Version in base suite: 6.3.6-1 Base version: kwin_6.3.6-1 Target version: kwin_6.3.6-1+deb13u1 Base file: /srv/ftp-master.debian.org/ftp/pool/main/k/kwin/kwin_6.3.6-1.dsc Target file: /srv/ftp-master.debian.org/policy/pool/main/k/kwin/kwin_6.3.6-1+deb13u1.dsc changelog | 12 + patches/series | 2 patches/upstream_172f8f2e_wayland-Check-for-nullptr-output-in-ColorManagemen.patch | 27 ++ patches/upstream_e1fd647b_wayland-Make-ColorManagementOutputV1-handle-output-r.patch | 110 ++++++++++ 4 files changed, 151 insertions(+) dpkg-source: warning: cannot verify inline signature for /srv/release.debian.org/tmp/tmp_l9yw6ac/kwin_6.3.6-1.dsc: no acceptable signature found dpkg-source: warning: cannot verify inline signature for /srv/release.debian.org/tmp/tmp_l9yw6ac/kwin_6.3.6-1+deb13u1.dsc: no acceptable signature found diff -Nru kwin-6.3.6/debian/changelog kwin-6.3.6/debian/changelog --- kwin-6.3.6/debian/changelog 2025-07-18 09:21:52.000000000 +0000 +++ kwin-6.3.6/debian/changelog 2026-10-05 13:25:07.000000000 +0000 @@ -1,3 +1,15 @@ +kwin (4:6.3.6-1+deb13u1) trixie; urgency=medium + + [ Sandro Knauß ] + * Backport from upstream plasma/6.5.4 [e1fd647b] (kde#504959): + Fix session crash in ColorManagementOutputV1 on output change (Closes: 1147212) + + [ Chris Halls ] + * Backport from upstream plasma/6.4.5 [172f8f2e] (kde#504959): + Fix crash in ColorManagementOutputV1 when unplugging monitors + + -- Sandro Knauß Mon, 05 Oct 2026 15:25:07 +0200 + kwin (4:6.3.6-1) unstable; urgency=medium [ Aurélien COUDERC ] diff -Nru kwin-6.3.6/debian/patches/series kwin-6.3.6/debian/patches/series --- kwin-6.3.6/debian/patches/series 2025-07-18 09:21:52.000000000 +0000 +++ kwin-6.3.6/debian/patches/series 2026-10-05 13:24:33.000000000 +0000 @@ -23,3 +23,5 @@ upstream_e8541cf2_wayland-Fix-resizing-with-fractional-increments.patch upstream_51c0880f_wayland-close-popups-upon-window-activation.patch upstream_267fa4ec_Fix-activate-and-raise-action-with-panels.patch +upstream_e1fd647b_wayland-Make-ColorManagementOutputV1-handle-output-r.patch +upstream_172f8f2e_wayland-Check-for-nullptr-output-in-ColorManagemen.patch diff -Nru kwin-6.3.6/debian/patches/upstream_172f8f2e_wayland-Check-for-nullptr-output-in-ColorManagemen.patch kwin-6.3.6/debian/patches/upstream_172f8f2e_wayland-Check-for-nullptr-output-in-ColorManagemen.patch --- kwin-6.3.6/debian/patches/upstream_172f8f2e_wayland-Check-for-nullptr-output-in-ColorManagemen.patch 1970-01-01 00:00:00.000000000 +0000 +++ kwin-6.3.6/debian/patches/upstream_172f8f2e_wayland-Check-for-nullptr-output-in-ColorManagemen.patch 2026-10-05 13:24:33.000000000 +0000 @@ -0,0 +1,27 @@ +From 172f8f2e71d93a27f23586587d9cf86cbfee8615 Mon Sep 17 00:00:00 2001 +From: Arnav Rawat +Date: Tue, 26 Aug 2025 06:29:18 -0500 +Subject: [PATCH] wayland: Check for nullptr output in ColorManagementOutputV1 + +m_output could be nullptr, and it would cause a crash when unplugging +monitors. +--- + src/wayland/colormanagement_v1.cpp | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/wayland/colormanagement_v1.cpp b/src/wayland/colormanagement_v1.cpp +index 49879a85896..90675f7a2a9 100644 +--- a/src/wayland/colormanagement_v1.cpp ++++ b/src/wayland/colormanagement_v1.cpp +@@ -593,7 +593,7 @@ ColorManagementOutputV1::ColorManagementOutputV1(wl_client *client, uint32_t id, + : QtWaylandServer::wp_color_management_output_v1(client, id, version) + , m_output(output) + { +- if (m_output->isRemoved()) { ++ if (!m_output || m_output->isRemoved()) { + return; + } + +-- +GitLab + diff -Nru kwin-6.3.6/debian/patches/upstream_e1fd647b_wayland-Make-ColorManagementOutputV1-handle-output-r.patch kwin-6.3.6/debian/patches/upstream_e1fd647b_wayland-Make-ColorManagementOutputV1-handle-output-r.patch --- kwin-6.3.6/debian/patches/upstream_e1fd647b_wayland-Make-ColorManagementOutputV1-handle-output-r.patch 1970-01-01 00:00:00.000000000 +0000 +++ kwin-6.3.6/debian/patches/upstream_e1fd647b_wayland-Make-ColorManagementOutputV1-handle-output-r.patch 2026-09-21 06:36:53.000000000 +0000 @@ -0,0 +1,110 @@ +From e1fd647b979df7f0bd10065932a614a2aa806e87 Mon Sep 17 00:00:00 2001 +From: Vlad Zahorodnii +Date: Thu, 29 May 2025 10:42:05 +0300 +Subject: [PATCH] wayland: Make ColorManagementOutputV1 handle output removal + better + +wl_output removal is racy. The compositor can remove the underlying +handle but the corresponding wl_output object may still linger for a +while. + +If that happens, the ColorManagementOutputV1 must not attempt to +dereference the handle object. + +BUG: 504959 +SENTRY: KWIN-CKJ +--- + src/wayland/colormanagement_v1.cpp | 22 ++++++++++++++++------ + src/wayland/colormanagement_v1.h | 7 +++---- + 2 files changed, 19 insertions(+), 10 deletions(-) + +diff --git a/src/wayland/colormanagement_v1.cpp b/src/wayland/colormanagement_v1.cpp +index c16af0a76c..4195fc68c9 100644 +--- a/src/wayland/colormanagement_v1.cpp ++++ b/src/wayland/colormanagement_v1.cpp +@@ -60,7 +60,7 @@ void ColorManagerV1::wp_color_manager_v1_destroy(Resource *resource) + + void ColorManagerV1::wp_color_manager_v1_get_output(Resource *resource, uint32_t id, struct ::wl_resource *output) + { +- new ColorManagementOutputV1(resource->client(), id, resource->version(), OutputInterface::get(output)->handle()); ++ new ColorManagementOutputV1(resource->client(), id, resource->version(), OutputInterface::get(output)); + } + + void ColorManagerV1::wp_color_manager_v1_get_surface(Resource *resource, uint32_t id, struct ::wl_resource *surface) +@@ -574,12 +574,15 @@ ImageDescriptionV1 *ImageDescriptionV1::get(wl_resource *resource) + } + } + +-ColorManagementOutputV1::ColorManagementOutputV1(wl_client *client, uint32_t id, uint32_t version, Output *output) ++ColorManagementOutputV1::ColorManagementOutputV1(wl_client *client, uint32_t id, uint32_t version, OutputInterface *output) + : QtWaylandServer::wp_color_management_output_v1(client, id, version) + , m_output(output) +- , m_colorDescription(output->colorDescription()) + { +- connect(output, &Output::colorDescriptionChanged, this, &ColorManagementOutputV1::colorDescriptionChanged); ++ if (m_output->isRemoved()) { ++ return; ++ } ++ ++ connect(output->handle(), &Output::colorDescriptionChanged, this, &ColorManagementOutputV1::colorDescriptionChanged); + } + + void ColorManagementOutputV1::wp_color_management_output_v1_destroy_resource(Resource *resource) +@@ -594,12 +597,19 @@ void ColorManagementOutputV1::wp_color_management_output_v1_destroy(Resource *re + + void ColorManagementOutputV1::wp_color_management_output_v1_get_image_description(Resource *resource, uint32_t image_description) + { +- new ImageDescriptionV1(resource->client(), image_description, resource->version(), m_colorDescription); ++ if (!m_output || m_output->isRemoved()) { ++ new ImageDescriptionV1(resource->client(), image_description, resource->version(), std::nullopt); ++ } else { ++ new ImageDescriptionV1(resource->client(), image_description, resource->version(), m_output->handle()->colorDescription()); ++ } + } + + void ColorManagementOutputV1::colorDescriptionChanged() + { +- m_colorDescription = m_output->colorDescription(); ++ if (!m_output || m_output->isRemoved()) { ++ return; ++ } ++ + send_image_description_changed(); + } + +diff --git a/src/wayland/colormanagement_v1.h b/src/wayland/colormanagement_v1.h +index 2cdb3b505c..b499a30131 100644 +--- a/src/wayland/colormanagement_v1.h ++++ b/src/wayland/colormanagement_v1.h +@@ -14,8 +14,8 @@ namespace KWin + { + + class Display; ++class OutputInterface; + class SurfaceInterface; +-class Output; + + class ColorManagerV1 : public QObject, private QtWaylandServer::wp_color_manager_v1 + { +@@ -125,7 +125,7 @@ class ColorManagementOutputV1 : public QObject, private QtWaylandServer::wp_colo + { + Q_OBJECT + public: +- explicit ColorManagementOutputV1(wl_client *client, uint32_t id, uint32_t version, Output *output); ++ explicit ColorManagementOutputV1(wl_client *client, uint32_t id, uint32_t version, OutputInterface *output); + + private: + void colorDescriptionChanged(); +@@ -133,8 +133,7 @@ private: + void wp_color_management_output_v1_destroy(Resource *resource) override; + void wp_color_management_output_v1_get_image_description(Resource *resource, uint32_t image_description) override; + +- Output *const m_output; +- ColorDescription m_colorDescription; ++ QPointer m_output; + }; + + } +-- +2.55.0 +