public inbox for git-commits@fedoraproject.org
help / color / mirror / Atom feed
From: Kevin Fenzi <kevin@scrye.com>
To: git-commits@fedoraproject.org
Subject: [rpms/glib2] cve-2026-58016-f44: Add already upstream patch to fix gdm crasher.
Date: Tue, 11 Aug 2026 10:37:14 GMT	[thread overview]
Message-ID: <178644463400.1.13494626053760027329.rpms-glib2-c71d2f1ddf70@fedoraproject.org> (raw)

A new commit has been pushed.

Repo   : rpms/glib2
Branch : cve-2026-58016-f44
Commit : c71d2f1ddf7080b93282838798b4ad96e7fbdadd
Author : Kevin Fenzi <kevin@scrye.com>
Date   : 2020-12-19T15:20:03-08:00
Stats  : +133/-1 in 2 file(s)
URL    : https://src.fedoraproject.org/rpms/glib2/c/c71d2f1ddf7080b93282838798b4ad96e7fbdadd?branch=cve-2026-58016-f44

Log:
Add already upstream patch to fix gdm crasher.

---
diff --git a/1786.patch b/1786.patch
new file mode 100644
index 0000000..c9f534f
--- /dev/null
+++ b/1786.patch
@@ -0,0 +1,127 @@
+From a2de4b24792e6aa62821bceeb5f60ea83a551c4a Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
+Date: Tue, 8 Dec 2020 18:09:50 +0200
+Subject: [PATCH 1/2] Clarify in g_object_weak_ref() docs that the callback is
+ called during disposing and not finalizing
+
+This especially has the effect that any GWeakRefs to the object will not
+necessarily be set to NULL yet if called as part of
+g_object_run_dispose() and not as part of g_object_unref().
+---
+ gobject/gobject.c | 2 +-
+ gobject/gobject.h | 4 ++--
+ 2 files changed, 3 insertions(+), 3 deletions(-)
+
+diff --git a/gobject/gobject.c b/gobject/gobject.c
+index 863d5b67a..2617dca3e 100644
+--- a/gobject/gobject.c
++++ b/gobject/gobject.c
+@@ -2975,7 +2975,7 @@ weak_refs_notify (gpointer data)
+  * @data: extra data to pass to notify
+  *
+  * Adds a weak reference callback to an object. Weak references are
+- * used for notification when an object is finalized. They are called
++ * used for notification when an object is disposed. They are called
+  * "weak references" because they allow you to safely hold a pointer
+  * to an object without calling g_object_ref() (g_object_ref() adds a
+  * strong reference, that is, forces the object to stay alive).
+diff --git a/gobject/gobject.h b/gobject/gobject.h
+index a84c183f8..aec8975e4 100644
+--- a/gobject/gobject.h
++++ b/gobject/gobject.h
+@@ -227,11 +227,11 @@ typedef void (*GObjectFinalizeFunc)     (GObject      *object);
+ /**
+  * GWeakNotify:
+  * @data: data that was provided when the weak reference was established
+- * @where_the_object_was: the object being finalized
++ * @where_the_object_was: the object being disposed
+  * 
+  * A #GWeakNotify function can be added to an object as a callback that gets
+  * triggered when the object is finalized. Since the object is already being
+- * finalized when the #GWeakNotify is called, there's not much you could do 
++ * disposed when the #GWeakNotify is called, there's not much you could do 
+  * with the object, apart from e.g. using its address as hash-index or the like. 
+  */
+ typedef void (*GWeakNotify)		(gpointer      data,
+-- 
+GitLab
+
+
+From e82eb490fea312ebe30e117288fc2e3bf2378a25 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
+Date: Tue, 8 Dec 2020 18:36:16 +0200
+Subject: [PATCH 2/2] Handle the case of g_object_run_dispose() in GBinding
+
+When this is called on the source or target, the weak notify of the
+corresponding object is called without the GWeakRef being cleared.
+See https://gitlab.gnome.org/GNOME/glib/-/issues/2266 for that issue.
+
+This means that a strong reference to these zombie objects can be
+retrieved from the GWeakRefs and the previous assumption that this can't
+happen was wrong. Remove the assertion for that accordingly and handle
+this case.
+
+Specifically, all signal handlers and weak notifies of the object are
+already gone and must not be disconnected/removed a second time, or
+otherwise memory corruption would be caused. Instead just set the
+GWeakRef to NULL and handle it otherwise as if the GWeakRef didn't give
+a strong reference to begin with.
+
+Fixes https://gitlab.gnome.org/GNOME/glib/-/issues/2265
+---
+ gobject/gbinding.c | 31 +++++++++++++++++++++++--------
+ 1 file changed, 23 insertions(+), 8 deletions(-)
+
+diff --git a/gobject/gbinding.c b/gobject/gbinding.c
+index 562f339da..48b4fbaec 100644
+--- a/gobject/gbinding.c
++++ b/gobject/gbinding.c
+@@ -388,11 +388,30 @@ weak_unbind (gpointer  user_data,
+   target = g_weak_ref_get (&context->target);
+ 
+   /* If this is called then either the source or target or both must be in the
+-   * process of being finalized and their weak reference must be reset to NULL
+-   * already.
++   * process of being disposed. If this happens as part of g_object_unref()
++   * then the weak references are actually cleared, otherwise if disposing
++   * happens as part of g_object_run_dispose() then they would still point to
++   * the disposed object.
+    *
+-   * If source==target then both will always be NULL here. */
+-  g_assert (source == NULL || target == NULL);
++   * If the object this is being called for is either the source or the target
++   * and we actually got a strong reference to it nonetheless (see above),
++   * then signal handlers and weak notifies for it are already disconnected
++   * and they must not be disconnected a second time. Instead simply clear the
++   * weak reference and be done with it.
++   *
++   * See https://gitlab.gnome.org/GNOME/glib/-/issues/2266 */
++
++  if (source == where_the_object_was)
++    {
++      g_weak_ref_set (&context->source, NULL);
++      g_clear_object (&source);
++    }
++
++  if (target == where_the_object_was)
++    {
++      g_weak_ref_set (&context->target, NULL);
++      g_clear_object (&target);
++    }
+ 
+   binding_was_removed = unbind_internal_locked (context, binding, source, target);
+ 
+@@ -627,10 +646,6 @@ g_binding_unbind_internal (GBinding *binding,
+   source = g_weak_ref_get (&context->source);
+   target = g_weak_ref_get (&context->target);
+ 
+-  /* If the binding was removed previously, source and target are both NULL.
+-   * Otherwise both will not be NULL. */
+-  g_assert ((source == NULL && target == NULL) || (source != NULL && target != NULL));
+-
+   binding_was_removed = unbind_internal_locked (context, binding, source, target);
+ 
+   g_mutex_unlock (&binding->unbind_lock);
+-- 
+GitLab
+

diff --git a/glib2.spec b/glib2.spec
index dada559..8f3a890 100644
--- a/glib2.spec
+++ b/glib2.spec
@@ -1,6 +1,6 @@
 Name: glib2
 Version: 2.67.1
-Release: 1%{?dist}
+Release: 2%{?dist}
 Summary: A library of handy utility functions
 
 License: LGPLv2+
@@ -11,6 +11,8 @@ Source0: http://download.gnome.org/sources/glib/2.67/glib-%{version}.tar.xz
 # https://gitlab.gnome.org/GNOME/glib/-/merge_requests/903
 Patch0: gnutls-hmac.patch
 
+Patch1: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/1786.patch
+
 # For gnutls-hmac.patch
 BuildRequires: pkgconfig(gnutls)
 
@@ -236,6 +238,9 @@ glib-compile-schemas %{_datadir}/glib-2.0/schemas &> /dev/null || :
 %{_datadir}/installed-tests
 
 %changelog
+* Sat Dec 19 2020 Kevin Fenzi <kevin@scrye.com> - 2.67.1-2
+- Add already upstream patch to fix gdm crasher.
+
 * Sat Dec 19 2020 Kalev Lember <klember@redhat.com> - 2.67.1-1
 - Update to 2.67.1
 

                 reply	other threads:[~2026-08-11 10:37 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=178644463400.1.13494626053760027329.rpms-glib2-c71d2f1ddf70@fedoraproject.org \
    --to=kevin@scrye.com \
    --cc=git-commits@fedoraproject.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox