Skip to content

v0.5.12 — What the window shows is data, not markup

Choose a tag to compare

@blessdyb blessdyb released this 01 Oct 07:58
· 13 commits to main since this release
4515b21

Found by opening the window on a real desktop, which this project had never done.

The bug, seen in situ

200 · 511 B              wget · pid 24142 · 1m ago
GET www.kernel.org/      wget · pid 24142 · 1m ago
GET api.github.com/zen   python3.12 · pid 24141 · 1m ago
                         firefox · pid 9886 · 3m ago      ← no request at all

That last row is Firefox asking merino.services.mozilla.com/api/v1/suggest?q=&providers=accuweather&…. libadwaita parses a row's title and subtitle as Pango markup unless it is told otherwise, and every row here carries text that came off the network. A query string with two parameters was enough to make the row empty.

The window had been saying so in its own log the whole time, once anybody looked:

Gtk-WARNING: Failed to set text '…' from markup due to error parsing markup: Entity did not end with
a semicolon; most likely you used an ampersand character without intending to start an entity

The half that is worse than a blank row

<span foreground="white"> in a path would have been rendered rather than shown. The window's own text was something a visited URL could write — in a program whose entire purpose is to say truthfully what a machine did.

The fix

Every row says its text is not markup, and so does the banner that carries error strings. Both setters are available at this project's libadwaita floor: v1_2 for rows, v1_3 for the banner, against the v1_5 already required for AlertDialog.

CI counts them — thirty-two rows, thirty-two declarations — and fails if those numbers ever differ. A grep is a blunt instrument, and the invariant is exactly "every row that carries data says so", which is what it checks.

One thing that is not this program's fault, written down anyway

On the machine this was found on, the window first drew its header bar and nothing else, which looks exactly like a program with nothing to say. It is GTK 4 rendering with the GPU on a machine whose GL is broken — MESA: error: ZINK: failed to choose pdev. GSK_RENDERER=cairo flowlight renders in software and shows everything, and the README now says so.

What else that session confirmed

v0.5.11's --socket-owner works where it was meant to: under the systemd unit the socket becomes the person's (srw------- blessdyb blessdyb) and the window connects, where before it was root's and the kernel refused. The window then shows real traffic, attributed, with byte counts and ages — which is the first time anybody has seen this program draw.