• Zhiyi Zhang's avatar
    win32u: Find the correct DIB driver in windrv_CreateDC(). · 36366f12
    Zhiyi Zhang authored
    push_dc_driver() places drivers based on their priorities, so the newly created driver is not
    necessarily on top. Thus in windrv_CreateDC(), find_dc_driver() should be used to find the DIB
    driver instead of assuming the DIB driver is the top driver, which could be the path driver because
    it has a higher priority.
    
    The exact wrong code path was:
    1. A path driver with priority 400 is created for a DC.
    2. windrv_CreateDC() is called to create a window driver for the DC.
    3. Then in dibdrv_CreateDC(), push_dc_driver() is called with 'dev' pointing to the top driver, which is the path driver.
    4. push_dc_driver() updates 'dev' to point to the address of the next driver because DIB driver has a lower 300 priority.
    5. The DIB driver is assigned to 'dev', which is not the original parameter passed into push_dc_driver().
    6. In windrv_CreateDC(), get_dibdrv_pdev(*dev) is called, assuming the top driver is the DIB driver. But actually the top
       driver that '*dev' points to is still the path driver.
    
    The added tests can demonstrate the memory corruption before this fix is applied.
    36366f12
Name
Last commit
Last update
..
dibdrv Loading commit data...
tests Loading commit data...
Makefile.in Loading commit data...
bitblt.c Loading commit data...
bitmap.c Loading commit data...
brush.c Loading commit data...
class.c Loading commit data...
clipboard.c Loading commit data...
clipping.c Loading commit data...
cursoricon.c Loading commit data...
dc.c Loading commit data...
dce.c Loading commit data...
defwnd.c Loading commit data...
dib.c Loading commit data...
driver.c Loading commit data...
emfdrv.c Loading commit data...
font.c Loading commit data...
freetype.c Loading commit data...
gdiobj.c Loading commit data...
hook.c Loading commit data...
imm.c Loading commit data...
input.c Loading commit data...
main.c Loading commit data...
mapping.c Loading commit data...
menu.c Loading commit data...
message.c Loading commit data...
ntgdi_private.h Loading commit data...
ntuser_private.h Loading commit data...
opentype.c Loading commit data...
painting.c Loading commit data...
palette.c Loading commit data...
path.c Loading commit data...
pen.c Loading commit data...
printdrv.c Loading commit data...
rawinput.c Loading commit data...
region.c Loading commit data...
scroll.c Loading commit data...
spy.c Loading commit data...
syscall.c Loading commit data...
sysparams.c Loading commit data...
systray.c Loading commit data...
vertical.c Loading commit data...
vulkan.c Loading commit data...
win32syscalls.h Loading commit data...
win32u.spec Loading commit data...
win32u_private.h Loading commit data...
window.c Loading commit data...
winstation.c Loading commit data...