Commit Graph
1 Commits
Author SHA1 Message Date
0x1f6andClaude Opus 5.5 9c2fccf0a0 Survive a malformed control datagram
One bad datagram on the control socket ended the whole relay. Its
dispatch in handle_control ran unguarded in the main loop, so any
exception propagated out of main() and the process exited. The simplest
trigger is "watch abc": float(words[1]) raises ValueError, and the relay
died with

    ValueError: could not convert string to float: 'abc'
      at handle_control, via the bare handle_control(now) call in the
      select loop

The control socket is an abstract socket bound to @frametop_relay.
Abstract sockets carry no permissions, so every local process can send
to it; nothing authenticates the sender. Dying from a datagram was bad
in three ways:

- Every grab is lost. Physical devices go back to gamescope and SteamVR,
  which read them themselves, so the mouse types into Steam and the
  desktop at once, and Meta+Shift shortcuts fire on both sides.
- The volume-key takeover is lost. gamescope aborts on a volume key when
  no window has keyboard focus (wlr_seat_keyboard_notify_enter asserts on
  a null focus surface), which ends the whole VR session - the exact
  failure the relay exists to prevent.
- systemd restarts the service, but Type=notify with READY only after
  the virtual devices exist makes the restart a visible hiccup, and a
  crash loop from repeated bad datagrams would flap SteamVR's input.

Reproduced by running the relay with stubbed uinput devices on a
non-Linux host and sending "watch abc" to the control socket: it exited
on the first datagram after answering "devices" correctly. After the
fix, the same exchange gets a log line ("bad control datagram ...") and
the relay keeps answering.

The fix wraps each datagram's dispatch in try/except inside
handle_control's loop, so one malformed message is logged and skipped
while the rest of the queue is still processed. Parsing of the common
helper commands (vrbtn, vrhello, gazeawake, keyboard) keeps its own
guards; the catch-all is only a backstop for anything the guards miss,
including float() on a non-numeric argument to "watch" and "vrcapture".

Adapted for experimental (from PR #8): the guard also wraps the textfield
command, which experimental added to this dispatch after the PR's base.

(cherry picked from commit ca7e58069b)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-01 09:34:12 -06:00