Re: Breakage from patch: Only root should be able to set the N_MOUSE line discipline.

From: Vojtech Pavlik
Date: Tue Mar 01 2005 - 06:47:00 EST


On Sat, Feb 26, 2005 at 11:20:44AM +0000, Alan Cox wrote:

> On Gwe, 2005-01-28 at 16:12, Linux Kernel Mailing List wrote:
> > ChangeSet 1.1977.1.2, 2005/01/28 17:12:20+01:00, vojtech@xxxxxxx
> >
> > input: Only root should be able to set the N_MOUSE line discipline.
> >
>
> I finally had a chance to trace down why my mouse code for a little gui
> library started working differently and causing problems. This broken
> change breaks apps that use framebuffer in unpriviledged process form
> and want to use the mouse support in kernel and forces them to become
> setuid root or to revert to 2.4 style user space mouse drivers. If this
> functonality is root only kernel space it might as well be entirely
> deleted IMHO.
>
> I can see no reason for this change - the ldisc is supposed to be
> configurable by non root users. It is reset on close/hangup in Linux so
> a user cannot jam a port up.
>
> Can someone please justify this change. If not can it be reverted

A nonprivileged user could inject mouse movement and/or keystrokes
(using the sunkbd driver) into the input subsystem, taking over the
console/X, where another user is logged in.

Simply using a slightly modified inputattach on a PTY will do the trick.

--
Vojtech Pavlik
SuSE Labs, SuSE CR
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/