Skip to content

(release/25.1) xnest: Check malloc return values in GCOps to avoid NULL dereferences - #3666

Open
metux wants to merge 4 commits into
release/25.1from
pr/release/25.1-xnest-check-malloc-return-values-in-gcops-to-avoid-null-dereferences_2026-08-31_15-05-17
Open

metux wants to merge 4 commits into
release/25.1from
pr/release/25.1-xnest-check-malloc-return-values-in-gcops-to-avoid-null-dereferences_2026-08-31_15-05-17

Conversation

@metux

@metux metux commented Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

malloc() require check on valid ptr

Check malloc() return values for NULL in xnestBitBlitHelper(), xnestPolyText8(), and
xnestPolyText16() to prevent potential NULL pointer dereferences.

Backport of #3637 (based on its current head commit
eae9444; original PR not merged yet)

(cherry picked from commit eae9444)

@metux

metux commented Aug 31, 2026

Copy link
Copy Markdown
Contributor Author

🤖 Automated review — generated by Starfleet ship Voyager on behalf of @metux. Not a human review.

Reviewed hw/xnest/GCOps.c — the release backport of #3637.

Verdict: PASS

Identical +12/−2 cherry-pick of the master fix on 25.2/25.1/25.0 (same path, no reorg),
applied cleanly on each branch. All three malloc NULL-checks (xnestBitBlitHelper q,
xnestPolyText8/xnestPolyText16 buffer) are correct defensive hardening with no behavioral
change on the malloc-success path; the free(event) in the failure branch also prevents an event
leak, and the added break; is a no-op (last case).

No ABI impact (nested software DDX, no external driver/nvidia surface). Pure defensive
malloc-failure hardening — not a client-triggerable security issue or reachable crash; not a
mandatory backport (opened on maintainer request).

No blocking findings.

@metux metux added the bot-review-passed Automated bot review found no blocking issues label Aug 31, 2026
When building the xserver SDK on Linux (e.g. GitHub Actions Ubuntu runners),
the BSD console macros (CONFIG_BSD_CONSOLE, CSRG_BASED, PCVT_SUPPORT,
SYSCONS_SUPPORT, WSCONS_SUPPORT) were not defined because they were gated
on host_machine.system(). This caused driver builds (e.g. xf86-input-keyboard)
to fail when building against the SDK, as they reference xf86Info.consType
and the PCCONS/SYSCONS/PCVT/WSCONS constants.

Fix by defining these macros unconditionally in conf_data and xorg_data when
build_xorg_sdk is true, so the installed SDK headers contain them regardless
of the build platform. For non-SDK builds, keep the platform-appropriate
conditional values.

Also add CONFIG_BSD_CONSOLE to the xlibre-server.h template.

Signed-off-by: Enrico Weigelt, metux IT consult <info@metux.net>
@metux
metux force-pushed the pr/release/25.1-xnest-check-malloc-return-values-in-gcops-to-avoid-null-dereferences_2026-08-31_15-05-17 branch from 6b0e139 to 7c6acea Compare September 14, 2026 13:14
metux and others added 3 commits September 18, 2026 15:54
The Cygwin meson runtime resolves to /usr/bin/python3.12.exe (python312 is
pulled in transitively as a meson dependency), while the workflow only
installed python39-lxml. hw/xwin/glx/meson.build therefore failed with
"python3 lxml module not found" on every PR.

Install the lxml module for the Python interpreter meson actually uses.

Signed-off-by: Enrico Weigelt, metux IT consult <info@metux.net>
Check malloc() return values for NULL in xnestBitBlitHelper(), xnestPolyText8(),
and xnestPolyText16() to prevent potential NULL pointer dereferences

(cherry picked from commit eae9444)
Signed-off-by: Enrico Weigelt, metux IT consult <info@metux.net>
@metux
metux force-pushed the pr/release/25.1-xnest-check-malloc-return-values-in-gcops-to-avoid-null-dereferences_2026-08-31_15-05-17 branch from 7c6acea to f627a48 Compare September 18, 2026 14:55
@metux
metux force-pushed the release/25.1 branch 2 times, most recently from 626b3bc to 62a1396 Compare October 5, 2026 08:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bot-review-passed Automated bot review found no blocking issues

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants