Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
406 commits
Select commit Hold shift + click to select a range
f076afd
reduce diff to upstream. no functional change.
Nov 22, 2016
b48dd83
fix tpyo - now fallback to ARGB masks when rendering glyphs actually …
Dec 22, 2016
9426796
back out previous - can be worked around elsewhere
Dec 28, 2016
3af688f
Fix -O0 build; <machine/bwx.h> should be included after ".arch ev56" …
Feb 20, 2017
e0d56af
apply
Mar 8, 2017
75bca22
apply
Mar 8, 2017
7add136
apply
Mar 8, 2017
896f471
CVE-2017-10971 and CVE-2017-10972: apply fixes to the event loop from
Jul 7, 2017
1bb5e67
make this build on netbsd.
Aug 5, 2017
4f8aa42
apply fixes for CVEs 2017-12176 to 2017-12187.
Nov 4, 2017
fe23e74
Fix compile error on evbarm-aarch64. (incompatible pointer types init…
Apr 3, 2018
bf8f17a
Don't error if we are unprivileged
Oct 26, 2018
23e7007
Initial revision
Dec 31, 2018
e0010db
merge xorg-server 1.20.3.
Dec 31, 2018
d163d6c
use xf86AddMatchedDriver().
Dec 31, 2018
efd3525
s/inclue/include/ in an error message.
Dec 31, 2018
25c6ec4
s/pointer/void */ in a few places. remove now (void *) casts.
Jan 1, 2019
eb011f7
make the intel driver work again with xorg-server 1.20:
Jan 3, 2019
c63d722
Undo unnecessary diff to vendor branch.
Jan 10, 2019
1d568d3
pEnt isn't initialized at this point, don't free it
Jan 10, 2019
24de51b
Undo merge botch, duplicate length checks
Jan 10, 2019
2790345
Remove duplicate length check (undo diff to upstream)
Jan 10, 2019
c3f329b
protect dup typedef.
Jan 22, 2019
956fa61
Avoid dup inconsistent definitions.
Jan 23, 2019
b07902c
Try the modesetting driver before wsfb on NetBSD arm and aarch64
Jan 28, 2019
d4d486e
Initial revision
Mar 3, 2019
3c61e37
merge xorg-server 1.20.4.
Mar 3, 2019
6c639ff
fix variable stack allocation for ssp
May 15, 2019
121cc40
Undo local diff.
May 31, 2019
b4807cb
merge xorg-server 1.20.5.
Jun 1, 2019
b57c242
Match wsfb on x86, too.
Aug 30, 2019
f75af88
Try modesetting on x86, too.
Aug 30, 2019
080dbc1
Try wsfb before vesa on x86. Modern video cards may not support VBE a…
Feb 9, 2020
dbf1d2f
Don't autoload vesa on x86 at all as it conflicts with wsfb.
Feb 9, 2020
acfc2ab
Revert previous two commits, will fix this another way.
Feb 9, 2020
70e6898
merge xorg-server 1.20.6.
Feb 23, 2020
d5a1564
Remove clause 3 and 4 from X68k server files written by Yasushi Yamas…
Apr 10, 2020
7fdc947
Pull changes of x68kInit.c rev 1.3 from xorg-server.old.
Jul 18, 2020
9803409
Update for removal of AddEnabledDevice and RemoveEnabledDevice.
Jul 18, 2020
a07e46d
Add a stub for miinitext of GLX.
Jul 18, 2020
1722b3d
Pull 1bpp server fixes from xorg-server.old:
Jul 18, 2020
0228ebf
Sync with xorg-server.old: Remove #ifdef XKB conditional.
Jul 19, 2020
29aca35
Import WIP Xorg-Server-1.20'fied monolithic Xsun servers.
Jul 22, 2020
352c6c5
Normalize #include paths.
Jul 22, 2020
6a2bcef
Use proper ANSI offsetof(3) to specify framebuffer offset in struct.
Jul 23, 2020
8d4f069
Apply upstream "free the EQ allocated memory on shutdown" fixes.
Jul 24, 2020
ce788d3
Use proper args for dixLookupResourceByType() to get defcolormap.
Jul 24, 2020
611d1bf
Add prototype declarations for CG2 functions.
Jul 26, 2020
67a425f
Implement functions to restore palette settings on exiting Xserver.
Jul 26, 2020
c5f2e5d
Explicitly initialize origColormapValid for readability.
Jul 26, 2020
06aac9a
Fix LED defintions to match xkb/xkbInit.c.
Jul 29, 2020
92c6f28
Remove unused functions required to handle non-XKB autorepeat.
Jul 29, 2020
9537a20
Initialize ModMap dynamically using keymap data per each keyboard.
Jul 30, 2020
98ddd6e
Remove now unused ModMap data for each keyboard.
Jul 30, 2020
6675653
Backport the only patch from xorg-server 1.20.9 as I can't find a tar…
Jul 31, 2020
37775b6
Use "empty" for rmlvo model and layout to avoid lingering default set…
Aug 1, 2020
e09bd01
Trailing whitespace.
Aug 1, 2020
389a2a8
TAB/space cleanup.
Aug 1, 2020
eccafc4
Replace 'pointer' type with 'void *' to sync with upstream manner.
Aug 1, 2020
f86ac3e
Call LogInit() for logging to /var/log/Xsun.%s.log as Xorg server.
Aug 4, 2020
df55e0d
Inform detected keyboard type and layout via LogMessage().
Aug 9, 2020
5ed36d1
Remove a leftover variable for non-XKB autorepeat.
Aug 9, 2020
d058958
Remove redundant command option arg checks.
Aug 9, 2020
ee9d323
Put probed framebuffer info to a log file by default.
Aug 9, 2020
61c7891
Revert upstream "fb: Remove even/odd tile slow-pathing" changes.
Aug 9, 2020
9c8d4ca
Remove more redundant command option arg checks.
Aug 11, 2020
50f616d
Avoid dumb DevicePtr casts.
Aug 13, 2020
a31b647
Call LogInit() for logging to /var/log/X68k.%s.log as Xorg and Xsun s…
Nov 1, 2020
4024a9b
Fix a suspicious chunk disabled on xfree 4.x migration as sunKbd.c does.
Nov 1, 2020
ba789f9
Restore video mode properly on exit even on CRT Mode 19 (640x480 31kH…
Nov 3, 2020
6f63df9
Add ModeDef for 640x480x4bit PseudoColor.
Nov 3, 2020
e93d6c3
Avoid a use of __UNVOLATILE(3). Tested on XM6i.
Nov 3, 2020
d2c1e0f
Remove unnecessary pointer casts from malloc(3).
Nov 3, 2020
f0a31a9
Use exact-width interger types properly for register accesses etc.
Nov 4, 2020
7403266
Fix typo in comment.
Nov 13, 2020
65ea705
Report which settings are chosen per a config file in the log file.
Nov 16, 2020
34b7704
valuator_mask_zero() is enough for mouse button events.
Nov 20, 2020
fa8ec02
valuator_mask_zero() is enough for mouse button events.
Nov 21, 2020
367ae89
merge xorg-server 1.20.10.
Dec 5, 2020
0e4138e
add dummy ddxInputThreadInit() if INPUTTHREAD is defined.
Dec 8, 2020
84ab2dd
Add "Emulate3Buttons" support to the X68k Xorg based monolithic server.
Feb 7, 2021
b10b8b3
ErrorF() doesn't append newlines at the end of messages.
Mar 11, 2021
8cd2cfc
ErrorF() doesn't append newlines at the end of messages.
Mar 11, 2021
57be5db
Avoid polluting console on non-fatal errors.
Mar 11, 2021
cbb8f62
Fixes "FatalError re-entered, aborting" error when Xservers get SIGSEGV.
Mar 17, 2021
05c6b57
Explicitly include dix-config.h for HAVE_foo definitions referred in …
Mar 22, 2021
97346b1
Initial revision
Apr 27, 2021
4269df4
merge xorg-server 1.20.11.
Apr 27, 2021
fd6079c
Avoid multiple definitions of the same variable.
May 31, 2021
f8f2103
Provide canonical declaration of IOPortBase for MIPS here, too.
Jun 2, 2021
85be7ad
use PORT_SIZE from compiler.h instead of int.
Jul 2, 2021
2a0a2de
Add missing include of compiler.h and make all declarations of
Jul 3, 2021
1f56359
elide cast warning: error: cast from pointer to integer of different …
Jul 4, 2021
6800398
merge xorg-server 1.20.12 and xkeyboard-config 2.33.
Jul 11, 2021
42f78fc
merge xorg-server 1.20.13.
Aug 23, 2021
a1ac805
Switch to xf86-input-ws for mouse by default, to allow more advanced
Sep 28, 2021
9637b97
Handle restoring keyboard state via AbortDevices() rather than AbortD…
Oct 15, 2021
3eb173e
recognize Southland Media MGX
Oct 22, 2021
009bf04
Follow the error path if asprintf fails, not if it succeeds.
Dec 5, 2021
c5ee61d
Initial revision
Jul 15, 2022
93ae20f
merge xorg-serer 21.1.3.
Jul 15, 2022
a1af363
fix merge botch.
Jul 15, 2022
b1496b1
use "1ULL << 32" for a 64 bit member, not 1UL.
Jul 15, 2022
961ebe5
make this actually build again on arm/mips.
Jul 15, 2022
3c0f476
Initial revision
Jul 15, 2022
6a206d1
merge xorg-server 21.1.4.
Jul 15, 2022
f63efac
couple of changes needed for xorg-server 21.1.4.
Jul 15, 2022
28ce460
Merge AbortDDX() into ddxGiveUp() as other upstream DDX servers.
Jul 16, 2022
35373f3
use PRIu64 and hopefully fix some clang builds.
Jul 20, 2022
7c74562
Restore -flipPixels option removed in upstream server-21.1-branch.
Jul 30, 2022
9bcc12c
Pull an upstream (post-21.1) fix for xf86CompatOutput().
Jul 30, 2022
55c5481
avoid variable stack arrays.
Aug 12, 2022
fc4420f
Initial revision
Dec 19, 2022
aa8ae19
merge xorg-server 1.21.1.5
Dec 19, 2022
2bd6703
fix a couple of merge botches (duplicated) delete #if 0'd sections.
Dec 19, 2022
f48fe14
merge xorg-server 21.1.6.
Jan 8, 2023
a4c15ea
merge xorg-server 21.1.7.
Feb 7, 2023
be695a6
merge xorg-server 21.1.8.
Mar 30, 2023
199f396
merge xorg-server 21.1.9.
Oct 25, 2023
af6c252
xf86-video-wsfb: Add support for 16 color mode on Amiga
Mar 25, 2024
485feda
make sure we fill in the name field in generated / converted modes
Jun 10, 2024
43b4fbf
fix build on alpha.
Jun 21, 2024
5014f94
merge xorg-server 21.1.13.
Jul 4, 2024
9aaf19f
merge xorg-server 21.1.14.
Oct 30, 2024
8be5bf2
merge xorg-server 21.1.16.
Feb 26, 2025
6534022
Properly apply DIX locking to input events in NetBSD-specific DDX ser…
Jun 17, 2025
4ab6b14
Initialize DDX pointer valuators consistently with other drivers/serv…
Jun 17, 2025
da44543
Refactor Xsun input device handling to remove SIGIO based event proce…
Jun 21, 2025
abf6dfe
Reduce global references to sunPtrPriv, as sunKbd.c does.
Jun 21, 2025
dc64381
Refactor sunPtrPrivRec in sunMouse.c to make it really private.
Jun 21, 2025
a8a1350
Also Refactor sunKbdPrivRec in sunKbd.c to make it private.
Jun 21, 2025
651d1a9
Replace old FNDELAY for fcntl(2) with O_NONBLOCK defined in POSIX.
Jun 21, 2025
875930b
Allocate keyboard and mouse event buffers in the device private struc…
Jun 21, 2025
8d14caf
Add and sort static function declarations in sunKbd.c.
Jun 21, 2025
812559e
Add a static function declaration in sunMouse.c.
Jun 21, 2025
7b0f3f2
Remove unused variables.
Jun 21, 2025
61888b5
No need to check if the device is enabled in event handler functions.
Jun 21, 2025
57a268b
Make sure the keyboard device is actually enabled in DDXRingBell().
Jun 21, 2025
7b63925
Use consistent name for DeviceIntPtr variables among keyboard and mouse.
Jun 22, 2025
4ad2e44
Refactor X68k input device handling to remove SIGIO based event proce…
Jun 22, 2025
2a73b30
Reduce references to x68kKbdPriv and x68kMousePriv for readability.
Jun 22, 2025
437a25d
Allocate X68kMousePriv dynamically to avoid static buffers.
Jun 22, 2025
8f0e0af
Allocate X68kKbdPriv dynamically to make it really private.
Jun 22, 2025
34890f3
Allocate keyboard and mouse event buffers in the device private struc…
Jun 22, 2025
005c252
Make sure the keyboard device is actually enabled in DDXRingBell().
Jun 22, 2025
9750c91
merge xorg-server 21.1.18.
Jun 24, 2025
2231425
Make sure to initialize default XKB rules earlier for Core Keyboard.
Jun 24, 2025
fa317d1
Register XFree86 DDX specific "XFree86_VT" Atom to appease xinit(1).
Jun 24, 2025
b5cded0
Initial revision
Nov 12, 2025
dfcb318
merge xorg-server 21.1.20.
Nov 12, 2025
b0fb6c5
merge xorg-server 21.1.21.
Dec 9, 2025
8df7e0c
Enshrine NetBSD work and nuke spineless corporate boilerplate
HaplessIdiot Mar 1, 2026
8baf823
Remove incorrect year information
HaplessIdiot Mar 1, 2026
9c500e7
Remove incorrect year information
HaplessIdiot Mar 1, 2026
f931bae
Remove incorrect year information
HaplessIdiot Mar 1, 2026
ec16e32
Make more broad stance against corporate its all a problem
HaplessIdiot Mar 1, 2026
062d894
Merge remote-tracking branch 'ssx/master'
HaplessIdiot Mar 8, 2026
88f71e5
Revert "Make more broad stance against corporate its all a problem"
HaplessIdiot Mar 8, 2026
e002021
Revert "Remove incorrect year information"
HaplessIdiot Mar 8, 2026
d823807
Revert "Remove incorrect year information"
HaplessIdiot Mar 8, 2026
0c99d42
Revert "Remove incorrect year information"
HaplessIdiot Mar 8, 2026
6191e2a
Revert "Enshrine NetBSD work and nuke spineless corporate boilerplate"
HaplessIdiot Mar 8, 2026
e96be2f
Swap readme.md for one that matches the project and enshrines XFree86…
HaplessIdiot Mar 8, 2026
cd11d51
Create SECURITY.md
HaplessIdiot Mar 9, 2026
3d64fcd
Create trajan.yaml
HaplessIdiot Mar 9, 2026
ca12ce7
Create ci.yaml
HaplessIdiot Mar 9, 2026
15c0263
Rename .github/ci.yaml to .github/workflows/ci.yaml
HaplessIdiot Mar 9, 2026
a65e927
Rename .github/trajan.yaml to .github/workflows/release.yaml
HaplessIdiot Mar 9, 2026
534465a
Create codeql.yml
HaplessIdiot Mar 9, 2026
21f15c9
Update codeql.yml
HaplessIdiot Mar 9, 2026
b6448e8
Update SECURITY.md
HaplessIdiot Mar 9, 2026
7ebca8d
Update codeql.yml
HaplessIdiot Mar 9, 2026
12de25f
Update codeql.yml
HaplessIdiot Mar 9, 2026
3c4507c
Update README.md
HaplessIdiot Mar 9, 2026
95466a2
Update ci.yaml
HaplessIdiot Mar 9, 2026
15b189c
Update ci.yaml
HaplessIdiot Mar 9, 2026
e44be66
Update ci.yaml
HaplessIdiot Mar 9, 2026
e355c58
Update ci.yaml
HaplessIdiot Mar 9, 2026
12919cd
Update ci.yaml
HaplessIdiot Mar 9, 2026
ae886d7
Update ci.yaml
HaplessIdiot Mar 9, 2026
2898c2a
Update ci.yaml
HaplessIdiot Mar 9, 2026
d1564fc
Update ci.yaml
HaplessIdiot Mar 9, 2026
d653f79
Update ci.yaml
HaplessIdiot Mar 9, 2026
b86b5f1
Update ci.yaml
HaplessIdiot Mar 9, 2026
4f422de
Update ci.yaml
HaplessIdiot Mar 9, 2026
f82b149
Update ci.yaml
HaplessIdiot Mar 9, 2026
12ebc63
Update ci.yaml
HaplessIdiot Mar 9, 2026
6379583
Update ci.yaml
HaplessIdiot Mar 9, 2026
2e5731a
Update ci.yaml
HaplessIdiot Mar 9, 2026
845dc51
Update ci.yaml
HaplessIdiot Mar 9, 2026
3e26ace
Update ci.yaml
HaplessIdiot Mar 9, 2026
58e9098
Update ci.yaml
HaplessIdiot Mar 9, 2026
881b6e6
Update ci.yaml
HaplessIdiot Mar 9, 2026
e691262
Update ci.yaml
HaplessIdiot Mar 9, 2026
5be5e0b
Update ci.yaml
HaplessIdiot Mar 9, 2026
0181a42
Update ci.yaml
HaplessIdiot Mar 9, 2026
63c92ec
Update ci.yaml
HaplessIdiot Mar 9, 2026
0ec04e8
Update ci.yaml
HaplessIdiot Mar 9, 2026
9ca1a6a
Update ci.yaml
HaplessIdiot Mar 9, 2026
1554d61
Update ci.yaml
HaplessIdiot Mar 9, 2026
5ff1579
Update codeql.yml
HaplessIdiot Mar 9, 2026
2f859d9
Create codeqlvanilla.yml
HaplessIdiot Mar 9, 2026
31186fe
Update codeqlvanilla.yml
HaplessIdiot Mar 9, 2026
3188510
Delete .github/workflows/codeqlvanilla.yml
HaplessIdiot Mar 9, 2026
afd0d50
Update SECURITY.md
HaplessIdiot Mar 9, 2026
98bfc7e
Update README.md
HaplessIdiot Mar 9, 2026
9933e8e
Update codeql.yml
HaplessIdiot Mar 9, 2026
52b8a1d
Create gcc.yml
HaplessIdiot Mar 9, 2026
22610ee
Update gcc.yml
HaplessIdiot Mar 9, 2026
f31629e
Update and rename ci.yaml to clang.yaml
HaplessIdiot Mar 9, 2026
e1ff535
restore vbe folder revert ajax b2de577f6388c6dd7a463e5cebb8b1366bb45d1f
HaplessIdiot Mar 9, 2026
c0f2560
restore xf86Build.sh with checkout on 23e70073f050c1a464e4d9ac318fa14…
HaplessIdiot Mar 10, 2026
f2b90aa
Update clang.yaml
HaplessIdiot Mar 10, 2026
e7df83a
Update gcc.yml
HaplessIdiot Mar 10, 2026
f3221bd
restore of FourCC headers from 23e70073f050c1a464e4d9ac318fa14778b89514
HaplessIdiot Mar 10, 2026
68566ac
Restored full CVT timing suite and utilities
HaplessIdiot Mar 10, 2026
0c4cc69
Restored core xf86cvt logic and headers
HaplessIdiot Mar 10, 2026
c615c6f
Restored full xfree86/modes folder from https://cgit.freedesktop.org/…
HaplessIdiot Mar 10, 2026
7992362
Merge pull request #1 from HaplessIdiot/master
HaplessIdiot Mar 10, 2026
22f67a3
Restore `hurd_mouse.c`
painter4supersonicx Mar 11, 2026
980f405
Try to update old hurd drivers to make sure they work with modern sys…
painter4supersonicx Mar 11, 2026
60e0247
Merge pull request #2 from supersonic-xserver/restorehurd1
HaplessIdiot Mar 11, 2026
7d20da5
Restore missing RAMDAC files
painter4supersonicx Mar 11, 2026
eb4a8ec
Merge pull request #3 from supersonic-xserver/restoreramdac1
HaplessIdiot Mar 11, 2026
37d9f40
Try to remove XWayland code
painter4supersonicx Mar 13, 2026
7b49ce0
Fix SlowBcopy support
painter4supersonicx Mar 13, 2026
f823eed
added amdgpu and modesetting as static driver with meson stuff
HaplessIdiot Mar 13, 2026
b8e666f
amdgpu meson fixes
HaplessIdiot Mar 13, 2026
982dc6f
amdgpu meson fixes
HaplessIdiot Mar 13, 2026
6b993f8
amdgpu meson fixes change drm_fourcc.h to sane fourcc.h
HaplessIdiot Mar 13, 2026
6f707dd
amdgpu meson fixes try to resolve unable to find fourcc.h
HaplessIdiot Mar 13, 2026
dd102ba
Merge pull request #6 from HaplessIdiot/master
HaplessIdiot Mar 13, 2026
9633484
Merge pull request #4 from supersonic-xserver/noxwayland
HaplessIdiot Mar 13, 2026
900daaa
Merge pull request #5 from supersonic-xserver/slowbcopyfixes
HaplessIdiot Mar 13, 2026
40b5d19
Potential fix for code scanning alert no. 139: Uncontrolled format st…
HaplessIdiot Mar 13, 2026
28e7779
Potential fix for code scanning alert no. 32: Non-constant format string
HaplessIdiot Mar 13, 2026
701c193
Potential fix for code scanning alert no. 1776: Use of potentially da…
HaplessIdiot Mar 13, 2026
56d3ea8
Potential fix for code scanning alert no. 16: Static array access may…
HaplessIdiot Mar 13, 2026
abffd05
Potential fix for code scanning alert no. 1461: Unbounded write
HaplessIdiot Mar 13, 2026
2aaa6ea
Merge pull request #9 from supersonic-xserver/alert-autofix-1776
HaplessIdiot Mar 13, 2026
163cd05
Merge pull request #8 from supersonic-xserver/alert-autofix-32
HaplessIdiot Mar 13, 2026
5073190
Apply patches used by GitHub Actions
painter4supersonicx Mar 14, 2026
5de3f1d
Remove patches used by GitHub actions
painter4supersonicx Mar 14, 2026
06f7dd0
Merge pull request #13 from supersonic-xserver/ghactionsfixes
HaplessIdiot Mar 14, 2026
2c02fcc
Merge pull request #7 from supersonic-xserver/alert-autofix-139
HaplessIdiot Mar 14, 2026
d74c7f0
Merge pull request #10 from supersonic-xserver/alert-autofix-16
HaplessIdiot Mar 14, 2026
0ee0a47
Merge pull request #12 from supersonic-xserver/alert-autofix-1461
HaplessIdiot Mar 14, 2026
5e53f8e
Potential fix for code scanning alert no. 28: Potential use after free
HaplessIdiot Mar 14, 2026
5140ef1
Merge pull request #14 from supersonic-xserver/alert-autofix-28
HaplessIdiot Mar 14, 2026
e8efeae
Update access.c with potential fix
HaplessIdiot Mar 14, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
50 changes: 50 additions & 0 deletions .github/SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,50 @@
# Super Sonic X Security Policy

The Super Sonic X project takes security seriously. If you discover any vulnerabilities, please bring them to our attention right away!

### How to Report a Security Vulnerability

Please **DO NOT** file a public issue to report a security vulberability, instead send your report privately to **legendarydood@gmail.com**. This will help ensure that any vulnerabilities that are found can be [disclosed responsibly](https://en.wikipedia.org/wiki/Responsible_disclosure) to any affected parties.

Include the following information:

1. **Vulnerability description**
- What did you observe, and why is it a concern?

2. **Steps to reproduce**
- Clear, step-by-step instructions
- Include specific configurations or inputs required

3. **System and environment details**
- OS version
- ssX version or commit hash
- Display manager, drivers, or hardware specifics

4. **Supporting data**
- Logs (in plain text)
- Core dumps (if available and safe to share)

5. **Impact analysis (if known)**
- Potential for remote or local exploitation
- Possible consequences (e.g. data exposure, privilege escalation, denial-of-service)

Please allow us ample time to validate and patch the issue before disclosing it publicly.

Feel free to privately message HaplessIdiot if the issue is of extreme importance.

We will get back to you as soon as possible.

## Supported Versions

| Version | Status |
| --------------- | ------------------------------------------------ |
| `master` branch | Supported and maintained |
| Tagged Releases | Recieves security updates, resources permitting |

Project versions that are currently being supported with security updates vary per project.
Please see specific project repositories for details.
If nothing is specified, only the latest major versions are supported.

---

We appreciate your help in keeping ssX safe for everyone. Let’s build something resilient, secure, and sonic.
74 changes: 74 additions & 0 deletions .github/workflows/clang.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,74 @@
name: Clang-Tidy on Clang + LLVM (OpenMandriva)
on:
push:
pull_request:

jobs:
clang-tidy:
runs-on: ubuntu-latest
container:
image: openmandriva/cooker
steps:
- name: Checkout repository
uses: actions/checkout@v4

- name: Install build dependencies
run: |
echo "max_parallel_downloads=10" >> /etc/dnf/dnf.conf
dnf install -y --setopt=protected_packages=bash,glibc,dnf \
task-c-devel clang clang-tools llvm lld meson ninja pkgconfig bison flex python3-mako \
xkbcomp xkbcomp-devel x11-font-util lib64udev-devel \
lib64xau-devel lib64xdmcp-devel gawk \
mesa-common-devel lib64gbm-devel lib64GL-devel lib64EGL_mesa-devel \
'pkgconfig(xproto)' 'pkgconfig(xtrans)' 'pkgconfig(xkbfile)' \
'pkgconfig(xfont2)' 'pkgconfig(nettle)' 'pkgconfig(libbsd)' \
'pkgconfig(dbus-1)' 'pkgconfig(xkbcommon)' 'pkgconfig(pixman-1)' \
'pkgconfig(epoxy)' 'pkgconfig(pciaccess)' 'pkgconfig(libdrm)' \
'pkgconfig(xshmfence)' 'pkgconfig(resourceproto)'

- name: Create .clang-tidy configuration
run: |
cat <<EOF > .clang-tidy
---
Checks: >
-*,
bugprone-*,
clang-analyzer-*,
performance-*,
portability-*,
-bugprone-reserved-identifier,
-bugprone-exception-escape,
readability-braces-around-statements,
readability-redundant-address-of,
readability-redundant-control-flow
WarningsAsErrors: 'bugprone-*,clang-analyzer-core.*'
...
EOF

- name: Configure with Meson
run: |
export CC=clang
export CXX=clang++

rm -rf builddir
meson setup builddir --buildtype=debug \
-Dxorg=true \
-Dglamor=true \
-Ddri3=true \
-Dhal=false \
-Dsecure-rpc=false \
-Dxephyr=false \
-Dxnest=false \
-Dxwin=false \
-Ddmx=false || (cat builddir/meson-logs/meson-log.txt && exit 1)

- name: Run clang-tidy
run: |
# The -p builddir uses the compile_commands.json Meson just made
run-clang-tidy -p builddir -header-filter='.*' -export-fixes=clang-tidy-fixes.yaml || true

- name: Upload clang-tidy results
uses: actions/upload-artifact@v4
with:
name: clang-tidy-report
path: clang-tidy-fixes.yaml
45 changes: 45 additions & 0 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
name: "CodeQL Advanced (Display Server Optimized)"

on:
workflow_dispatch:

jobs:
analyze:
name: Analyze C/C++
runs-on: self-hosted # Use my 5800X3D rig instead of the slow GitHub VM
permissions:
security-events: write
contents: read

steps:
- name: Checkout repository
uses: actions/checkout@v4

- name: Initialize CodeQL
uses: github/codeql-action/init@v3
with:
languages: c-cpp
# Use 'none' if you want a fast scan of all source files
# Use 'autobuild' if you want to ensure it compiles (more accurate but slower)
build-mode: none

# This is the "Magic Sauce" for ssX to prevent the 10MB SARIF error:
paths-ignore: |
- 'extras/**'
- 'fonts/**'
- 'doc/**'
- 'man/**'
- '**/test/**'
- '**/testing/**'
- '**/examples/**'

# We use security-extended rather than security-and-quality.
# Quality queries add thousands of "style" alerts that bloat the SARIF file.
queries: security-extended

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v3
with:
category: "/language:c-cpp"
# If the file is STILL too large, this flag can help compress diagnostics
upload: true
74 changes: 74 additions & 0 deletions .github/workflows/gcc.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,74 @@
name: Clang-Tidy on GCC + LLD (OpenMandriva)
on:
push:
pull_request:

jobs:
clang-tidy:
runs-on: ubuntu-latest
container:
image: openmandriva/cooker
steps:
- name: Checkout repository
uses: actions/checkout@v4

- name: Install build dependencies (GCC Edition)
run: |
echo "max_parallel_downloads=10" >> /etc/dnf/dnf.conf
dnf install -y --setopt=protected_packages=bash,glibc,dnf \
task-c-devel gcc gcc-c++ binutils meson ninja pkgconfig \
bison flex python3-mako xkbcomp xkbcomp-devel x11-font-util \
lib64udev-devel lib64xau-devel lib64xdmcp-devel gawk \
mesa-common-devel lib64gbm-devel lib64GL-devel lib64EGL_mesa-devel \
'pkgconfig(xproto)' 'pkgconfig(xtrans)' 'pkgconfig(xkbfile)' \
'pkgconfig(xfont2)' 'pkgconfig(nettle)' 'pkgconfig(libbsd)' \
'pkgconfig(dbus-1)' 'pkgconfig(xkbcommon)' 'pkgconfig(pixman-1)' \
'pkgconfig(epoxy)' 'pkgconfig(pciaccess)' 'pkgconfig(libdrm)' \
'pkgconfig(xshmfence)' 'pkgconfig(resourceproto)'

- name: Create .clang-tidy configuration
run: |
cat <<EOF > .clang-tidy
---
Checks: >
-*,
bugprone-*,
clang-analyzer-*,
performance-*,
portability-*,
-bugprone-reserved-identifier,
-bugprone-exception-escape,
readability-braces-around-statements,
readability-redundant-address-of,
readability-redundant-control-flow
WarningsAsErrors: 'bugprone-*,clang-analyzer-core.*'
...
EOF

- name: Configure with Meson (GCC)
run: |
export CC=gcc
export CXX=g++

rm -rf builddir
meson setup builddir --buildtype=debug \
-Dxorg=true \
-Dglamor=true \
-Ddri3=true \
-Dhal=false \
-Dsecure-rpc=false \
-Dxephyr=false \
-Dxnest=false \
-Dxwin=false \
-Ddmx=false || (cat builddir/meson-logs/meson-log.txt && exit 1)

- name: Run clang-tidy
run: |
# The -p builddir uses the compile_commands.json Meson just made
run-clang-tidy -p builddir -header-filter='.*' -export-fixes=clang-tidy-fixes.yaml || true

- name: Upload clang-tidy results
uses: actions/upload-artifact@v4
with:
name: clang-tidy-report
path: clang-tidy-fixes.yaml
92 changes: 92 additions & 0 deletions .github/workflows/release.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,92 @@
name: Release

on:
push:
branches: [main]

concurrency:
group: release
cancel-in-progress: false

permissions:
contents: write

jobs:
create-tag:
name: Create Tag
runs-on: ubuntu-latest
outputs:
version: ${{ steps.version.outputs.version }}
tag_created: ${{ steps.tag.outputs.tag_created }}

steps:
- name: Checkout code
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
fetch-depth: 0

- name: Fetch all tags
run: git fetch --tags --force

- name: Calculate version
id: version
run: |
NEW_VERSION=$(make -s version)
echo "New version: $NEW_VERSION"
echo "version=$NEW_VERSION" >> "$GITHUB_OUTPUT"

- name: Create and push tag
id: tag
run: |
git config user.name "github-actions[bot]"
git config user.email "github-actions[bot]@users.noreply.github.com"
git tag -a "${{ steps.version.outputs.version }}" -m "Release ${{ steps.version.outputs.version }}"
git push origin "${{ steps.version.outputs.version }}"
echo "tag_created=true" >> "$GITHUB_OUTPUT"
env:
GH_TOKEN: ${{ github.token }}

goreleaser:
name: GoReleaser
needs: [create-tag]
environment: production
runs-on: ubuntu-latest

steps:
- name: Checkout code
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
fetch-depth: 0
ref: ${{ needs.create-tag.outputs.version }}

- name: Set up Go
uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5
with:
go-version-file: 'go.mod'
cache: true

- name: Run GoReleaser
uses: goreleaser/goreleaser-action@e435ccd777264be153ace6237001ef4d979d3a7a # v6
with:
version: '~> v2'
args: release --clean
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

cleanup-on-failure:
name: Cleanup on Failure
needs: [create-tag, goreleaser]
if: failure() && needs.create-tag.outputs.tag_created == 'true'
runs-on: ubuntu-latest

steps:
- name: Checkout code
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4

- name: Delete release and tag
run: |
echo "Cleaning up failed release ${{ needs.create-tag.outputs.version }}"
gh release delete "${{ needs.create-tag.outputs.version }}" --yes || true
git push --delete origin "${{ needs.create-tag.outputs.version }}" || true
env:
GH_TOKEN: ${{ github.token }}
Loading
Loading