Backport of the input-device name fix (PR #8129 by @acrogenesis, merged to
quattro as 9285b19d) onto the v4-0-1 release branch.
Hyprland input-device and monitor names come from USB descriptors and hyprctl
output, so they are attacker-influenceable, yet the toggle and monitor commands
interpolated them straight into hyprctl eval and into generated Lua that
Hyprland re-executes on every reload. XF86TouchpadToggle is bound with
locked = true, so a malicious USB name reached Lua execution from the lock
screen as the logged-in user, and a persisted disable made it run on every
start. Publicly reported by Jorrit Jongma / Chainfire.
The disable is no longer executable Lua anywhere. The device name is stored as
plain-text data in a *-disabled-name sidecar and read back by a packaged module,
default/hypr/disabled-input-device.lua, on every reload; the live hyprctl eval
Lua-quotes the name and rejects control characters outright. The reload loader
excludes the two legacy filenames, so a leftover generated *-disabled.lua on a
not-yet-migrated install can never be sourced as code again, and a migration
recovers the device name from it and deletes it, sanitizing installs that ran
the vulnerable version. All four monitor scripts validate an output name against
a plain-connector-name pattern before writing it as Lua, closing the same latent
pattern in the siblings, and paths.lua treats a set-but-empty XDG_STATE_HOME as
unset to match the bash side.
Clean cherry-pick: all fourteen files are byte-identical to quattro, so merging
v4-0-1 into quattro resolves without a conflict. This branch ships no leftover
*-disabled.lua template of its own -- the tracked "disabled" files are the same
two quattro has -- so the migration is the only path that has to sanitize
anything here.
test/shell passes: 192 files, including the three this adds. The toggle suite's
public-PoC case passes here, as do the monitor scripts' accept/reject cases and
the XDG path cases. test/cli passes.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018DEMYa9UWtroz93DhMTtcV
77 lines
1.9 KiB
Bash
Executable File
77 lines
1.9 KiB
Bash
Executable File
#!/bin/bash
|
|
|
|
# omarchy:summary=Enable, disable, or toggle a Hyprland input device
|
|
# omarchy:args=<touchpad|touchscreen> [on|off|toggle]
|
|
# omarchy:hidden=true
|
|
|
|
KIND="${1:-}"
|
|
ACTION="${2:-toggle}"
|
|
|
|
usage() {
|
|
echo "Usage: omarchy-toggle-input-device <touchpad|touchscreen> [on|off|toggle]" >&2
|
|
}
|
|
|
|
case "$KIND" in
|
|
touchpad) LABEL="Touchpad" ICON="touchpad" ;;
|
|
touchscreen) LABEL="Touchscreen" ICON="touch" ;;
|
|
*)
|
|
usage
|
|
exit 1
|
|
;;
|
|
esac
|
|
|
|
# The persisted disable is the device name stored as plain data; on every
|
|
# reload default/hypr/disabled-input-device.lua reads it back and disables the
|
|
# device. Names come from USB descriptors and must not be interpolated into
|
|
# shell or Lua. The path is hardcoded to ~/.local/state like the sibling
|
|
# toggle tools, so it keeps working when XDG_STATE_HOME diverges.
|
|
NAME_FILE="$HOME/.local/state/omarchy/toggles/hypr/$KIND-disabled-name"
|
|
|
|
device="$("omarchy-hw-$KIND")"
|
|
|
|
require_device() {
|
|
if [[ -z $device ]]; then
|
|
echo "No $KIND device found" >&2
|
|
exit 1
|
|
fi
|
|
|
|
if [[ $device == *[[:cntrl:]]* ]]; then
|
|
echo "Invalid $KIND device name" >&2
|
|
exit 1
|
|
fi
|
|
}
|
|
|
|
apply_device() {
|
|
local enabled=$1
|
|
local quoted=${device//\\/\\\\}
|
|
quoted=${quoted//\"/\\\"}
|
|
hyprctl eval "hl.device({ name = \"$quoted\", enabled = $enabled })" >/dev/null
|
|
}
|
|
|
|
enable() {
|
|
# Clear the persisted state before requiring a usable device, so a device
|
|
# that stops reporting a valid name can never wedge the disable in place.
|
|
rm -f "$NAME_FILE"
|
|
require_device
|
|
apply_device true
|
|
omarchy-osd -i "$ICON" -m "$LABEL enabled"
|
|
}
|
|
|
|
disable() {
|
|
require_device
|
|
apply_device false
|
|
mkdir -p "$(dirname "$NAME_FILE")"
|
|
printf '%s\n' "$device" >"$NAME_FILE"
|
|
omarchy-osd -i "$ICON" -m "$LABEL disabled"
|
|
}
|
|
|
|
case "$ACTION" in
|
|
on) enable ;;
|
|
off) disable ;;
|
|
toggle) if [[ -f $NAME_FILE ]]; then enable; else disable; fi ;;
|
|
*)
|
|
usage
|
|
exit 1
|
|
;;
|
|
esac
|