ---- a/hw/kdrive/ephyr/ephyr_glamor_xv.c -+++ b/hw/kdrive/ephyr/ephyr_glamor_xv.c -@@ -50,16 +50,16 @@ ephyr_glamor_xv_stop_video(KdScreenInfo *screen, void *data, Bool cleanup) - - static int - ephyr_glamor_xv_set_port_attribute(KdScreenInfo *screen, -- Atom attribute, INT32 value, void *data) -+ Atom attribute, int value, void *data) - { -- return glamor_xv_set_port_attribute(data, attribute, value); -+ return glamor_xv_set_port_attribute(data, attribute, (INT32)value); - } - - static int - ephyr_glamor_xv_get_port_attribute(KdScreenInfo *screen, -- Atom attribute, INT32 *value, void *data) -+ Atom attribute, int *value, void *data) - { -- return glamor_xv_get_port_attribute(data, attribute, value); -+ return glamor_xv_get_port_attribute(data, attribute, (INT32 *)value); - } - - static void --- -2.43.0 - diff --git a/sources b/sources index 475e678..7aa13d9 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (xorg-server-21.1.13.tar.xz) = a55fbeeed227c12c67f166f2c06a7f4f8d78feeea04c6e73509dbc723185fd0772349aa23f7c44cf0828ac0a0e2f9e4b26cffb220e6dfa7186d60f88b25ccaf1 +SHA512 (xorg-server-21.1.14.tar.xz) = 833d36ca4a409363dc021a50702bc29dbb32d074de319d6910a158b6e4d8f51a20c3b0de0486d9613d4e526fe4fd60ca306b3c9fcce7d014ca8cc10185afd973 diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 72315c0..aec1963 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -16,8 +16,8 @@ Summary: X.Org X11 X server Name: xorg-x11-server -Version: 21.1.13 -Release: 6%{?dist} +Version: 21.1.14 +Release: 1%{?dist} URL: http://www.x.org # SPDX License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant @@ -41,9 +41,6 @@ Patch1: 0001-xfree86-use-modesetting-driver-by-default-on-GeForce.patch Patch2: 0001-xf86-dri2-Use-va_gl-as-vdpau_driver-for-Intel-i965-G.patch # because the display-managers are not ready yet, do not upstream Patch3: 0001-Fedora-hack-Make-the-suid-root-wrapper-always-start-.patch -# Fix compilation error on i686 (21.1.14+) -# https://gitlab.freedesktop.org/xorg/xserver/-/commit/8407181c7dfe14086d99697af0b86120320ab73e -Patch4: 0001-ephyr-Fix-incompatible-pointer-type-build-error.patch BuildRequires: bison BuildRequires: flex @@ -418,6 +415,9 @@ find %{buildroot} -type f -name '*.la' -delete %changelog +* Tue Oct 29 2024 José Expósito - 21.1.14-1 +- Update to v21.1.14 + * Wed Oct 16 2024 Peter Robinson - Obsolete xorg-x11-drv-armsoc From 28edf326d982c10de016326fa90c8813841c9912 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jos=C3=A9=20Exp=C3=B3sito?= Date: Wed, 27 Nov 2024 09:52:42 +0100 Subject: [PATCH 61/74] Fix error copying Xorg.wrap Building the latest Rawhide code fails with this error: objcopy: unable to copy file '/builddir/build/BUILD/xorg-x11-server-21.1.14-build/BUILDROOT/usr/libexec/Xorg.wrap'; reason: Permission denied Upstream patch 09cd65233e0f ("xfree86: Set appropriate install_mode for suid_wrapper") changed the permissions of Xorg.wrap at install time, preventing it from being copied. Revert the patch to be able to build the X.Org server again. For reference, after reverting the upstream patch, the permissions of Xorg.wrap matches the permissions in my system: $ rpm -qlvp xorg-x11-server-Xorg-21.1.14-2.fc42.x86_64.rpm [...] -rwsr-xr-x 1 root root 16256 Nov 18 01:00 /usr/libexec/Xorg.wrap $ ll /usr/libexec/Xorg.wrap -rwsr-xr-x. 1 root root 15K Oct 29 01:00 /usr/libexec/Xorg.wrap --- ...et-appropriate-install_mode-for-suid.patch | 27 +++++++++++++++++++ xorg-x11-server.spec | 1 + 2 files changed, 28 insertions(+) create mode 100644 0001-Revert-xfree86-Set-appropriate-install_mode-for-suid.patch diff --git a/0001-Revert-xfree86-Set-appropriate-install_mode-for-suid.patch b/0001-Revert-xfree86-Set-appropriate-install_mode-for-suid.patch new file mode 100644 index 0000000..9bb86c6 --- /dev/null +++ b/0001-Revert-xfree86-Set-appropriate-install_mode-for-suid.patch @@ -0,0 +1,27 @@ +From f093f6192d4b145e76b6514634fd013bcd915e01 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Jos=C3=A9=20Exp=C3=B3sito?= +Date: Wed, 27 Nov 2024 09:33:50 +0100 +Subject: [PATCH] Revert "xfree86: Set appropriate install_mode for + suid_wrapper" + +This reverts commit 09cd65233e0f5c04e7e3d063decf357f239a65f6. +--- + hw/xfree86/meson.build | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/hw/xfree86/meson.build b/hw/xfree86/meson.build +index c4db85cdb..78c023d12 100644 +--- a/hw/xfree86/meson.build ++++ b/hw/xfree86/meson.build +@@ -152,7 +152,7 @@ if get_option('suid_wrapper') + c_args: xorg_c_args, + install: true, + install_dir: get_option('libexecdir'), +- install_mode: ['r-sr-xr-x', 0, 0], ++ # install_mode: ['r-sr-xr-x', 0, 0], + ) + + # meson gets confused when there are two targets of the same name +-- +2.47.0 + diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index aec1963..3f4b98e 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -41,6 +41,7 @@ Patch1: 0001-xfree86-use-modesetting-driver-by-default-on-GeForce.patch Patch2: 0001-xf86-dri2-Use-va_gl-as-vdpau_driver-for-Intel-i965-G.patch # because the display-managers are not ready yet, do not upstream Patch3: 0001-Fedora-hack-Make-the-suid-root-wrapper-always-start-.patch +Patch4: 0001-Revert-xfree86-Set-appropriate-install_mode-for-suid.patch BuildRequires: bison BuildRequires: flex From 6b1c1806e3e1aa3138d07fef07dea709842d162d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jos=C3=A9=20Exp=C3=B3sito?= Date: Wed, 27 Nov 2024 09:53:39 +0100 Subject: [PATCH 62/74] Restore quirks for Apple silicon Fixes: 422064e45a42 ("Update X11-server to 21.1.13 and ABI numbers of videodrv and xinput") Resolves: https://bugzilla.redhat.com/show_bug.cgi?id=2152414 --- 0001-add-a-quirk-for-apple-silicon.patch | 30 ++++++++++++++++++++++++ xorg-x11-server.spec | 10 +++++++- 2 files changed, 39 insertions(+), 1 deletion(-) create mode 100644 0001-add-a-quirk-for-apple-silicon.patch diff --git a/0001-add-a-quirk-for-apple-silicon.patch b/0001-add-a-quirk-for-apple-silicon.patch new file mode 100644 index 0000000..17c40e5 --- /dev/null +++ b/0001-add-a-quirk-for-apple-silicon.patch @@ -0,0 +1,30 @@ +commit 39934a656a44722d16a80bf4db411c53e2d67b38 (HEAD -> master, origin/master, origin/HEAD) +Author: Eric Curtin +Date: Fri Dec 16 11:10:12 2022 +0000 + + config: add a quirk for Apple Silicon appledrm + + Xorg server does not correctly select the DCP for the display without a + quirk on Apple Silicon. + + Signed-off-by: Eric Curtin + Suggested-by: Hector Martin + +diff --git a/config/10-quirks.conf b/config/10-quirks.conf +index 47907d82d..54dd908a7 100644 +--- a/config/10-quirks.conf ++++ b/config/10-quirks.conf +@@ -36,3 +36,13 @@ Section "InputClass" + MatchDriver "evdev" + Option "TypeName" "MOUSE" + EndSection ++ ++# https://bugzilla.redhat.com/show_bug.cgi?id=2152414 ++# Xorg server does not correctly select the DCP for the display without ++# a quirk on Apple Silicon ++Section "OutputClass" ++ Identifier "appledrm" ++ MatchDriver "apple" ++ Driver "modesetting" ++ Option "PrimaryGPU" "true" ++EndSection diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 3f4b98e..077f6ad 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -17,7 +17,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 21.1.14 -Release: 1%{?dist} +Release: 2%{?dist} URL: http://www.x.org # SPDX License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant @@ -42,6 +42,8 @@ Patch2: 0001-xf86-dri2-Use-va_gl-as-vdpau_driver-for-Intel-i965-G.patch # because the display-managers are not ready yet, do not upstream Patch3: 0001-Fedora-hack-Make-the-suid-root-wrapper-always-start-.patch Patch4: 0001-Revert-xfree86-Set-appropriate-install_mode-for-suid.patch +# https://bugzilla.redhat.com/show_bug.cgi?id=2326701 +Patch5: 0001-add-a-quirk-for-apple-silicon.patch BuildRequires: bison BuildRequires: flex @@ -416,6 +418,12 @@ find %{buildroot} -type f -name '*.la' -delete %changelog +* Mon Nov 18 2024 José Expósito - 21.1.14-2 +- Fix build issues caused by Xorg.wrap +- Restore quirks for Apple silicon + Fixes: 422064e45a42 ("Update X11-server to 21.1.13 and ABI numbers of videodrv and xinput") + Resolves: https://bugzilla.redhat.com/show_bug.cgi?id=2326701 + * Tue Oct 29 2024 José Expósito - 21.1.14-1 - Update to v21.1.14 From cb5f4ca65c1249426c7a6b1a50f5db6003aa2de6 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?S=C3=A9rgio=20M=2E=20Basto?= Date: Fri, 29 Nov 2024 00:07:55 +0000 Subject: [PATCH 63/74] Revert commit "Fix error copying Xorg.wrap", debugedit-5.1-2 have the real fix --- ...et-appropriate-install_mode-for-suid.patch | 27 ------------------- xorg-x11-server.spec | 6 +++-- 2 files changed, 4 insertions(+), 29 deletions(-) delete mode 100644 0001-Revert-xfree86-Set-appropriate-install_mode-for-suid.patch diff --git a/0001-Revert-xfree86-Set-appropriate-install_mode-for-suid.patch b/0001-Revert-xfree86-Set-appropriate-install_mode-for-suid.patch deleted file mode 100644 index 9bb86c6..0000000 --- a/0001-Revert-xfree86-Set-appropriate-install_mode-for-suid.patch +++ /dev/null @@ -1,27 +0,0 @@ -From f093f6192d4b145e76b6514634fd013bcd915e01 Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Jos=C3=A9=20Exp=C3=B3sito?= -Date: Wed, 27 Nov 2024 09:33:50 +0100 -Subject: [PATCH] Revert "xfree86: Set appropriate install_mode for - suid_wrapper" - -This reverts commit 09cd65233e0f5c04e7e3d063decf357f239a65f6. ---- - hw/xfree86/meson.build | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/hw/xfree86/meson.build b/hw/xfree86/meson.build -index c4db85cdb..78c023d12 100644 ---- a/hw/xfree86/meson.build -+++ b/hw/xfree86/meson.build -@@ -152,7 +152,7 @@ if get_option('suid_wrapper') - c_args: xorg_c_args, - install: true, - install_dir: get_option('libexecdir'), -- install_mode: ['r-sr-xr-x', 0, 0], -+ # install_mode: ['r-sr-xr-x', 0, 0], - ) - - # meson gets confused when there are two targets of the same name --- -2.47.0 - diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 077f6ad..5bc1630 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -17,7 +17,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 21.1.14 -Release: 2%{?dist} +Release: 3%{?dist} URL: http://www.x.org # SPDX License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant @@ -41,7 +41,6 @@ Patch1: 0001-xfree86-use-modesetting-driver-by-default-on-GeForce.patch Patch2: 0001-xf86-dri2-Use-va_gl-as-vdpau_driver-for-Intel-i965-G.patch # because the display-managers are not ready yet, do not upstream Patch3: 0001-Fedora-hack-Make-the-suid-root-wrapper-always-start-.patch -Patch4: 0001-Revert-xfree86-Set-appropriate-install_mode-for-suid.patch # https://bugzilla.redhat.com/show_bug.cgi?id=2326701 Patch5: 0001-add-a-quirk-for-apple-silicon.patch @@ -418,6 +417,9 @@ find %{buildroot} -type f -name '*.la' -delete %changelog +* Fri Nov 29 2024 Sérgio Basto - 21.1.14-3 +- Revert commit "Fix error copying Xorg.wrap", debugedit-5.1-2 have the real fix + * Mon Nov 18 2024 José Expósito - 21.1.14-2 - Fix build issues caused by Xorg.wrap - Restore quirks for Apple silicon From e3a0a54473c7d63df39467bdf0b093fedb25a962 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jos=C3=A9=20Exp=C3=B3sito?= Date: Fri, 20 Dec 2024 08:50:05 +0100 Subject: [PATCH 64/74] Update to v21.1.15 Resolves: https://bugzilla.redhat.com/show_bug.cgi?id=2332880 --- 0001-add-a-quirk-for-apple-silicon.patch | 30 ------------------------ sources | 2 +- xorg-x11-server.spec | 9 +++---- 3 files changed, 6 insertions(+), 35 deletions(-) delete mode 100644 0001-add-a-quirk-for-apple-silicon.patch diff --git a/0001-add-a-quirk-for-apple-silicon.patch b/0001-add-a-quirk-for-apple-silicon.patch deleted file mode 100644 index 17c40e5..0000000 --- a/0001-add-a-quirk-for-apple-silicon.patch +++ /dev/null @@ -1,30 +0,0 @@ -commit 39934a656a44722d16a80bf4db411c53e2d67b38 (HEAD -> master, origin/master, origin/HEAD) -Author: Eric Curtin -Date: Fri Dec 16 11:10:12 2022 +0000 - - config: add a quirk for Apple Silicon appledrm - - Xorg server does not correctly select the DCP for the display without a - quirk on Apple Silicon. - - Signed-off-by: Eric Curtin - Suggested-by: Hector Martin - -diff --git a/config/10-quirks.conf b/config/10-quirks.conf -index 47907d82d..54dd908a7 100644 ---- a/config/10-quirks.conf -+++ b/config/10-quirks.conf -@@ -36,3 +36,13 @@ Section "InputClass" - MatchDriver "evdev" - Option "TypeName" "MOUSE" - EndSection -+ -+# https://bugzilla.redhat.com/show_bug.cgi?id=2152414 -+# Xorg server does not correctly select the DCP for the display without -+# a quirk on Apple Silicon -+Section "OutputClass" -+ Identifier "appledrm" -+ MatchDriver "apple" -+ Driver "modesetting" -+ Option "PrimaryGPU" "true" -+EndSection diff --git a/sources b/sources index 7aa13d9..0ba10a5 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (xorg-server-21.1.14.tar.xz) = 833d36ca4a409363dc021a50702bc29dbb32d074de319d6910a158b6e4d8f51a20c3b0de0486d9613d4e526fe4fd60ca306b3c9fcce7d014ca8cc10185afd973 +SHA512 (xorg-server-21.1.15.tar.xz) = 677bbec81ecdd1d14e1d289a00c40249988985ec636e5473b30c4f63bad03a6cc5f9168cea94969e1550370eee8863595bc9c064c3d218a96123afc7567bf363 diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 5bc1630..7b79c3b 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -16,8 +16,8 @@ Summary: X.Org X11 X server Name: xorg-x11-server -Version: 21.1.14 -Release: 3%{?dist} +Version: 21.1.15 +Release: 1%{?dist} URL: http://www.x.org # SPDX License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant @@ -41,8 +41,6 @@ Patch1: 0001-xfree86-use-modesetting-driver-by-default-on-GeForce.patch Patch2: 0001-xf86-dri2-Use-va_gl-as-vdpau_driver-for-Intel-i965-G.patch # because the display-managers are not ready yet, do not upstream Patch3: 0001-Fedora-hack-Make-the-suid-root-wrapper-always-start-.patch -# https://bugzilla.redhat.com/show_bug.cgi?id=2326701 -Patch5: 0001-add-a-quirk-for-apple-silicon.patch BuildRequires: bison BuildRequires: flex @@ -417,6 +415,9 @@ find %{buildroot} -type f -name '*.la' -delete %changelog +* Fri Dec 20 2024 José Expósito - 21.1.15-1 +- Update to v21.1.15 + * Fri Nov 29 2024 Sérgio Basto - 21.1.14-3 - Revert commit "Fix error copying Xorg.wrap", debugedit-5.1-2 have the real fix From 928204fc3981ab85b5b81932001c2efeca6d68c0 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?S=C3=A9rgio=20M=2E=20Basto?= Date: Tue, 31 Dec 2024 17:57:55 +0000 Subject: [PATCH 65/74] Remove this unused patch which have characters that flagged by the automatic scanning tools. This pach is already in upstream code, as this patch have characters that are flagged by the automatic scanning tools, it was remove from previous commits to avoid delays. Now that we already rebase xorg-x11-server to 21.x and shipped in F41, we can complete the cleanup --- ...artz-Remove-invalid-Unicode-sequence.patch | 30 ------------------- 1 file changed, 30 deletions(-) delete mode 100644 0001-xquartz-Remove-invalid-Unicode-sequence.patch diff --git a/0001-xquartz-Remove-invalid-Unicode-sequence.patch b/0001-xquartz-Remove-invalid-Unicode-sequence.patch deleted file mode 100644 index 926849e..0000000 --- a/0001-xquartz-Remove-invalid-Unicode-sequence.patch +++ /dev/null @@ -1,30 +0,0 @@ -From a7ba1e9fe41019296a0f3ddff3d681f77e041ad7 Mon Sep 17 00:00:00 2001 -From: Olivier Fourdan -Date: Tue, 7 May 2024 18:04:02 +0200 -Subject: [PATCH] xquartz: Remove invalid Unicode sequence - -This is flagged by the automatic scanning tools. - -Signed-off-by: Olivier Fourdan -Closes: https://gitlab.freedesktop.org/xorg/xserver/-/issues/1673 -Part-of: ---- - hw/xquartz/bundle/Resources/he.lproj/main.nib/designable.nib | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/hw/xquartz/bundle/Resources/he.lproj/main.nib/designable.nib b/hw/xquartz/bundle/Resources/he.lproj/main.nib/designable.nib -index e56c1adbc..42042a18d 100644 ---- a/hw/xquartz/bundle/Resources/he.lproj/main.nib/designable.nib -+++ b/hw/xquartz/bundle/Resources/he.lproj/main.nib/designable.nib -@@ -438,7 +438,7 @@ - - - -- -+ - - - --- -2.45.0 - From 3e4c792ded00f648fa6962c854aeb548c2db7ec7 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sun, 19 Jan 2025 16:10:32 +0000 Subject: [PATCH 66/74] Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild --- xorg-x11-server.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 7b79c3b..8001dbb 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -17,7 +17,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 21.1.15 -Release: 1%{?dist} +Release: 2%{?dist} URL: http://www.x.org # SPDX License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant @@ -415,6 +415,9 @@ find %{buildroot} -type f -name '*.la' -delete %changelog +* Sun Jan 19 2025 Fedora Release Engineering - 21.1.15-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild + * Fri Dec 20 2024 José Expósito - 21.1.15-1 - Update to v21.1.15 From 572824c02838f507eae74def293150579d64e5db Mon Sep 17 00:00:00 2001 From: Olivier Fourdan Date: Tue, 25 Feb 2025 10:51:32 +0100 Subject: [PATCH 67/74] Fix DRI2 failure Resolves: #2347345 --- ...inst-dri2ClientPrivate-assertion-fai.patch | 67 +++++++++++++++++++ xorg-x11-server.spec | 8 +++ 2 files changed, 75 insertions(+) create mode 100644 0001-dri2-Protect-against-dri2ClientPrivate-assertion-fai.patch diff --git a/0001-dri2-Protect-against-dri2ClientPrivate-assertion-fai.patch b/0001-dri2-Protect-against-dri2ClientPrivate-assertion-fai.patch new file mode 100644 index 0000000..0c3a7bb --- /dev/null +++ b/0001-dri2-Protect-against-dri2ClientPrivate-assertion-fai.patch @@ -0,0 +1,67 @@ +From e71d86dafbca036f32455caa25c2733c069a5010 Mon Sep 17 00:00:00 2001 +From: Doug Brown +Date: Mon, 15 Jul 2024 19:44:23 -0700 +Subject: [PATCH xserver] dri2: Protect against dri2ClientPrivate assertion + failures +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +If DRI2ScreenInit hasn't been called yet, DRI2Authenticate and +DRI2CreateDrawable2 cause the X server to crash. This has been observed +to happen on multiple modern Linux distros in various conditions, +including QEMU and VMware VMs. Make these functions more robust in order +to prevent the crash. + +This patch was originally provided by Bernhard Übelacker and expanded +upon by Mark Wagner. + +Signed-off-by: Doug Brown +Closes: https://gitlab.freedesktop.org/xorg/xserver/-/issues/1053 +Closes: https://gitlab.freedesktop.org/xorg/xserver/-/issues/1534 +Part-of: +(cherry picked from commit a0834009cfb10b8982a1f2b47b8ed00de254c2c3) +--- + hw/xfree86/dri2/dri2.c | 14 ++++++++++++-- + 1 file changed, 12 insertions(+), 2 deletions(-) + +diff --git a/hw/xfree86/dri2/dri2.c b/hw/xfree86/dri2/dri2.c +index 3397bb50c..3975d40ca 100644 +--- a/hw/xfree86/dri2/dri2.c ++++ b/hw/xfree86/dri2/dri2.c +@@ -356,10 +356,15 @@ DRI2CreateDrawable2(ClientPtr client, DrawablePtr pDraw, XID id, + XID *dri2_id_out) + { + DRI2DrawablePtr pPriv; +- DRI2ClientPtr dri2_client = dri2ClientPrivate(client); ++ DRI2ClientPtr dri2_client; + XID dri2_id; + int rc; + ++ if (!dixPrivateKeyRegistered(dri2ScreenPrivateKey)) ++ return BadValue; ++ ++ dri2_client = dri2ClientPrivate(client); ++ + pPriv = DRI2GetDrawable(pDraw); + if (pPriv == NULL) + pPriv = DRI2AllocateDrawable(pDraw); +@@ -1362,9 +1367,14 @@ Bool + DRI2Authenticate(ClientPtr client, ScreenPtr pScreen, uint32_t magic) + { + DRI2ScreenPtr ds; +- DRI2ClientPtr dri2_client = dri2ClientPrivate(client); ++ DRI2ClientPtr dri2_client; + ScreenPtr primescreen; + ++ if (!dixPrivateKeyRegistered(dri2ScreenPrivateKey)) ++ return FALSE; ++ ++ dri2_client = dri2ClientPrivate(client); ++ + ds = DRI2GetScreenPrime(pScreen, dri2_client->prime_id); + if (ds == NULL) + return FALSE; +-- +2.48.1 + diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 8001dbb..c8178bb 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -42,6 +42,11 @@ Patch2: 0001-xf86-dri2-Use-va_gl-as-vdpau_driver-for-Intel-i965-G.patch # because the display-managers are not ready yet, do not upstream Patch3: 0001-Fedora-hack-Make-the-suid-root-wrapper-always-start-.patch +# https://bugzilla.redhat.com/show_bug.cgi?id=2347345 +# https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/1608 +# https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/1824 +Patch4: 0001-dri2-Protect-against-dri2ClientPrivate-assertion-fai.patch + BuildRequires: bison BuildRequires: flex BuildRequires: gawk @@ -415,6 +420,9 @@ find %{buildroot} -type f -name '*.la' -delete %changelog +* Tue Feb 25 2025 Olivier Fourdan - 21.1.15-3 +- Fix DRI2 failure (#2347345) + * Sun Jan 19 2025 Fedora Release Engineering - 21.1.15-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild From dd5395436b87a535ea27a644b004feeea949a4a1 Mon Sep 17 00:00:00 2001 From: Olivier Fourdan Date: Wed, 26 Feb 2025 09:24:14 +0100 Subject: [PATCH 68/74] Update to v21.1.16 CVE fix for: CVE-2025-26594, CVE-2025-26595, CVE-2025-26596, CVE-2025-26597, CVE-2025-26598, CVE-2025-26599, CVE-2025-26600, CVE-2025-26601 Resolves: #2347558 --- ...inst-dri2ClientPrivate-assertion-fai.patch | 67 ------------------- sources | 2 +- xorg-x11-server.spec | 16 ++--- 3 files changed, 9 insertions(+), 76 deletions(-) delete mode 100644 0001-dri2-Protect-against-dri2ClientPrivate-assertion-fai.patch diff --git a/0001-dri2-Protect-against-dri2ClientPrivate-assertion-fai.patch b/0001-dri2-Protect-against-dri2ClientPrivate-assertion-fai.patch deleted file mode 100644 index 0c3a7bb..0000000 --- a/0001-dri2-Protect-against-dri2ClientPrivate-assertion-fai.patch +++ /dev/null @@ -1,67 +0,0 @@ -From e71d86dafbca036f32455caa25c2733c069a5010 Mon Sep 17 00:00:00 2001 -From: Doug Brown -Date: Mon, 15 Jul 2024 19:44:23 -0700 -Subject: [PATCH xserver] dri2: Protect against dri2ClientPrivate assertion - failures -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -If DRI2ScreenInit hasn't been called yet, DRI2Authenticate and -DRI2CreateDrawable2 cause the X server to crash. This has been observed -to happen on multiple modern Linux distros in various conditions, -including QEMU and VMware VMs. Make these functions more robust in order -to prevent the crash. - -This patch was originally provided by Bernhard Übelacker and expanded -upon by Mark Wagner. - -Signed-off-by: Doug Brown -Closes: https://gitlab.freedesktop.org/xorg/xserver/-/issues/1053 -Closes: https://gitlab.freedesktop.org/xorg/xserver/-/issues/1534 -Part-of: -(cherry picked from commit a0834009cfb10b8982a1f2b47b8ed00de254c2c3) ---- - hw/xfree86/dri2/dri2.c | 14 ++++++++++++-- - 1 file changed, 12 insertions(+), 2 deletions(-) - -diff --git a/hw/xfree86/dri2/dri2.c b/hw/xfree86/dri2/dri2.c -index 3397bb50c..3975d40ca 100644 ---- a/hw/xfree86/dri2/dri2.c -+++ b/hw/xfree86/dri2/dri2.c -@@ -356,10 +356,15 @@ DRI2CreateDrawable2(ClientPtr client, DrawablePtr pDraw, XID id, - XID *dri2_id_out) - { - DRI2DrawablePtr pPriv; -- DRI2ClientPtr dri2_client = dri2ClientPrivate(client); -+ DRI2ClientPtr dri2_client; - XID dri2_id; - int rc; - -+ if (!dixPrivateKeyRegistered(dri2ScreenPrivateKey)) -+ return BadValue; -+ -+ dri2_client = dri2ClientPrivate(client); -+ - pPriv = DRI2GetDrawable(pDraw); - if (pPriv == NULL) - pPriv = DRI2AllocateDrawable(pDraw); -@@ -1362,9 +1367,14 @@ Bool - DRI2Authenticate(ClientPtr client, ScreenPtr pScreen, uint32_t magic) - { - DRI2ScreenPtr ds; -- DRI2ClientPtr dri2_client = dri2ClientPrivate(client); -+ DRI2ClientPtr dri2_client; - ScreenPtr primescreen; - -+ if (!dixPrivateKeyRegistered(dri2ScreenPrivateKey)) -+ return FALSE; -+ -+ dri2_client = dri2ClientPrivate(client); -+ - ds = DRI2GetScreenPrime(pScreen, dri2_client->prime_id); - if (ds == NULL) - return FALSE; --- -2.48.1 - diff --git a/sources b/sources index 0ba10a5..c71afbe 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (xorg-server-21.1.15.tar.xz) = 677bbec81ecdd1d14e1d289a00c40249988985ec636e5473b30c4f63bad03a6cc5f9168cea94969e1550370eee8863595bc9c064c3d218a96123afc7567bf363 +SHA512 (xorg-server-21.1.16.tar.xz) = 38fd4232a293a497d13f8b57e85e84cf6a531453a7d8d5de1a77d67ceaf8714d5770951a8a21f1b3f519e83be1fc0926dce269846e75a8b11aa1062dd507f67d diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index c8178bb..ff890cc 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -16,8 +16,8 @@ Summary: X.Org X11 X server Name: xorg-x11-server -Version: 21.1.15 -Release: 2%{?dist} +Version: 21.1.16 +Release: 1%{?dist} URL: http://www.x.org # SPDX License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant @@ -42,11 +42,6 @@ Patch2: 0001-xf86-dri2-Use-va_gl-as-vdpau_driver-for-Intel-i965-G.patch # because the display-managers are not ready yet, do not upstream Patch3: 0001-Fedora-hack-Make-the-suid-root-wrapper-always-start-.patch -# https://bugzilla.redhat.com/show_bug.cgi?id=2347345 -# https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/1608 -# https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/1824 -Patch4: 0001-dri2-Protect-against-dri2ClientPrivate-assertion-fai.patch - BuildRequires: bison BuildRequires: flex BuildRequires: gawk @@ -420,7 +415,12 @@ find %{buildroot} -type f -name '*.la' -delete %changelog -* Tue Feb 25 2025 Olivier Fourdan - 21.1.15-3 +* Wed Feb 26 2025 Olivier Fourdan - 21.1.16-1 +- Update to xserver 21.1.16 (#2347558) +- CVE fix for: CVE-2025-26594, CVE-2025-26595, CVE-2025-26596, CVE-2025-26597, + CVE-2025-26598, CVE-2025-26599, CVE-2025-26600, CVE-2025-26601 + +* Tue Feb 25 2025 Olivier Fourdan - 21.1.15-3 - Fix DRI2 failure (#2347345) * Sun Jan 19 2025 Fedora Release Engineering - 21.1.15-2 From 5b50181e4f38bdff8a253c05106f790f5f34f1e3 Mon Sep 17 00:00:00 2001 From: Olivier Fourdan Date: Tue, 17 Jun 2025 16:41:21 +0200 Subject: [PATCH 69/74] Update to v21.1.17 CVE fix for: CVE-2025-49175, CVE-2025-49176, CVE-2025-49177, CVE-2025-49178, CVE-2025-49179, CVE-2025-49180 --- sources | 2 +- xorg-x11-server.spec | 7 ++++++- 2 files changed, 7 insertions(+), 2 deletions(-) diff --git a/sources b/sources index c71afbe..6a837c5 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (xorg-server-21.1.16.tar.xz) = 38fd4232a293a497d13f8b57e85e84cf6a531453a7d8d5de1a77d67ceaf8714d5770951a8a21f1b3f519e83be1fc0926dce269846e75a8b11aa1062dd507f67d +SHA512 (xorg-server-21.1.17.tar.xz) = 6f301c532b2ad6edfab76f21f8e88c4bd9d7df88c12e52caaed72a2c2084547c323fd29ff8769fe0c1cb230b483d4620bc3f382df80899c6b58d3c12431d62d0 diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index ff890cc..75eb82c 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -16,7 +16,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server -Version: 21.1.16 +Version: 21.1.17 Release: 1%{?dist} URL: http://www.x.org # SPDX @@ -415,6 +415,11 @@ find %{buildroot} -type f -name '*.la' -delete %changelog +* Tue Jun 17 2025 Olivier Fourdan - 21.1.17-1 +- Update to xserver 21.1.17 +- CVE fix for: CVE-2025-49175, CVE-2025-49176, CVE-2025-49177 + CVE-2025-49178, CVE-2025-49179, CVE-2025-49180 + * Wed Feb 26 2025 Olivier Fourdan - 21.1.16-1 - Update to xserver 21.1.16 (#2347558) - CVE fix for: CVE-2025-26594, CVE-2025-26595, CVE-2025-26596, CVE-2025-26597, From 5d7ed4931eb5a7d2c3832549ad66d663f872e46d Mon Sep 17 00:00:00 2001 From: Olivier Fourdan Date: Wed, 18 Jun 2025 19:10:33 +0200 Subject: [PATCH 70/74] Update to v21.1.18 Contains an additional fix for CVE-2025-49176 --- sources | 2 +- xorg-x11-server.spec | 6 +++++- 2 files changed, 6 insertions(+), 2 deletions(-) diff --git a/sources b/sources index 6a837c5..fc2e23f 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (xorg-server-21.1.17.tar.xz) = 6f301c532b2ad6edfab76f21f8e88c4bd9d7df88c12e52caaed72a2c2084547c323fd29ff8769fe0c1cb230b483d4620bc3f382df80899c6b58d3c12431d62d0 +SHA512 (xorg-server-21.1.18.tar.xz) = 839ce759fc0e5405599c4cff0acf381f278d22b465b9fb9e335b5fd1c63f6d546788e4e869854026eb4b1e1a77a83b60d6fef472cf8534d45630f31b587a50dd diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 75eb82c..8924b56 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -16,7 +16,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server -Version: 21.1.17 +Version: 21.1.18 Release: 1%{?dist} URL: http://www.x.org # SPDX @@ -415,6 +415,10 @@ find %{buildroot} -type f -name '*.la' -delete %changelog +* Wed Jun 18 2025 Olivier Fourdan - 21.1.18-1 +- Update to xserver 21.1.18 +- Contains an additional fix for CVE-2025-49176 + * Tue Jun 17 2025 Olivier Fourdan - 21.1.17-1 - Update to xserver 21.1.17 - CVE fix for: CVE-2025-49175, CVE-2025-49176, CVE-2025-49177 From 96c4fa6fb3a467bccfbb84fc9ef52893285edd53 Mon Sep 17 00:00:00 2001 From: Peter Hutterer Date: Wed, 9 Jul 2025 08:21:37 +1000 Subject: [PATCH 71/74] Update Xvfb SPDX license identifier --- xorg-x11-server.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 8924b56..9cf48dd 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -169,7 +169,7 @@ wish to test their applications without running them on their real X server. %package Xvfb Summary: A X Windows System virtual framebuffer X server # xvfb-run is GPLv2, rest is MIT -License: MIT and GPLv2 +License: MIT and GPL-2.0-only Requires: xorg-x11-server-common >= %{version}-%{release} # required for xvfb-run Requires: xorg-x11-xauth @@ -415,6 +415,9 @@ find %{buildroot} -type f -name '*.la' -delete %changelog +* Wed Jul 09 2025 Peter Hutterer +- Update Xvfb SPDX license identifier + * Wed Jun 18 2025 Olivier Fourdan - 21.1.18-1 - Update to xserver 21.1.18 - Contains an additional fix for CVE-2025-49176 From ab69deda47e577d79cfeb6bfd8be40d4d53650cd Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 25 Jul 2025 21:00:45 +0000 Subject: [PATCH 72/74] Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild --- xorg-x11-server.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 9cf48dd..ff50dbf 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -17,7 +17,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server Version: 21.1.18 -Release: 1%{?dist} +Release: 2%{?dist} URL: http://www.x.org # SPDX License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant @@ -415,6 +415,9 @@ find %{buildroot} -type f -name '*.la' -delete %changelog +* Fri Jul 25 2025 Fedora Release Engineering - 21.1.18-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild + * Wed Jul 09 2025 Peter Hutterer - Update Xvfb SPDX license identifier From 115bb19734421bf8443a8499614f87c38e092fb1 Mon Sep 17 00:00:00 2001 From: Olivier Fourdan Date: Tue, 28 Oct 2025 18:28:57 +0100 Subject: [PATCH 73/74] Update to v21.1.20 CVE fix for: CVE-2025-62229, CVE-2025-62230, CVE-2025-62231 Resolves: #2406803 --- sources | 2 +- xorg-x11-server.spec | 8 ++++++-- 2 files changed, 7 insertions(+), 3 deletions(-) diff --git a/sources b/sources index fc2e23f..fa87b01 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (xorg-server-21.1.18.tar.xz) = 839ce759fc0e5405599c4cff0acf381f278d22b465b9fb9e335b5fd1c63f6d546788e4e869854026eb4b1e1a77a83b60d6fef472cf8534d45630f31b587a50dd +SHA512 (xorg-server-21.1.20.tar.xz) = cb83cfaaa804b39d4c6d827222439c7725ee2c6fe738d5f5ac9a406c3978ef3d7fafe9ba9fda54ba93fb37447f88edbc1e48656d5771b204945c6d67d1233f80 diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index ff50dbf..3070d65 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -16,8 +16,8 @@ Summary: X.Org X11 X server Name: xorg-x11-server -Version: 21.1.18 -Release: 2%{?dist} +Version: 21.1.20 +Release: 1%{?dist} URL: http://www.x.org # SPDX License: Adobe-Display-PostScript AND BSD-3-Clause AND DEC-3-Clause AND HPND AND HPND-sell-MIT-disclaimer-xserver AND HPND-sell-variant AND ICU AND ISC AND MIT AND MIT-open-group AND NTP AND SGI-B-2.0 AND SMLNJ AND X11 AND X11-distribute-modifications-variant @@ -415,6 +415,10 @@ find %{buildroot} -type f -name '*.la' -delete %changelog +* Tue Oct 28 2025 Olivier Fourdan - 21.1.20-1 +- Update to xserver 21.1.20 (#2406803) +- CVE fix for: CVE-2025-62229, CVE-2025-62230, CVE-2025-62231 + * Fri Jul 25 2025 Fedora Release Engineering - 21.1.18-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild From e356a592b71be6324de0c655adc8e69bfb1b4c67 Mon Sep 17 00:00:00 2001 From: Olivier Fourdan Date: Tue, 25 Nov 2025 14:06:02 +0100 Subject: [PATCH 74/74] Update to v21.1.21 Resolves: #2417000 --- sources | 2 +- xorg-x11-server.spec | 5 ++++- 2 files changed, 5 insertions(+), 2 deletions(-) diff --git a/sources b/sources index fa87b01..888c6f9 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (xorg-server-21.1.20.tar.xz) = cb83cfaaa804b39d4c6d827222439c7725ee2c6fe738d5f5ac9a406c3978ef3d7fafe9ba9fda54ba93fb37447f88edbc1e48656d5771b204945c6d67d1233f80 +SHA512 (xorg-server-21.1.21.tar.xz) = bb2eb4e6756eb9e38b61bd47c017da44bcf5f45f2b7a906b4bb3a56b3d791cec64abb9bf37b224efe1e4fab9cc296f3672c9b2f8e00e1cdfc54337bef63cd16c diff --git a/xorg-x11-server.spec b/xorg-x11-server.spec index 3070d65..788acf9 100644 --- a/xorg-x11-server.spec +++ b/xorg-x11-server.spec @@ -16,7 +16,7 @@ Summary: X.Org X11 X server Name: xorg-x11-server -Version: 21.1.20 +Version: 21.1.21 Release: 1%{?dist} URL: http://www.x.org # SPDX @@ -415,6 +415,9 @@ find %{buildroot} -type f -name '*.la' -delete %changelog +* Tue Nov 25 2025 Olivier Fourdan - 21.1.21-1 +- Update to xserver 21.1.21 (#2417000) + * Tue Oct 28 2025 Olivier Fourdan - 21.1.20-1 - Update to xserver 21.1.20 (#2406803) - CVE fix for: CVE-2025-62229, CVE-2025-62230, CVE-2025-62231