From db484d13c3bf7d527c0baa3b4ca7def54ec65d27 Mon Sep 17 00:00:00 2001 From: Cigydd Date: Mon, 15 Jun 2026 22:42:23 +0200 Subject: drivemount: fix crash when the icon theme changes DriveButton connects a "changed" handler to the global default GtkIconTheme but drive_button_dispose() never disconnected it. The icon theme outlives the button, so after a button is destroyed (a volume or mount is removed) a later "changed" emission runs the handler on freed memory and schedules drive_button_update() via an idle source, crashing the panel with a use-after-free. Disconnect the handler in drive_button_dispose(). Assisted-by: Claude:claude-opus-4.8 --- drivemount/src/drive-button.c | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/drivemount/src/drive-button.c b/drivemount/src/drive-button.c index d33600f0..80f4b7ce 100644 --- a/drivemount/src/drive-button.c +++ b/drivemount/src/drive-button.c @@ -144,6 +144,15 @@ drive_button_dispose (GObject *object) { DriveButton *self = DRIVE_BUTTON (object); + /* The "changed" handler was connected to the process-global default icon + * theme (see drive_button_new / drive_button_new_from_mount), which + * outlives this button. If we don't disconnect it, the theme keeps a + * dangling pointer to the freed button and a later "changed" emission + * schedules drive_button_update() on freed memory -> use-after-free crash. */ + g_signal_handlers_disconnect_by_func (gtk_icon_theme_get_default (), + G_CALLBACK (drive_button_theme_change), + self); + drive_button_set_volume (self, NULL); if (self->update_tag) -- cgit v1.2.1