A parasitic Fibonacci computation inside /usr/bin/top
2 days ago
- Terminfo parameter expansion is a stack machine with arithmetic, logic, conditionals, and persistent registers, but lacks loops; loops are provided by repeated external expansion.
- Two-counter Minsky machines can be simulated using terminfo's registers and conditional branches, proving computational universality.
- An addition machine example computes 4 + 9 = 13, using the cup capability and repeated tput calls to clock each step.
- A Fibonacci machine using three registers (A, B, N) is also implemented, printing trace lines as it computes Fibonacci numbers.
- A variant uses /usr/bin/top's cursor movement (setuid-root) as an external clock, running the Fibonacci program parasitically in the terminal title.
- This is a hack rather than a bug; terminfo cannot execute commands or open files, so no privilege escalation occurs even when evaluated by setuid programs.
- Only a vulnerability in the terminfo parser or evaluator could lead to privileged impact; the article demonstrates the universality of terminfo parameter expansion.