Skip to content

fix: destroy wayland proxy before cleanup to prevent use-after-free crash#1621

Open
LFRon wants to merge 1 commit into
linuxdeepin:masterfrom
LFRon:fix-crash-by-open-trayloader-app
Open

fix: destroy wayland proxy before cleanup to prevent use-after-free crash#1621
LFRon wants to merge 1 commit into
linuxdeepin:masterfrom
LFRon:fix-crash-by-open-trayloader-app

Conversation

@LFRon
Copy link
Copy Markdown

@LFRon LFRon commented Jun 7, 2026

在treeland渲染器下, 点击系统托盘(dde-tray-loader)中的应用图标调出应用主窗口时会引发整个dde-shell (dock栏)崩溃, 该PR用于修复这个问题

Call destroy() on the treeland_foreign_toplevel_handle_v1 proxy before emitting handlerIsDeleted() to stop the compositor from sending further events to a handle scheduled for C++ destruction. Without this, pending state events could arrive after the ForeignToplevelHandle object is freed by QScopedPointer, causing a crash in m_states.append() when activating applications from the system tray.

Summary by Sourcery

Bug Fixes:

  • Destroy the treeland_foreign_toplevel_handle_v1 proxy before emitting the deletion signal to prevent use-after-free crashes triggered by pending Wayland events.

…rash

Call destroy() on the treeland_foreign_toplevel_handle_v1 proxy before emitting
handlerIsDeleted() to stop the compositor from sending further events to a handle
scheduled for C++ destruction. Without this, pending state events could arrive
after the ForeignToplevelHandle object is freed by QScopedPointer, causing a
crash in m_states.append() when activating applications from the system tray.
@deepin-ci-robot
Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: LFRon

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@deepin-ci-robot
Copy link
Copy Markdown

Hi @LFRon. Thanks for your PR. 😃

@deepin-ci-robot
Copy link
Copy Markdown

Hi @LFRon. Thanks for your PR.

I'm waiting for a linuxdeepin member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@sourcery-ai
Copy link
Copy Markdown

sourcery-ai Bot commented Jun 7, 2026

Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

Ensures the Wayland treeland_foreign_toplevel_handle_v1 proxy is explicitly destroyed before the corresponding C++ ForeignToplevelHandle object is torn down, preventing compositor events from targeting a freed object and causing crashes when activating apps from the system tray.

Sequence diagram for destroying treeland_foreign_toplevel_handle_v1 before C++ teardown

sequenceDiagram
    participant Compositor
    participant ForeignToplevelHandle
    participant DockTaskManager

    Compositor->>ForeignToplevelHandle: treeland_foreign_toplevel_handle_v1_closed
    ForeignToplevelHandle->>ForeignToplevelHandle: destroy
    ForeignToplevelHandle->>DockTaskManager: handlerIsDeleted
Loading

File-Level Changes

Change Details Files
Destroy the Wayland treeland_foreign_toplevel_handle_v1 proxy before emitting the deletion signal to avoid use-after-free crashes.
  • Invoke destroy() in the treeland_foreign_toplevel_handle_v1_closed() callback before emitting handlerIsDeleted()
  • Rely on destroy() to stop the compositor from sending further events to a soon-to-be-deleted ForeignToplevelHandle instance
panels/dock/taskmanager/treelandwindow.cpp

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

Copy link
Copy Markdown

@sourcery-ai sourcery-ai Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've left some high level feedback:

  • Consider whether treeland_foreign_toplevel_handle_v1_closed can be invoked multiple times and, if so, whether destroy() is idempotent or should guard against double calls to avoid double-destroying the proxy.
  • It may be worth confirming that calling destroy() before emitting handlerIsDeleted() cannot trigger re-entrant callbacks back into this object (e.g., further Wayland events) that assume state already cleaned up, and if so, adding defensive checks or state flags.
Prompt for AI Agents
Please address the comments from this code review:

## Overall Comments
- Consider whether `treeland_foreign_toplevel_handle_v1_closed` can be invoked multiple times and, if so, whether `destroy()` is idempotent or should guard against double calls to avoid double-destroying the proxy.
- It may be worth confirming that calling `destroy()` before emitting `handlerIsDeleted()` cannot trigger re-entrant callbacks back into this object (e.g., further Wayland events) that assume state already cleaned up, and if so, adding defensive checks or state flags.

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants