Live data from Hacker News

Déjà vu: Ghostly CVEs in my terminal title

dgl.cx

11–20 of 68 posts

Re: Déjà vu: Ghostly CVEs in my terminal title

#11
post #5

Earlier quoted context omitted.

You proposal does not address this issue since shells would still need full privileges. This entire class of exploits (query responses with user controlled data leading to shells executing commands) would be removed if shells just moved to using the kitty keyboard protocol with all key events represented as escape codes and implemented a full escape code parser for data received form the terminal. You cannot embed an…

I believe it could. A shell could reduce capability by default for all executed shell scripts (file or inline on the prompt) and require opt in to not do this. Something akin to a umask of sorts. It’d break exceedingly few real scripts. (Hand waving a lot here with the “opt in” mechanism to avoid that being scripted but I have ideas) Also note my thoughts (very much not even close to being a proposal) are very raw. I…

So if I am to understand your proposal more concretely it is something like implement an escape code that the shell can use to turn off all other escape codes (presumably with some kind of listing mechanism) and then have the shell do that before launching any third party script/program/function? How would the shell know which escape codes the program it is running needs?

I can, kind of, see the utility of a pledge() type system within a single program, but in a shell, whose whole job is basically running programs it knows nothing about beyond their name? How would that work?

Re: Déjà vu: Ghostly CVEs in my terminal title

#12
post #11

Earlier quoted context omitted.

I believe it could. A shell could reduce capability by default for all executed shell scripts (file or inline on the prompt) and require opt in to not do this. Something akin to a umask of sorts. It’d break exceedingly few real scripts. (Hand waving a lot here with the “opt in” mechanism to avoid that being scripted but I have ideas) Also note my thoughts (very much not even close to being a proposal) are very raw. I…

So if I am to understand your proposal more concretely it is something like implement an escape code that the shell can use to turn off all other escape codes (presumably with some kind of listing mechanism) and then have the shell do that before launching any third party script/program/function? How would the shell know which escape codes the program it is running needs? I can, kind of, see the utility of a pledge()…

Sorry to be a broken record but I have no “proposal” whatsoever. It’s more of an information sharing and seeking discussion. I don’t know what I want yet except that I think we can do better. The end result could be that it’s all a terrible idea and that’s okay, but hopefully something comes out of it eventually.

Id love to continue this discussion, but I think HN threads probably aren’t the right medium. If you’d like I can email you or we can schedule a call. I’m not trying to seek privacy, I’d be happy for any to be recorded or shared publicly, I just don’t find HN to be a good place if you really want to dive into this!

Re: Déjà vu: Ghostly CVEs in my terminal title

#13
post #4
post #2

I’m impressed with how many bugs (security and otherwise) have been fixed and new features included [0] in the 1.0.1 release, considering the first public release (1.0) was only 5 days ago. [0]: https://ghostty.org/docs/install/release-notes/1-0-1

[flagged]

Kitty is a great terminal and Kovid does excellent work. I have a ton of respect for him. Ghostty (disclaimer: I’m the creator) could also be and I appreciate anyone who thinks so. There doesn’t have to be a winner/loser mentality!

The big picture is to get more people to use the terminal more for cases it’s good for. Infighting amongst people who already like terminals is counter productive, in my opinion.

Re: Déjà vu: Ghostly CVEs in my terminal title

#14
post #10
post #8

Earlier quoted context omitted.

What a strange reply. Kitty has been my terminal for years. I haven’t even used ghostty. I’m not shilling anything. Good grief. Try looking in a mirror. I was making a good faith comment just adding something positive. No need to turn it into a war. It’s strange (and just wrong) that you think I need to review the development velocity of all other projects before being impressed by something. Actually, no. To be impr…

[flagged]

Implying I’m a liar is a silly cheap shot.

I’ve made zero HN comments about Firefox, Thunderbird and Blender. But I must be lying when I say I use those every day.

You seem to have interpreted my original comment as a declaration of ghostty’s superiority. It wasn’t. Not every positive comment about a piece of software must also be interpreted as an attack on another piece of software, such that you have to come to its defence.

Though perhaps you will tell me I’m forbidden from being impressed by any terminal other than Kitty, and certainly not God-forbid actually share that thought on HN!

Re: Déjà vu: Ghostly CVEs in my terminal title

#15
post #11

Earlier quoted context omitted.

So if I am to understand your proposal more concretely it is something like implement an escape code that the shell can use to turn off all other escape codes (presumably with some kind of listing mechanism) and then have the shell do that before launching any third party script/program/function? How would the shell know which escape codes the program it is running needs? I can, kind of, see the utility of a pledge()…

Sorry to be a broken record but I have no “proposal” whatsoever. It’s more of an information sharing and seeking discussion. I don’t know what I want yet except that I think we can do better. The end result could be that it’s all a terrible idea and that’s okay, but hopefully something comes out of it eventually. Id love to continue this discussion, but I think HN threads probably aren’t the right medium. If you’d li…

Of course, I didn't mean to put you in a spot. We can always continue this later once your thoughts have matured. Sadly I have an extremely full schedule so I dont think I have the badwidth to noodle on this at this stage but if and when you have something more concrete please do post it somewhere public and I will try to contribute to the discussion.

Re: Déjà vu: Ghostly CVEs in my terminal title

#16
post #15

Earlier quoted context omitted.

Sorry to be a broken record but I have no “proposal” whatsoever. It’s more of an information sharing and seeking discussion. I don’t know what I want yet except that I think we can do better. The end result could be that it’s all a terrible idea and that’s okay, but hopefully something comes out of it eventually. Id love to continue this discussion, but I think HN threads probably aren’t the right medium. If you’d li…

Of course, I didn't mean to put you in a spot. We can always continue this later once your thoughts have matured. Sadly I have an extremely full schedule so I dont think I have the badwidth to noodle on this at this stage but if and when you have something more concrete please do post it somewhere public and I will try to contribute to the discussion.

Appreciate it! <3

Re: Déjà vu: Ghostly CVEs in my terminal title

#17
post #14
post #10

Earlier quoted context omitted.

[flagged]

Implying I’m a liar is a silly cheap shot. I’ve made zero HN comments about Firefox, Thunderbird and Blender. But I must be lying when I say I use those every day. You seem to have interpreted my original comment as a declaration of ghostty’s superiority. It wasn’t. Not every positive comment about a piece of software must also be interpreted as an attack on another piece of software, such that you have to come to it…

[flagged]

Re: Déjà vu: Ghostly CVEs in my terminal title

#18
post #17
post #14

Earlier quoted context omitted.

Implying I’m a liar is a silly cheap shot. I’ve made zero HN comments about Firefox, Thunderbird and Blender. But I must be lying when I say I use those every day. You seem to have interpreted my original comment as a declaration of ghostty’s superiority. It wasn’t. Not every positive comment about a piece of software must also be interpreted as an attack on another piece of software, such that you have to come to it…

[flagged]

It’s actually possible to make a positive comment about something and for it to be sincere. These are not mutually exclusive.

Though it seems if there’s a positive comment about a terminal that you don’t personally think deserves it, the commenter must be a shill.

Honestly quite bizarre how this sub-thread has turned out. What I thought was an innocent comment, you’ve turned into ghostty vs kitty. Not everything has to be turned into Vim vs Emacs, systemd vs anti-systemd, or which is objectively the best terminal. It’s possible to be impressed with ghostty’s release velocity without it being a judgment about Kitty or any other terminal or software project. But alas, in order to make a positive comment about ghostty, I must have already had a proven history of making positive comments about other terminals ;)

Re: Déjà vu: Ghostly CVEs in my terminal title

#19
post #4
post #2

I’m impressed with how many bugs (security and otherwise) have been fixed and new features included [0] in the 1.0.1 release, considering the first public release (1.0) was only 5 days ago. [0]: https://ghostty.org/docs/install/release-notes/1-0-1

[flagged]

Oh, did he start actually fixing vulnerabilities instead of insisting they aren't there while repeatedly being given PoC exploits?

In case someone didn't know, the infamous Calibre bug report: https://bugs.launchpad.net/calibre/+bug/885027

Re: Déjà vu: Ghostly CVEs in my terminal title

#20
post #18
post #17

Earlier quoted context omitted.

[flagged]

It’s actually possible to make a positive comment about something and for it to be sincere. These are not mutually exclusive. Though it seems if there’s a positive comment about a terminal that you don’t personally think deserves it, the commenter must be a shill. Honestly quite bizarre how this sub-thread has turned out. What I thought was an innocent comment, you’ve turned into ghostty vs kitty. Not everything has…

[flagged]
Post reply on HN