Skip to content

Commit 19b6179

Browse files
committed
st/mesa: don't cast the incomplete framebufer to st_framebuffer
The incomplete framebuffer is set for a surfaceless context. This leads to the following error in piglit spec@egl_khr_surfaceless_context@viewport: ==26703==ERROR: AddressSanitizer: global-buffer-overflow on address 0x7f6886e43240 at pc 0x7f68854db0fd bp 0x7ffca404b3b0 sp 0x7ffca404b3a0 READ of size 8 at 0x7f6886e43240 thread T0 #0 0x7f68854db0fc in st_viewport ../../../mesa-src/src/mesa/state_tracker/st_cb_viewport.c:57 #1 0x556840176cdb in main tests/egl/spec/egl_khr_surfaceless_context/viewport.c:101 #2 0x7f688edcf3f0 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x203f0) #3 0x556840176e19 in _start (/home/nha/amd/piglit/bin/egl-surfaceless-context-viewport+0xe19) 0x7f6886e43240 is located 32 bytes to the left of global variable 'DummyRenderbuffer' defined in '../../../mesa-src/src/mesa/main/fbobject.c:69:31' (0x7f6886e43260) of size 112 0x7f6886e43240 is located 8 bytes to the right of global variable 'IncompleteFramebuffer' defined in '../../../mesa-src/src/mesa/main/fbobject.c:73:30' (0x7f6886e42de0) of size 1112 SUMMARY: AddressSanitizer: global-buffer-overflow ../../../mesa-src/src/mesa/state_tracker/st_cb_viewport.c:57 in st_viewport Cc: mesa-stable@lists.freedesktop.org Reviewed-by: Marek Olšák <marek@olsak@amd.com>
1 parent 28ec0fc commit 19b6179

File tree

2 files changed

+4
-2
lines changed

2 files changed

+4
-2
lines changed

src/mesa/state_tracker/st_cb_fbo.h

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -85,7 +85,8 @@ static inline struct st_framebuffer *
8585
st_ws_framebuffer(struct gl_framebuffer *fb)
8686
{
8787
/* FBO cannot be casted. See st_new_framebuffer */
88-
if (fb && _mesa_is_winsys_fbo(fb))
88+
if (fb && _mesa_is_winsys_fbo(fb) &&
89+
fb != _mesa_get_incomplete_framebuffer())
8990
return (struct st_framebuffer *) fb;
9091
return NULL;
9192
}

src/mesa/state_tracker/st_manager.c

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -844,13 +844,14 @@ st_manager_flush_frontbuffer(struct st_context *st)
844844
struct st_framebuffer *stfb = st_ws_framebuffer(st->ctx->DrawBuffer);
845845
struct st_renderbuffer *strb = NULL;
846846

847+
assert(st->ctx->DrawBuffer != _mesa_get_incomplete_framebuffer());
848+
847849
if (stfb)
848850
strb = st_renderbuffer(stfb->Base.Attachment[BUFFER_FRONT_LEFT].Renderbuffer);
849851
if (!strb)
850852
return;
851853

852854
/* never a dummy fb */
853-
assert(&stfb->Base != _mesa_get_incomplete_framebuffer());
854855
stfb->iface->flush_front(&st->iface, stfb->iface, ST_ATTACHMENT_FRONT_LEFT);
855856
}
856857

0 commit comments

Comments
 (0)