A11yKeyboardMonitorState::key_event calls self.has_key_grab() inside
self.clients guard loop.
A "well-behaved" a11y client calls `WatchKeyboard` before `SetKeyGrabs`.
If WatchKeyboard is not called first, the `!client.watched` guard does
not short-circuit, so `has_key_grab()` runs and locks `self.clients` again.
This causes a deadlock and the compositor freezes, requiring a hard reboot.
This commit moves the `self.has_key_grab()` before the guard to
prevent a double lock.
display_configuration() issued an ALLOW_MODESET atomic commit on every udev
event, even when no planes needed detaching. The empty commit is a no-op
modeset that interferes with in-flight commits on the render thread, and it
fails with EPERM whenever we don't hold DRM master (e.g. a render-only
secondary GPU), aborting device enumeration.
Track whether any property was added and skip the commit when there is nothing
to do. A commit that does have changes still propagates its error as before, so
a genuine failure to apply cleanup is not silently swallowed.
https://github.com/pop-os/cosmic-comp/issues/2375
Authored by Claude Opus 4.8
Reviewed by Timo Strunk <Timo.Strunk@gmail.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
When the kiosk child exits, calling process::exit() directly from the calloop
callback runs libc's atexit handlers (Mesa's util_queue_kill_threads) while a
KMS surface thread may still be mid-frame in eglCreateSync(). Concurrent Mesa
teardown and live EGL use corrupt the heap and glibc aborts the process
("free(): corrupted unsorted chunks", SIGABRT).
Stop the event loop cleanly via should_stop instead, stashing the child's exit
code in Common::kiosk_exit_code. After the loop returns, pause() each DRM device
(releasing master so the surface drop path skips its blocking clear_state(), and
the incoming compositor gets master immediately), then drop_and_join() every
surface so no thread is left in Mesa. Only then is process::exit() called, at
which point atexit is safe to run.
The join is done here rather than in Surface::Drop because an unconditional join
in Drop deadlocks against apply_config_for_outputs during normal operation; once
the event loop has stopped, the surface thread can process ThreadCommand::End
and exit without the main thread servicing any pending message.
https://github.com/pop-os/cosmic-comp/issues/2375
Authored by Claude Opus 4.8
Reviewed by Timo Strunk <Timo.Strunk@gmail.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
If a window with an active popup grab is closed or crashes unexpectedly, the input grab state can get stuck, freezing keyboard and mouse clicks.
This patch iterates over all seats and releases the active seat grab if it is owned by the destroyed window or one of its child popups.
Signed-off-by: littlezabi <zohaibjozvi@gmail.com>
Gnome seems to send `motion` in these cases. The spec isn't 100%
explicit, but it seems `motion` events are needed for the client to have
the same understanding of where the pointer is as the compositor, which
generally seems to be desired.
This is also needed for toplevel cursor image-copy to get the position
change. Likewise, we want image-copy to have the same understanding of
where the cursor is as the compositor and client.
This ensures we avoid advertising a `0,0` buffer size (which will
protocol error to actually allocate), and avoids defining the supported
formats for cursor capture buffers in a bunch of places.
We were just running whatever was given on the command line as the
kiosk command, which meant that if --no-xwayland was given, we'd try
execing --no-xwayland. Preserve the processed command line from the
option parser, and run only what's left over as the kiosk command to
fix this.
Other service supervisors implement systemd's readiness notification
protocol. For example, s6 implements it with the
s6-notify-fd-from-socket[1] program. libsystemd::daemon::notify
already checks for NOTIFY_SOCKET being set, which should be sufficient
to tell if systemd-style readiness notification is wanted.
Link: https://skarnet.org/software/s6/s6-notify-fd-from-socket.html [1]
Libinput reports natural scrolling via AxisRelativeDirection. Qt sets
QWheelEvent::inverted() from wl_pointer.axis_relative_direction. COSMIC
was forwarding axis values but not the direction hint.
Tested on Fedora 44 COSMIC Wayland with Telegram Desktop (native Wayland),
natural scrolling enabled — horizontal touchpad swipes fixed.
Assisted-by: AI (root-cause analysis)
Signed-off-by: Erik <erik-balfe@users.noreply.github.com>