Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider: - [Low] vt: unprivileged log injection via pr_warn_once in cursor sizing --
commit 4874174842fbef217a6215957d5bf1bff1442b36 Author: Thomas Zimmermann <[email protected]> vt: Add cursor-size helpers The new helpers vc_cursor_start() and vc_cursor_end() return the scanlines in which the cursor block starts respectively ends. Users can control the cursor size with the vt module's parameter cur_default or with the ESC sequence \e[?Nc. In case of an invalid setting, the new helpers fall back to cur_default and then underline cursors. > diff --git a/drivers/tty/vt/vt.c b/drivers/tty/vt/vt.c > index 57edf37495a81..8141296ccad05 100644 > --- a/drivers/tty/vt/vt.c > +++ b/drivers/tty/vt/vt.c [ ... ] > @@ -264,6 +265,109 @@ unsigned int vc_font_size(const struct vc_font *font) > } > EXPORT_SYMBOL_GPL(vc_font_size); > > +/* > + * Cursors > + */ > + > +static unsigned int vc_cursor_size(unsigned int cursor_size) > +{ > + const unsigned int cursor_default_size = > CUR_SIZE(READ_ONCE(cur_default)); > + > +retry: > + switch (cursor_size) { > + case CUR_NONE: > + case CUR_UNDERLINE: > + case CUR_LOWER_THIRD: > + case CUR_LOWER_HALF: > + case CUR_TWO_THIRDS: > + case CUR_BLOCK: > + return cursor_size; > + default: > + pr_warn_once("Unknown cursor %u\n", cursor_size); > + fallthrough; [Severity: Low] Is it expected that an unprivileged user can trigger this warning message? An unprivileged user can write a specific DEC escape sequence (e.g., \e[?103c) to the VT, which parses an unhandled size into vc->vc_cursor_type via CSI_MAKE. When the console driver later updates the cursor, vc_cursor_size() hits the default case and emits this warning. Since pr_warn_once() is rate-limited to once per boot, it cannot cause a denial of service, but it still allows local unprivileged users with write access to a VT to add a warning line to the kernel log. > + case CUR_DEF: > + /* > + * Use user-given default size, or underline if > + * the given default is invalid. > + */ > + if (cursor_size != cursor_default_size) > + cursor_size = cursor_default_size; > + else > + cursor_size = CUR_UNDERLINE; > + goto retry; > + } > +} [ ... ] -- Sashiko AI review ยท https://sashiko.dev/#/patchset/[email protected]?part=1
