fix(wireplumber): read gboolean into a gboolean, not a 1-byte bool (OOB write)

g_variant_lookup with the "b" format writes a gboolean (gint, 4 bytes),
but muted_ and source_muted_ are C++ bool members (1 byte). Passing their
addresses caused a 3-byte out-of-bounds write past the member (undefined
behavior). Read into a gboolean temporary and assign back to the bool,
preserving the prior value when "mute" is absent.
This commit is contained in:
Alex
2026-07-05 10:19:51 +02:00
parent acc7060be6
commit 9b093c53e9
+11 -2
View File
@@ -304,7 +304,12 @@ void waybar::modules::Wireplumber::updateVolume(waybar::modules::Wireplumber* se
g_variant_lookup(variant, "volume", "d", &self->volume_);
g_variant_lookup(variant, "step", "d", &self->min_step_);
g_variant_lookup(variant, "mute", "b", &self->muted_);
// GVariant "b" writes a gboolean (4 bytes); reading directly into the 1-byte bool member is an
// out-of-bounds write. Read into a gboolean temporary and assign back.
gboolean mute = FALSE;
if (g_variant_lookup(variant, "mute", "b", &mute)) {
self->muted_ = mute;
}
g_clear_pointer(&variant, g_variant_unref);
self->dp.emit();
@@ -329,7 +334,11 @@ void waybar::modules::Wireplumber::updateSourceVolume(waybar::modules::Wireplumb
}
g_variant_lookup(variant, "volume", "d", &self->source_volume_);
g_variant_lookup(variant, "mute", "b", &self->source_muted_);
// See updateVolume: GVariant "b" writes a gboolean (4 bytes), not a 1-byte bool.
gboolean mute = FALSE;
if (g_variant_lookup(variant, "mute", "b", &mute)) {
self->source_muted_ = mute;
}
g_clear_pointer(&variant, g_variant_unref);
self->dp.emit();