Find a file
Peter Hutterer 74b4ca132f tools/debug-tablet-pad: add bounds checks for array accesses
A few not-really-an-issue fixes found by Claude:

1. ctx->buttons_down[number]: the 'number' value comes from
   libinput_event_tablet_pad_get_button_number() and is written into
   a fixed-size array of 32 elements without bounds checking. A crafted
   or malicious device reporting button numbers >= 32 causes a stack
   buffer overflow.

2. ctx->ring[number], ctx->strip[number], ctx->dial[number]: these are
   fixed-size arrays of 2 elements each. Ring/strip/dial numbers from
   libinput events are used as indices without bounds checking. Values
   >= 2 cause out-of-bounds writes.

3. assert()-based error handling for open() and libevdev_new_from_fd():
   assert() is compiled to a no-op in release builds (NDEBUG). This
   means that in release builds, a failed open() returns fd=-1, and
   libevdev_new_from_fd() is called with an invalid fd. The result is
   undefined behavior.

4. Variable-length array (VLA) 'empty[termwidth]' in print_bar():
   termwidth comes from an ioctl(TIOCGWINSZ) call and could be very
   large, causing a stack overflow. Replace with a fixed-size buffer.

None of these really matter for a niche debugging tool.

Co-Authored-by: Claude Code <noreply@anthropic.com>
Part-of: <https://gitlab.freedesktop.org/libinput/libinput/-/merge_requests/1467>
2026-04-22 04:53:13 +00:00
.gitlab/issue_templates gitlab: make the bug template the default template 2023-11-23 09:53:09 +10:00
.gitlab-ci CI: rebuild to pick up newer libwacom on Fedora 43 2026-01-14 09:27:28 +10:00
completion/zsh tools: add --compress-motion-events to the man page and zsh completion 2026-03-11 14:22:40 +10:00
doc doc/user: add an illustration of the touch arbitration rectangle 2026-04-21 11:12:59 +10:00
include include: sync headers with kernel 6.18 2025-12-01 21:39:11 +00:00
plugins plugin: add an example for controlling a mouse with a tablet 2026-01-21 08:44:13 +00:00
quirks quirks: add missing modification warning to a quirks file 2026-04-14 09:48:15 +10:00
src plugin: use safe_strdup() instead of strdup() 2026-04-22 04:53:13 +00:00
test util: allow for 'e' in safe_atod strings 2026-04-22 04:53:13 +00:00
tools tools/debug-tablet-pad: add bounds checks for array accesses 2026-04-22 04:53:13 +00:00
udev udev: use xclose() instead of close() 2026-04-22 04:53:13 +00:00
.clang-format clang-format: add litest_with_logcapture to foreach macros 2025-08-01 04:02:56 +00:00
.clang-format-ignore Add a clang-format file for consistent code formatting 2025-07-01 16:42:44 +10:00
.clang-tidy clang-tidy: fix WarningAsErrors option to actually work 2025-08-11 15:27:35 +10:00
.clang-tidy-ignore Add a clang-tidy file 2025-04-07 08:43:36 +00:00
.dir-locals.el indentation: add .dir-locals.el for emacs 2018-02-26 18:44:00 +10:00
.editorconfig editorconfig: add settings for sym files 2024-11-04 10:31:30 +00:00
.git-blame-ignore-revs git: add git-blame-ignore-revs to ignore the clang-format commits 2025-07-02 12:43:13 +10:00
.gitignore gitignore: ignore gnuplot files 2018-05-10 16:25:40 +10:00
.gitlab-ci.yml CI: rebuild to pick up newer libwacom on Fedora 43 2026-01-14 09:27:28 +10:00
.pre-commit-config.yaml pre-commit: update the name for the ruff check 2025-07-15 16:24:27 +10:00
.triage-policies.yml triage-policies: add a bugbot hook for re-closing a bug 2025-10-13 06:21:26 +00:00
.vimdir Add .vimdir for libinput-specific settings 2015-05-25 09:17:29 +10:00
CODING_STYLE.md Drop the Signed-off-by requirement 2023-07-21 09:08:46 +10:00
CONTRIBUTING.md CONTRIBUTING: Add CONTRIBUTING.md 2024-02-28 17:07:45 +01:00
COPYING Change various references to the master branch to main 2021-04-29 01:31:03 +00:00
meson.build meson.build: explicitly convert a boolean to string 2026-03-13 12:15:21 +10:00
meson_options.txt Revert "lua: drop compatibility to 5.1 to allow for luajit" 2025-11-18 01:46:53 +00:00
README.md Change various references to the master branch to main 2021-04-29 01:31:03 +00:00

libinput

libinput is a library that provides a full input stack for display servers and other applications that need to handle input devices provided by the kernel.

libinput provides device detection, event handling and abstraction to minimize the amount of custom input code the user of libinput needs to provide the common set of functionality that users expect. Input event processing includes scaling touch coordinates, generating relative pointer events from touchpads, pointer acceleration, etc.

User documentation

Documentation explaining features available in libinput is available here.

This includes the FAQ and the instructions on reporting bugs.

Source code

The source code of libinput can be found at: https://gitlab.freedesktop.org/libinput/libinput

For a list of current and past releases visit: https://www.freedesktop.org/wiki/Software/libinput/

Build instructions: https://wayland.freedesktop.org/libinput/doc/latest/building.html

Reporting Bugs

Bugs can be filed on freedesktop.org GitLab: https://gitlab.freedesktop.org/libinput/libinput/issues/

Where possible, please provide the libinput record output of the input device and/or the event sequence in question.

See https://wayland.freedesktop.org/libinput/doc/latest/reporting-bugs.html for more info.

Documentation

Examples of how to use libinput are the debugging tools in the libinput repository. Developers are encouraged to look at those tools for a real-world (yet simple) example on how to use libinput.

License

libinput is licensed under the MIT license.

Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: [...]

See the COPYING file for the full license information.

About

Documentation generated from git commit GIT_VERSION