gtk: limit direct module paths to GTK_PATH

This commit is contained in:
Daemonratte 2026-05-15 15:34:32 +02:00
commit 55d5543eed

View file

@ -51,6 +51,8 @@ static gboolean default_display_opened = FALSE;
static gint gtk_argc = 0;
static gchar **gtk_argv = NULL;
static gint module_path_env_dirs = 0;
static gchar **
split_file_list (const gchar *str)
{
@ -191,6 +193,23 @@ get_module_path (void)
g_free (default_dir);
result = split_file_list (module_path);
if (module_path_env)
{
gchar **env_paths;
gchar **path;
env_paths = split_file_list (module_path_env);
module_path_env_dirs = 0;
for (path = env_paths; *path; path++)
module_path_env_dirs++;
g_strfreev (env_paths);
}
else
module_path_env_dirs = 0;
g_free (module_path);
return result;
@ -221,6 +240,9 @@ _gtk_get_module_path (const gchar *type)
for (path = get_module_path (); *path; path++)
{
gint use_version, use_host;
gboolean path_from_env;
path_from_env = (path - paths) < module_path_env_dirs;
for (use_version = TRUE; use_version >= FALSE; use_version--)
for (use_host = TRUE; use_host >= FALSE; use_host--)
@ -245,10 +267,11 @@ _gtk_get_module_path (const gchar *type)
* live directly in .../.libs directories, for example print backends,
* theme engines or input modules.
*
* Keep this limited to absolute paths so the removed fallback that could
* load modules from the current working directory is not reintroduced.
* Keep this limited to absolute GTK_PATH entries so the removed fallback
* that could load modules from the current working directory is not
* reintroduced for built-in default paths.
*/
if (g_path_is_absolute (*path))
if (path_from_env && g_path_is_absolute (*path))
result[count++] = g_strdup (*path);
}