From 803ead19ddc2b200114e297b069e70d93bd1b84d Mon Sep 17 00:00:00 2001 From: EVV1E Date: Mon, 28 Sep 2026 01:34:40 +0200 Subject: [PATCH] fix: Post error for negative toplevel size hints The xdg-shell protocol states that the width and height for xdg_toplevel::set_min_size and xdg_toplevel::set_max_size must be greater than or equal to zero and attempting to set negative width/height values should raise an invalid_size error. Previously, smithay would not post an invalid_size error for such cases. Additionally, because the toplevel handler converts these values into a smithay::utils::Size, this would trigger an abort due to the debug_assert for negative sizes on Size::new for debug builds. --- CHANGELOG.md | 2 ++ src/wayland/shell/xdg/handlers/surface/toplevel.rs | 14 ++++++++++++++ 2 files changed, 16 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index b6d3e0d4cbed..bd63d9f6e831 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -237,6 +237,8 @@ additionally drops the buffers cached for copying between a render and a target ### Bugfixes +The `xdg_toplevel` request handler now posts an `invalid_size` error when a client performs a `set_max_size` or `set_min_size` request with a negative width or height. + `DrmDeviceFd::new` no longer tries to become DRM master on a render node, which the kernel always refuses, so it no longer warns about it. diff --git a/src/wayland/shell/xdg/handlers/surface/toplevel.rs b/src/wayland/shell/xdg/handlers/surface/toplevel.rs index 41576b119fc2..cf2a00702f86 100644 --- a/src/wayland/shell/xdg/handlers/surface/toplevel.rs +++ b/src/wayland/shell/xdg/handlers/surface/toplevel.rs @@ -128,11 +128,25 @@ where } } xdg_toplevel::Request::SetMaxSize { width, height } => { + if width < 0 || height < 0 { + toplevel.post_error( + xdg_toplevel::Error::InvalidSize, + "The max size cannot be negative", + ); + return; + } with_toplevel_pending_state(self, |toplevel_data| { toplevel_data.max_size = (width, height).into(); }); } xdg_toplevel::Request::SetMinSize { width, height } => { + if width < 0 || height < 0 { + toplevel.post_error( + xdg_toplevel::Error::InvalidSize, + "The min size cannot be negative", + ); + return; + } with_toplevel_pending_state(self, |toplevel_data| { toplevel_data.min_size = (width, height).into(); });