[Git][xorg-team/lib/libxi][upstream-unstable] 4 commits: gitlab CI: drop the ci-fairy check-mr job

"Timo Aaltonen (@tjaalton)" <[email protected]>
Newsgroups gmane.linux.debian.devel.x
Message-ID <[email protected]>

Timo Aaltonen pushed to branch upstream-unstable at X Strike Force / lib / libxi


Commits:
3103b584 by Alan Coopersmith at 2026-01-25T15:31:53-08:00
gitlab CI: drop the ci-fairy check-mr job

The only thing this checked was the checkbox for allowing maintainers to
edit the MR. Changed permissions checks now fail this job but luckily
the setting it checked has been the default for years anyway so we can
drop it.

https://gitlab.freedesktop.org/freedesktop/ci-templates/-/issues/81

Signed-off-by: Alan Coopersmith <[email protected]>
Part-of: <https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/19>

- - - - -
c4cbdcf7 by Peter Hutterer at 2026-05-13T14:13:15+10:00
Discard Valuator/Key/ButtonStateNotify without the preceeding events

DeviceKeyStateNotify, DeviceButtonStateNotify, and DeviceValuator are
follow-on wire events that carry overflow data from a preceding event.
DeviceKey/ButtonStateNotify carry keys/buttons 33-255 from a preceding
DeviceStateNotify, while DeviceValuator carries axis data from a
preceding DeviceKeyPress, DeviceMotionNotify, etc. The wire-to-event
handler (XInputWireToEvent) accumulates these multi-event sequences in
a persistent 'save' buffer: the primary event populates it, then the
follow-on events append to it.

Because the 'save' event is used as the buffer it is not
zero-initialized for those follow-on events. If the first events we
receive is such a follow-on event, then we operate on uninitialized
data, causing infinte loops (anyclass->length ==0) or OOB read (garbge
anyclass->length). In the fallthrough case (class not found) we had a
memcpy to an arbitrary location.

Fix this by adding a helper function that now checks for zero length,
save->type and that we actually find the expected class.

Reported-by: Joshua J. Drake <[email protected]>
Part-of: <https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/20>

- - - - -
0700edcb by Peter Hutterer at 2026-05-13T14:13:18+10:00
Skip unknown preceeding events to DeviceValuator

If we receive a DeviceValuator events, we check the preceding 'save'
event to figure out where to append the valuator data to. This check was
missing the fallthrough case, if none of the saved types matched our
expectation we continued anyway, returning the 'save' event to the
caller.

There are two event sequences where this matters, if the DeviceValuator
follows an event that shouldn't be followed by a valuator event. In that
case we enqueued 'save' again though we should've already enqueued that
once anyway.
The second case is where the very first event is a DeviceValuator event
which now passes a zero save event. That is likely to cause a segfault
lateron.

Fix this by ignoring the bogus event.

Part-of: <https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/20>

- - - - -
f00f7e91 by Peter Hutterer at 2026-05-18T10:12:04+10:00
libXi 1.8.3

Signed-off-by: Peter Hutterer <[email protected]>

- - - - -


3 changed files:

- .gitlab-ci.yml
- configure.ac
- src/XExtInt.c


Changes:

=====================================
.gitlab-ci.yml
=====================================
@@ -46,21 +46,6 @@ check-commits:
       junit: results.xml
   allow_failure: true
 
-#
-# Verify that the merge request has the allow-collaboration checkbox ticked
-#
-check-merge-request:
-  extends:
-    - .fdo.ci-fairy
-  stage: deploy
-  script:
-    - ci-fairy check-merge-request --require-allow-collaboration --junit-xml=results.xml
-  artifacts:
-    when: on_failure
-    reports:
-      junit: results.xml
-  allow_failure: true
-
 
 #
 # Build a container with the given tag and the packages pre-installed.


=====================================
configure.ac
=====================================
@@ -1,7 +1,7 @@
 
 # Initialize Autoconf
 AC_PREREQ([2.60])
-AC_INIT([libXi], [1.8.2],
+AC_INIT([libXi], [1.8.3],
 	[https://gitlab.freedesktop.org/xorg/lib/libXi/issues], [libXi])
 AC_CONFIG_SRCDIR([Makefile.am])
 AC_CONFIG_HEADERS([src/config.h])


=====================================
src/XExtInt.c
=====================================
@@ -382,7 +382,7 @@ _XiCheckExtInit(
     }
 
     if (info->data == NULL) {
-	info->data = (XPointer) Xmalloc(sizeof(XInputData));
+	info->data = (XPointer) Xcalloc(1, sizeof(XInputData));
 	if (!info->data) {
 	    UnlockDisplay(dpy);
 	    return (-1);
@@ -464,6 +464,26 @@ _XiGetDevicePresenceNotifyEvent(Display * dpy)
     return info->codes->first_event + XI_DevicePresenceNotify;
 }
 
+static XInputClass *
+find_class(XInputClass *classes, size_t num_classes, int which)
+{
+    XInputClass *current = classes;
+    size_t i;
+
+    for (i = 0; i < num_classes; i++) {
+        if (current->length == 0)
+            return NULL;
+        if (current->class == which)
+            break;
+        current = (XInputClass *)((char *)current +
+                                   current->length);
+    }
+    if (i >= num_classes)
+        return NULL;
+
+    return current;
+}
+
 /***********************************************************************
  *
  * Handle Input extension events.
@@ -700,12 +720,15 @@ XInputWireToEvent(
                     } else if (save_type == XI_DeviceStateNotify) {
                         int j;
                         XDeviceStateNotifyEvent *sev = (XDeviceStateNotifyEvent *) save;
-                        XInputClass *any = (XInputClass *) & sev->data[0];
+                        XInputClass *any;
                         XValuatorStatus *v;
 
-                        for (i = 0; i < sev->num_classes; i++)
-                            if (any->class != ValuatorClass)
-                                any = (XInputClass *) ((char *)any + any->length);
+                        any = find_class((XInputClass *) & sev->data[0],
+                                         sev->num_classes,
+                                         ValuatorClass);
+                        if (!any)
+                            return (DONT_ENQUEUE);
+
                         v = (XValuatorStatus *) any;
                         i = v->num_valuators;
                         j = xev->num_valuators;
@@ -721,6 +744,8 @@ XInputWireToEvent(
                         }
                         v->num_valuators += j;
 
+                    } else {
+                        return (DONT_ENQUEUE);
                     }
                     *re = *save;
                     return (ENQUEUE_EVENT);
@@ -801,19 +826,19 @@ XInputWireToEvent(
                 break;
             case XI_DeviceKeystateNotify:
                 {
-                    int i;
                     XInputClass *anyclass;
                     register XKeyStatus *kv;
                     deviceKeyStateNotify *ksev = (deviceKeyStateNotify *) event;
                     XDeviceStateNotifyEvent *kstev = (XDeviceStateNotifyEvent *) save;
 
-                    anyclass = (XInputClass *) & kstev->data[0];
-                    for (i = 0; i < kstev->num_classes; i++)
-                        if (anyclass->class == KeyClass)
-                            break;
-                        else
-                            anyclass = (XInputClass *) ((char *)anyclass +
-                                    anyclass->length);
+                    if (save->type != info->codes->first_event + XI_DeviceStateNotify)
+                        return (DONT_ENQUEUE);
+
+                    anyclass = find_class((XInputClass *) & kstev->data[0],
+                                          kstev->num_classes,
+                                          KeyClass);
+                    if (!anyclass)
+                        return (DONT_ENQUEUE);
 
                     kv = (XKeyStatus *) anyclass;
                     kv->num_keys = 256;
@@ -828,19 +853,19 @@ XInputWireToEvent(
                 break;
             case XI_DeviceButtonstateNotify:
                 {
-                    int i;
                     XInputClass *anyclass;
                     register XButtonStatus *bv;
                     deviceButtonStateNotify *bsev = (deviceButtonStateNotify *) event;
                     XDeviceStateNotifyEvent *bstev = (XDeviceStateNotifyEvent *) save;
 
-                    anyclass = (XInputClass *) & bstev->data[0];
-                    for (i = 0; i < bstev->num_classes; i++)
-                        if (anyclass->class == ButtonClass)
-                            break;
-                        else
-                            anyclass = (XInputClass *) ((char *)anyclass +
-                                    anyclass->length);
+                    if (save->type != info->codes->first_event + XI_DeviceStateNotify)
+                        return (DONT_ENQUEUE);
+
+                    anyclass = find_class((XInputClass *) & bstev->data[0],
+                                          bstev->num_classes,
+                                          ButtonClass);
+                    if (!anyclass)
+                        return (DONT_ENQUEUE);
 
                     bv = (XButtonStatus *) anyclass;
                     bv->num_buttons = 256;



View it on GitLab: https://salsa.debian.org/xorg-team/lib/libxi/-/compare/3c2d5aedd7708c75710b39268631762de904c304...f00f7e9140b4707775331950dd67851e55058c40

-- 
View it on GitLab: https://salsa.debian.org/xorg-team/lib/libxi/-/compare/3c2d5aedd7708c75710b39268631762de904c304...f00f7e9140b4707775331950dd67851e55058c40
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.