diff options
| author | Danilo M. <danix@danix.xyz> | 2026-09-15 18:09:26 +0200 |
|---|---|---|
| committer | Danilo M. <danix@danix.xyz> | 2026-09-15 18:09:26 +0200 |
| commit | 2a3916ce192d73bdd6f621cc3842782814351227 (patch) | |
| tree | 4c275a9cd02cad501a77925cbdd0d18807a15c88 /internal/notify/icons.go | |
| parent | 6ad6f122eb2ec9cd8a55c042dffe38db41ed1959 (diff) | |
| download | notifyd-2a3916ce192d73bdd6f621cc3842782814351227.tar.gz notifyd-2a3916ce192d73bdd6f621cc3842782814351227.zip | |
fix(notify): cap image dimensions and rank icon_data last
A notification is untrusted input. RawImage.PNG computed
stride*(Height-1)+Width*Channels in int, so Width=Height=2^31-1 with
RowStride=0 wrapped the length expression negative, slipped past the
guard, and reached image.NewRGBA, which panics. The D-Bus call path has
no recover, so one malformed Notify killed the daemon. Cap Width/Height
at 1<<16 before any multiplication and compute the required byte count
in int64.
image-data, image-path and the deprecated icon_data were read as one
tier, with icon_data ahead of image-path, inverting the spec's order.
Split the deprecated key into IconDataFromHints and apply tier 1
(image-data/image_data), then image-path, then icon_data. Raw handling
is unchanged: encode, hold pendingImage, WriteImage after Add, SetImage.
Diffstat (limited to 'internal/notify/icons.go')
0 files changed, 0 insertions, 0 deletions
