Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
For bugs related to Red Hat Enterprise Linux 4 product line. The current stable release is 4.9. For Red Hat Enterprise Linux 6 and above, please visit Red Hat JIRA https://issues.redhat.com/secure/CreateIssue!default.jspa?pid=12332745 to report new issues.

Bug 649811

Summary: Integer overflow for dashed lines longer than 46340
Product: Red Hat Enterprise Linux 4 Reporter: Olivier Fourdan <ofourdan>
Component: xorg-x11-serverAssignee: Adam Jackson <ajax>
Status: CLOSED WONTFIX QA Contact: desktop-bugs <desktop-bugs>
Severity: medium Docs Contact:
Priority: low    
Version: 4.8CC: kem
Target Milestone: rcKeywords: Patch, Triaged
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: 649809 Environment:
Last Closed: 2012-06-20 16:03:22 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 649809    
Bug Blocks: 649810    
Attachments:
Description Flags
Reproducer program
none
Proposed patch none

Description Olivier Fourdan 2010-11-04 15:54:13 UTC
Created attachment 457835 [details]
Reproducer program

+++ This bug was initially created as a clone of Bug #649809 +++

Description of problem:

Lines of length greater than 46340 can be drawn with one of the coordinates being negative. However for dashed lines, miPolyBuildPoly() overflows the "int" type when setting up edges for a section of the dashed line. This results in the dashed segments not being drawn at all.

Version-Release number of selected component (if applicable):

xorg-x11-6.8.2-1.EL.63

How reproducible:

Always

Steps to Reproduce:

1. Save attached reproducer program as line.c
2. Build the rproducer program with
   $ gcc -DBREAK -o line line.c -lX11
3. Run the test program in X11
   $ ./line
4. Right-click within the window created by the test application
  
Actual results:

No dotted line is displayed

Expected results:

A dotted line is shown

Additional info:

Remove the "-DBREAK"  from step #2 to get the expected result. The difference is that defining BREAK sets y2 to 31341 causing the overflow.

This has been reported upstream as bug 31093:

  https://bugs.freedesktop.org/show_bug.cgi?id=31093

The patch proposed by Siddhesh Poyarekar has been reviewed by Keith Packard:

  http://lists.x.org/archives/xorg-devel/2010-October/014559.html

Comment 1 Olivier Fourdan 2010-11-04 15:55:12 UTC
Created attachment 457836 [details]
Proposed patch

Patch by Siddhesh Poyarekar proposed in upstream bug fd.o #31093

Comment 2 RHEL Program Management 2010-11-04 15:58:11 UTC
This request was evaluated by Red Hat Product Management for
inclusion in the current release of Red Hat Enterprise Linux.
Because the affected component is not scheduled to be updated in the
current release, Red Hat is unfortunately unable to address this
request at this time. Red Hat invites you to ask your support
representative to propose this request, if appropriate and relevant,
in the next release of Red Hat Enterprise Linux.

Comment 3 Matěj Cepl 2010-11-13 19:32:11 UTC
Yes, can perfectly reproduce as with other RHEL versions.

Comment 4 Jiri Pallich 2012-06-20 16:03:22 UTC
Thank you for submitting this issue for consideration in Red Hat Enterprise Linux. The release for which you requested us to review is now End of Life. 
Please See https://access.redhat.com/support/policy/updates/errata/

If you would like Red Hat to re-consider your feature request for an active release, please re-open the request via appropriate support channels and provide additional supporting details about the importance of this issue.