ncurses terminfo parameter expansion is presented as a small, stateful programming language: it supports pushing constants and parameters, arithmetic, conditionals, output, and persistent registers (A-Z, a-z). The tparm instruction set lets one read cursor parameters and manipulate registers, and repeated capability expansions provide iteration. By mapping two counters to registers A and B and a program counter to register Z, each terminfo expansion can implement one step of a two-counter Minsky machine (INC and conditional decrement/JZDEC are encoded with %g, %{n}, %+/%-, %?…%t…%e…%; and %P to persist). With unbounded registers and unlimited expansions this yields computational universality; in practice implementations bound register sizes and entry lengths, making real instances finite-state.
Concrete examples include an adding machine that computes 4+9 by performing 20 expansions and a Fibonacci machine using registers A, B, N that prints successive Fibonacci numbers. The clock driving expansions can be any repeated capability use: a yes loop or, strikingly, /usr/bin/top repainting its header once per second triggers a specific cup(x,y) cursor move (e.g. 0,78) and thus drives a parasitic Fibonacci program that updates the terminal title. This is a hackable composition rather than a bug: terminfo expansion cannot perform syscalls or spawn processes, so it is not by itself a privilege escalation, but treating user-controlled terminfo as executable code inside other processes creates a trust-boundary concern and amplifies the impact of parser/evaluator vulnerabilities.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.