diff --git a/CHANGELOG.md b/CHANGELOG.md index b6d3e0d4cbed..bd63d9f6e831 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -237,6 +237,8 @@ additionally drops the buffers cached for copying between a render and a target ### Bugfixes +The `xdg_toplevel` request handler now posts an `invalid_size` error when a client performs a `set_max_size` or `set_min_size` request with a negative width or height. + `DrmDeviceFd::new` no longer tries to become DRM master on a render node, which the kernel always refuses, so it no longer warns about it. diff --git a/src/wayland/shell/xdg/handlers/surface/toplevel.rs b/src/wayland/shell/xdg/handlers/surface/toplevel.rs index 41576b119fc2..cf2a00702f86 100644 --- a/src/wayland/shell/xdg/handlers/surface/toplevel.rs +++ b/src/wayland/shell/xdg/handlers/surface/toplevel.rs @@ -128,11 +128,25 @@ where } } xdg_toplevel::Request::SetMaxSize { width, height } => { + if width < 0 || height < 0 { + toplevel.post_error( + xdg_toplevel::Error::InvalidSize, + "The max size cannot be negative", + ); + return; + } with_toplevel_pending_state(self, |toplevel_data| { toplevel_data.max_size = (width, height).into(); }); } xdg_toplevel::Request::SetMinSize { width, height } => { + if width < 0 || height < 0 { + toplevel.post_error( + xdg_toplevel::Error::InvalidSize, + "The min size cannot be negative", + ); + return; + } with_toplevel_pending_state(self, |toplevel_data| { toplevel_data.min_size = (width, height).into(); });