Thank you for your contribution! Sashiko AI review found 1 potential issue(s) 
to consider:
- [Low] vt: unprivileged log injection via pr_warn_once in cursor sizing
--

commit 4874174842fbef217a6215957d5bf1bff1442b36
Author: Thomas Zimmermann <[email protected]>

vt: Add cursor-size helpers

The new helpers vc_cursor_start() and vc_cursor_end() return the scanlines
in which the cursor block starts respectively ends. Users can control the
cursor size with the vt module's parameter cur_default or with the ESC
sequence \e[?Nc. In case of an invalid setting, the new helpers fall back
to cur_default and then underline cursors.

> diff --git a/drivers/tty/vt/vt.c b/drivers/tty/vt/vt.c
> index 57edf37495a81..8141296ccad05 100644
> --- a/drivers/tty/vt/vt.c
> +++ b/drivers/tty/vt/vt.c

[ ... ]

> @@ -264,6 +265,109 @@ unsigned int vc_font_size(const struct vc_font *font)
>  }
>  EXPORT_SYMBOL_GPL(vc_font_size);
>  
> +/*
> + * Cursors
> + */
> +
> +static unsigned int vc_cursor_size(unsigned int cursor_size)
> +{
> +     const unsigned int cursor_default_size = 
> CUR_SIZE(READ_ONCE(cur_default));
> +
> +retry:
> +     switch (cursor_size) {
> +     case CUR_NONE:
> +     case CUR_UNDERLINE:
> +     case CUR_LOWER_THIRD:
> +     case CUR_LOWER_HALF:
> +     case CUR_TWO_THIRDS:
> +     case CUR_BLOCK:
> +             return cursor_size;
> +     default:
> +             pr_warn_once("Unknown cursor %u\n", cursor_size);
> +             fallthrough;

[Severity: Low]
Is it expected that an unprivileged user can trigger this warning message?

An unprivileged user can write a specific DEC escape sequence (e.g.,
\e[?103c) to the VT, which parses an unhandled size into
vc->vc_cursor_type via CSI_MAKE.

When the console driver later updates the cursor, vc_cursor_size() hits
the default case and emits this warning.

Since pr_warn_once() is rate-limited to once per boot, it cannot cause
a denial of service, but it still allows local unprivileged users with
write access to a VT to add a warning line to the kernel log.

> +     case CUR_DEF:
> +             /*
> +              * Use user-given default size, or underline if
> +              * the given default is invalid.
> +              */
> +             if (cursor_size != cursor_default_size)
> +                     cursor_size = cursor_default_size;
> +             else
> +                     cursor_size = CUR_UNDERLINE;
> +             goto retry;
> +     }
> +}

[ ... ]

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/[email protected]?part=1

Reply via email to