mirror of
https://github.com/brl/mutter.git
synced 2024-11-22 16:10:41 -05:00
c86d8a23c3
clutter_actor_get_transformed_position() would write the uninitialized values of v2 when clutter_actor_apply_transform_to_point() fails in _clutter_actor_fully_transform_vertices() because the actor has not been added to the stage yet. When called from JS this would overwrite the zero initialized values passed in from gjs. If the uninitialized values now happen to correspond to one of the NaN float values used by mozjs to represent a pointer type, this would lead to seemingly random crashes in mozjs code later on. Avoid this by using _clutter_actor_fully_transform_vertices() directly, which allows us to check if it failed. Related: https://gitlab.gnome.org/GNOME/gnome-shell-extensions/-/issues/469 Related: https://gitlab.gnome.org/GNOME/gjs/-/issues/591 Part-of: <https://gitlab.gnome.org/GNOME/mutter/-/merge_requests/3453> |
||
---|---|---|
.. | ||
clutter | ||
.gitignore | ||
meson.build |