From abb1c7988612b6475409ece4256013b47127cde8 Mon Sep 17 00:00:00 2001 From: nicm Date: Mon, 28 Sep 2026 09:32:06 +0000 Subject: [PATCH 1/2] Bounds check size and offsets for v1 layouts, found by ossfuzz. --- layout-custom.c | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/layout-custom.c b/layout-custom.c index 514db1369..d7f8f7e9f 100644 --- a/layout-custom.c +++ b/layout-custom.c @@ -1,4 +1,4 @@ -/* $OpenBSD: layout-custom.c,v 1.43 2026/09/22 06:48:01 nicm Exp $ */ +/* $OpenBSD: layout-custom.c,v 1.44 2026/09/28 09:32:06 nicm Exp $ */ /* * Copyright (c) 2010 Nicholas Marriott @@ -826,7 +826,12 @@ layout_construct_cell(struct layout_cell *lcparent, const char **layout) if (!isdigit((u_char) **layout)) return (NULL); - if (sscanf(*layout, "%ux%u,%d,%d", &sx, &sy, &xoff, &yoff) != 4) + if (sscanf(*layout, "%5ux%5u,%5d,%5d", &sx, &sy, &xoff, &yoff) != 4) + return (NULL); + if (sx < PANE_MINIMUM || sx > PANE_MAXIMUM || + sy < PANE_MINIMUM || sy > PANE_MAXIMUM || + xoff < 0 || xoff > WINDOW_MAXIMUM || + yoff < 0 || yoff > WINDOW_MAXIMUM) return (NULL); while (isdigit((u_char) **layout)) From 86af3c816734a931ff4f2d61881f4e3a563bef7d Mon Sep 17 00:00:00 2001 From: nicm Date: Mon, 28 Sep 2026 09:41:53 +0000 Subject: [PATCH 2/2] Add a second comparison for key bindings to avoid ties, GitHub issue 5647 from Alexandre Fiori. --- sort.c | 12 +++++++++--- 1 file changed, 9 insertions(+), 3 deletions(-) diff --git a/sort.c b/sort.c index 1b71db494..3b4d77301 100644 --- a/sort.c +++ b/sort.c @@ -1,4 +1,4 @@ -/* $OpenBSD: sort.c,v 1.10 2026/08/25 07:23:30 nicm Exp $ */ +/* $OpenBSD: sort.c,v 1.11 2026/09/28 09:41:53 nicm Exp $ */ /* * Copyright (c) 2026 Dane Jensen @@ -312,7 +312,7 @@ sort_key_binding_cmp(const void *a0, const void *b0) (b->key & KEYC_MASK_MODIFIERS); break; case SORT_NAME: - result = strcasecmp(a->tablename, b->tablename) == 0; + result = strcasecmp(a->tablename, b->tablename); break; case SORT_ACTIVITY: case SORT_CREATION: @@ -324,7 +324,13 @@ sort_key_binding_cmp(const void *a0, const void *b0) } if (result == 0) - result = strcasecmp(a->tablename, b->tablename) == 0; + result = strcasecmp(a->tablename, b->tablename); + if (result == 0) { + if (a->key < b->key) + result = -1; + else if (a->key > b->key) + result = 1; + } if (sort_crit->reversed) result = -result;