From 244fa852fe2775cf52a3901966cd6d8700df8227 Mon Sep 17 00:00:00 2001 From: Chris Down Date: Wed, 7 Jan 2026 22:02:00 +0800 Subject: [PATCH 01/10] dwm: Fix heap buffer overflow in getatomprop When getatomprop() is called, it invokes XGetWindowProperty() to retrieve an Atom. If the property exists but has zero elements (length 0), Xlib returns Success and sets p to a valid, non-NULL memory address containing a single null byte. However, dl (that is, the number of items) is 0. dwm blindly casts p to Atom* and dereferences it. While Xlib guarantees that p is safe to read as a string (that is, it is null-terminated), it does _not_ guarantee it is safe to read as an Atom (an unsigned long). The Atom type is a typedef for unsigned long. Reading an Atom (which thus will either likely be 4 or 8 bytes) from a 1-byte allocated buffer results in a heap buffer overflow. Since property content is user controlled, this allows any client to trigger an out of bounds read simply by setting a property with format 32 and length 0. An example client which reliably crashes dwm under ASAN: #include #include #include #include #include int main(void) { Display *d; Window root, w; Atom net_wm_state; d = XOpenDisplay(NULL); if (!d) return 1; root = DefaultRootWindow(d); w = XCreateSimpleWindow(d, root, 10, 10, 200, 200, 1, 0, 0); net_wm_state = XInternAtom(d, "_NET_WM_STATE", False); if (net_wm_state == None) return 1; XChangeProperty(d, w, net_wm_state, XA_ATOM, 32, PropModeReplace, NULL, 0); XMapWindow(d, w); XSync(d, False); sleep(1); XCloseDisplay(d); return 0; } In order to avoid this, check that the number of items returned is greater than zero before dereferencing the pointer. --- dwm.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/dwm.c b/dwm.c index 4f345ee..8f4fa75 100644 --- a/dwm.c +++ b/dwm.c @@ -870,7 +870,8 @@ getatomprop(Client *c, Atom prop) if (XGetWindowProperty(dpy, c->win, prop, 0L, sizeof atom, False, XA_ATOM, &da, &di, &dl, &dl, &p) == Success && p) { - atom = *(Atom *)p; + if (dl > 0) + atom = *(Atom *)p; XFree(p); } return atom; From 85fe518c1af5eb43f222f4d8579e4814ed769f3b Mon Sep 17 00:00:00 2001 From: Hiltjo Posthuma Date: Sat, 10 Jan 2026 11:31:44 +0100 Subject: [PATCH 02/10] bump version to 6.7 Put the maintainer at the top and bump years (time flies). --- LICENSE | 2 +- config.mk | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/LICENSE b/LICENSE index 995172f..596e6cd 100644 --- a/LICENSE +++ b/LICENSE @@ -1,5 +1,6 @@ MIT/X Consortium License +© 2010-2026 Hiltjo Posthuma © 2006-2019 Anselm R Garbe © 2006-2009 Jukka Salmi © 2006-2007 Sander van Dijk @@ -11,7 +12,6 @@ MIT/X Consortium License © 2008 Martin Hurton © 2008 Neale Pickett © 2009 Mate Nagy -© 2010-2016 Hiltjo Posthuma © 2010-2012 Connor Lane Smith © 2011 Christoph Lohmann <20h@r-36.net> © 2015-2016 Quentin Rameau diff --git a/config.mk b/config.mk index b469a2b..6e875f1 100644 --- a/config.mk +++ b/config.mk @@ -1,5 +1,5 @@ # dwm version -VERSION = 6.6 +VERSION = 6.7 # Customize below to fit your system From a9aa0d8ffbb548b0b1f9f755557aef2482c0f820 Mon Sep 17 00:00:00 2001 From: Chris Down Date: Wed, 14 Jan 2026 14:58:05 +0800 Subject: [PATCH 03/10] dwm: Fix getatomprop regression from heap overflow fix Commit 244fa852fe27 ("dwm: Fix heap buffer overflow in getatomprop") introduced a check for dl > 0 before dereferencing the property pointer. However, I missed that the variable dl is passed to XGetWindowProperty for both nitems_return and bytes_after_return parameters: XGetWindowProperty(..., &dl, &dl, &p) The final value in dl is bytes_after_return, not nitems_return. For a successfully read property, bytes_after is typically 0 (indicating all data was retrieved), so the check `dl > 0` is always false and dwm never reads any atom properties. So this is safe, but not very helpful :-) dl is probably just a dummy variable anyway, so fix by using a separate variable for nitems, and check nitems > 0 as originally intended. --- dwm.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/dwm.c b/dwm.c index 8f4fa75..53b393e 100644 --- a/dwm.c +++ b/dwm.c @@ -864,13 +864,13 @@ Atom getatomprop(Client *c, Atom prop) { int di; - unsigned long dl; + unsigned long nitems, dl; unsigned char *p = NULL; Atom da, atom = None; if (XGetWindowProperty(dpy, c->win, prop, 0L, sizeof atom, False, XA_ATOM, - &da, &di, &dl, &dl, &p) == Success && p) { - if (dl > 0) + &da, &di, &nitems, &dl, &p) == Success && p) { + if (nitems > 0) atom = *(Atom *)p; XFree(p); } From f63cde9354504ee9cfecc07517c03736d0f90c26 Mon Sep 17 00:00:00 2001 From: Hiltjo Posthuma Date: Fri, 30 Jan 2026 11:18:38 +0100 Subject: [PATCH 04/10] bump version to 6.8 --- config.mk | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/config.mk b/config.mk index 6e875f1..982dc21 100644 --- a/config.mk +++ b/config.mk @@ -1,5 +1,5 @@ # dwm version -VERSION = 6.7 +VERSION = 6.8 # Customize below to fit your system From 397d618f1cfbed398ef05d0c9d1e5dbcdb8144e7 Mon Sep 17 00:00:00 2001 From: NRK Date: Thu, 12 Feb 2026 22:28:02 +0000 Subject: [PATCH 05/10] fix not updating _NET_ACTIVE_WINDOW currently clients that set the input field of WM_HINTS to true (c->neverfocus) will never be updated as _NET_ACTIVE_WINDOW even when they are focused. according to the ICCCM [0] the input field of WM_HINTS tells the WM to either use or not use XSetInputFocus(), it shouldn't have any relation to _NET_ACTIVE_WINDOW. EWMH spec [1] also does not mention any relationship between the two. this issue was noticed when launching games via steam/proton and noticing that _NET_ACTIVE_WINDOW was always wrong/stale (i.e not updated to the game window). for reference I've looked at bspwm [2] and it also seems to set _NET_ACTIVE_WINDOW regardless of whether the client has WM_HINTS input true or not. [0]: https://x.org/releases/X11R7.6/doc/xorg-docs/specs/ICCCM/icccm.html#input_focus [1]: https://specifications.freedesktop.org/wm/1.5/ar01s03.html#id-1.4.10 [2]: https://github.com/baskerville/bspwm/blob/c5cf7d3943f9a34a5cb2bab36bf473fd77e7d4f6/src/tree.c#L659-L662 --- dwm.c | 8 +++----- 1 file changed, 3 insertions(+), 5 deletions(-) diff --git a/dwm.c b/dwm.c index 53b393e..fc4232e 100644 --- a/dwm.c +++ b/dwm.c @@ -1470,12 +1470,10 @@ sendevent(Client *c, Atom proto) void setfocus(Client *c) { - if (!c->neverfocus) { + if (!c->neverfocus) XSetInputFocus(dpy, c->win, RevertToPointerRoot, CurrentTime); - XChangeProperty(dpy, root, netatom[NetActiveWindow], - XA_WINDOW, 32, PropModeReplace, - (unsigned char *) &(c->win), 1); - } + XChangeProperty(dpy, root, netatom[NetActiveWindow], XA_WINDOW, 32, + PropModeReplace, (unsigned char *)&c->win, 1); sendevent(c, wmatom[WMTakeFocus]); } From 5c9f30300bec2f7eec9ba61d0c11df999e17f860 Mon Sep 17 00:00:00 2001 From: NRK Date: Sun, 15 Feb 2026 22:59:13 +0000 Subject: [PATCH 06/10] getstate: fix access type and remove redundant cast WM_STATE is defined to be format == 32 which xlib returns as `long` and so accessing it as `unsigned char` is incorrect. and also &p is already an `unsigned char **` and so the cast was completely redundant. given the redundant cast, i assume `p` was `long *` at some time but was changed to `unsigned char *` later, but the pointer access (and the cast) wasn't updated. also add a `format == 32` check as safety measure before accessing, just in case. --- dwm.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/dwm.c b/dwm.c index fc4232e..a5e1ce9 100644 --- a/dwm.c +++ b/dwm.c @@ -897,10 +897,10 @@ getstate(Window w) Atom real; if (XGetWindowProperty(dpy, w, wmatom[WMState], 0L, 2L, False, wmatom[WMState], - &real, &format, &n, &extra, (unsigned char **)&p) != Success) + &real, &format, &n, &extra, &p) != Success) return -1; - if (n != 0) - result = *p; + if (n != 0 && format == 32) + result = *(long *)p; XFree(p); return result; } From c3dd6a829b3f5cb9474bcca787a9c8a86932d75d Mon Sep 17 00:00:00 2001 From: NRK Date: Tue, 17 Feb 2026 07:31:35 +0000 Subject: [PATCH 07/10] more overflow fix in getatomprop() commit 244fa852 (and a9aa0d8) tried to fix overflow by checking the number of items returned. however this is not sufficient since the format may be lower than 32 bits. to reproduce the crash, i used the reproducer given in commit 244fa85 but changed the XChangeProperty line to the following to set the property to a 1 element 16 bit item: short si = 1; XChangeProperty(d, w, net_wm_state, XA_ATOM, 16, PropModeReplace, (unsigned char *)&si, 1); this client reliably crashes dwm under ASAN since dwm is trying to read a 32 bit value from a 16 bit one. fix it by checking for format == 32 as well. also change the access type from Atom to long, on my machine Atom is typedef-ed to long already but that may not be true everywere. the XGetWindowProperty manpage says format == 32 is returned as `long` so use `long` directly. (N.B: it also might be worth checking if the returned type is XA_ATOM as well, but i wasn't able to cause any crashes by setting different types so i'm leaving it out for now.) --- dwm.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/dwm.c b/dwm.c index a5e1ce9..0a67103 100644 --- a/dwm.c +++ b/dwm.c @@ -863,15 +863,15 @@ focusstack(const Arg *arg) Atom getatomprop(Client *c, Atom prop) { - int di; + int format; unsigned long nitems, dl; unsigned char *p = NULL; Atom da, atom = None; if (XGetWindowProperty(dpy, c->win, prop, 0L, sizeof atom, False, XA_ATOM, - &da, &di, &nitems, &dl, &p) == Success && p) { - if (nitems > 0) - atom = *(Atom *)p; + &da, &format, &nitems, &dl, &p) == Success && p) { + if (nitems > 0 && format == 32) + atom = *(long *)p; XFree(p); } return atom; From 2bb919e6342ae04242e3af6d5921e550d3e0a619 Mon Sep 17 00:00:00 2001 From: Ruben Gonzalez Date: Sun, 8 Mar 2026 11:24:40 +0200 Subject: [PATCH 08/10] sendmon: resize fullscreen windows to target monitor When a fullscreen window is moved to another monitor (e.g. via tagmon), its geometry does not always match the new monitor's dimensions. Steps to reproduce: 1. Start dwm with two monitors (A and B). 2. Open a window on Monitor A. 3. Make the window fullscreen (e.g. Firefox with F11). 4. Move the window to Monitor B using the tagmon shortcut (Mod+Shift+>). 5. Go to the other monitor (B), observe that the window is still visible on Monitor A and its contents, even though the window's title is seen on Monitor B bar. 6. Go to the monitor A where the window is still in fullscreen, remove the fullscreen and the window automatically will go to monitor B. This fix ensures that fullscreen windows are correctly resized to the new monitor's geometry during the move. --- dwm.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/dwm.c b/dwm.c index 0a67103..6fe226f 100644 --- a/dwm.c +++ b/dwm.c @@ -1429,6 +1429,8 @@ sendmon(Client *c, Monitor *m) c->tags = m->tagset[m->seltags]; /* assign tags of target monitor */ attach(c); attachstack(c); + if (c->isfullscreen) + resizeclient(c, m->mx, m->my, m->mw, m->mh); focus(NULL); arrange(NULL); } From 44dbc6809d05b8f2addc483f882e670db0b6b8e9 Mon Sep 17 00:00:00 2001 From: Ruben Gonzalez Date: Fri, 13 Mar 2026 15:23:24 +0200 Subject: [PATCH 09/10] buttonpress: fix status text click area mismatch The status bar in drawbar() calculates the text width as TEXTW(stext) - lrpad + 2. However, the click detection in buttonpress() used TEXTW(stext) without adjusting for that padding. This created an "extra" clickable area of some pixels to the left of the status text that would incorrectly trigger ClkStatusText actions instead of ClkWinTitle. Steps to reproduce: 1. Set a status text: xsetroot -name "HELLO" 2. Move the mouse to the empty space with some pixels close to the left of the word "HELLO" but in the title area. 3. Middle-click (or any binding for ClkStatusText). 4. You can see that the status bar action is triggered (default a terminal spawns), even though you clicked in the window title area. This fix ensures that the clickable area matches the visual text. --- dwm.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/dwm.c b/dwm.c index 6fe226f..ab3a84c 100644 --- a/dwm.c +++ b/dwm.c @@ -440,7 +440,7 @@ buttonpress(XEvent *e) arg.ui = 1 << i; } else if (ev->x < x + TEXTW(selmon->ltsymbol)) click = ClkLtSymbol; - else if (ev->x > selmon->ww - (int)TEXTW(stext)) + else if (ev->x > selmon->ww - (int)TEXTW(stext) + lrpad - 2) click = ClkStatusText; else click = ClkWinTitle; From a929abd5bc5d6a2311562be77dfc80c6dce00f34 Mon Sep 17 00:00:00 2001 From: cannoli-fruit Date: Tue, 21 Jul 2026 17:57:25 -0400 Subject: [PATCH 10/10] Added bldit.lua --- bldit.lua | 38 ++++++++++++++++++++++++++++++++++++++ 1 file changed, 38 insertions(+) create mode 100644 bldit.lua diff --git a/bldit.lua b/bldit.lua new file mode 100644 index 0000000..2fd0960 --- /dev/null +++ b/bldit.lua @@ -0,0 +1,38 @@ +bldit_version = "1.1.3" +package_version = "1.1.3" + +dependencies = {} + +targets = { + default = { + build = function() + e,h,c = os.execute("rm config.h") -- I don't really like config.h personally i prefer config.def.h + if c ~= 0 and c ~= nil then + print("Clean Error") + print("GIVEN UP") + return c + end + e,h,c = os.execute("make clean") + if c ~= 0 and c ~= nil then + print("Clean Error") + print("GIVEN UP") + return c + end + e,h,c = os.execute("make") + if c ~= 0 and c ~= nil then + print("Build Error") + print("GIVEN UP") + return c + end + return 0 + end, + install = function() + e,h,c = os.execute("make install PREFIX="..prefix) + return c or 0 + end, + uninstall = function() + e,h,c = os.execute("make uninstall PREFIX="..prefix) + return c or 0 + end, + } +}