aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorEd Maste <emaste@FreeBSD.org>2026-05-25 13:59:40 +0000
committerEd Maste <emaste@FreeBSD.org>2026-06-09 16:38:54 +0000
commitc289291a6736c01dd68fb8459ec3801859b0a59a (patch)
tree5c3b666362e62b172a29ac747679a70813fa16ef
parent13fb6dbc738f4ba30e78a8fb21efa1382c520d33 (diff)
tty: Add sysctl knob to globally disable TIOCSTI
Reviewed by: markj Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D57233
-rw-r--r--sys/kern/tty.c8
1 files changed, 8 insertions, 0 deletions
diff --git a/sys/kern/tty.c b/sys/kern/tty.c
index 3d20d225087c..13147613f7f6 100644
--- a/sys/kern/tty.c
+++ b/sys/kern/tty.c
@@ -101,6 +101,10 @@ static int tty_drainwait = 5 * 60;
SYSCTL_INT(_kern, OID_AUTO, tty_drainwait, CTLFLAG_RWTUN,
&tty_drainwait, 0, "Default output drain timeout in seconds");
+static bool tty_tiocsti = true;
+SYSCTL_BOOL(_security_bsd, OID_AUTO, tiocsti, CTLFLAG_RWTUN,
+ &tty_tiocsti, 0, "Allow TIOCSTI ioctl");
+
/*
* Set TTY buffer sizes.
*/
@@ -1651,6 +1655,10 @@ tty_set_winsize(struct tty *tp, const struct winsize *wsz)
static int
tty_sti_check(struct tty *tp, int fflag, struct thread *td)
{
+ /* Check for global disable. */
+ if (!tty_tiocsti)
+ return (EPERM);
+
/* Root can bypass all of our constraints. */
if (priv_check(td, PRIV_TTY_STI) == 0)
return (0);