Re: [PATCH] TIOCSTI: always enable for CAP_SYS_ADMIN

From: Jiri Slaby
Date: Thu Jul 13 2023 - 02:02:00 EST


On 10. 07. 23, 2:26, Samuel Thibault wrote:
83efeeeb3d04 ("tty: Allow TIOCSTI to be disabled") broke BRLTTY's
ability to simulate keypresses on the console, thus effectively breaking
braille keyboards of blind users.

This restores the TIOCSTI feature for CAP_SYS_ADMIN processes, which
BRLTTY is, thus fixing braille keyboards without re-opening the security
issue.

Signed-off-by: Samuel Thibault <samuel.thibault@xxxxxxxxxxxx>
Acked-by: Kees Cook <keescook@xxxxxxxxxxxx>
Fixes: 83efeeeb3d04 ("tty: Allow TIOCSTI to be disabled")
Cc: stable@xxxxxxxxxxxxxxx

Acked-by: Jiri Slaby <jirislaby@xxxxxxxxxx>

thanks,
--
js
suse labs