Skip to content

feat(linux): add auto privilege bootstrap for evdev - #86

Open
lywing-god wants to merge 230 commits into
vladelaina:mainfrom
lywing-god:feature/linux-evdev-auto-elevation
Open

lywing-god wants to merge 230 commits into
vladelaina:mainfrom
lywing-god:feature/linux-evdev-auto-elevation

Conversation

@lywing-god

Copy link
Copy Markdown

Summary

Add automatic privilege elevation for the experimental Linux Wayland evdev backend.

When started with BONGOCAT_ENABLE_EVDEV=1, BongoCat first attempts to open keyboard, pointer, and other event devices as the current user.

If access is denied, the program restarts itself through sudo and opens the devices read-only. It then removes the elevated identity and runs as the original user with the opened device descriptors.

This avoids persistent /dev/input ACLs and membership in the input group.

Details

  • Runs before SDL, configuration, UI, and model initialization.
  • Uses read-only, nonblocking, no-follow device access.
  • Validates inherited descriptors and marks them close-on-exec.
  • Uses /proc/self/exe for the unprivileged restart.
  • Uses a trusted absolute sudo path, configurable at build time with BONGO_CAT_SUDO_EXECUTABLE.
  • Monitors only devices present at startup; hot-plug is intentionally unsupported.
  • Leaves Windows, macOS, native X11, and Wayland without the opt-in variable unchanged.
  • Wayland evdev sessions use XWayland/GLX because the GLEW loader bundled with Cubism behaves incorrectly with native Wayland/EGL.

Security notes

  • Does not modify ACLs, install udev rules, grab devices, or inject input.
  • Raw evdev input may include passwords and does not pause on lock or session switching.
  • Automatic elevation is intended for protected executables, such as package-manager installations writable only by root.

CN Trans 中文

概要

为 Linux Wayland evdev 后端增加自动提权流程。

使用 BONGOCAT_ENABLE_EVDEV=1 环境变量启动时,BongoCat 会先以当前用户身份尝试打开键鼠等Event设备。

如果权限不足,程序将通过 sudo 重新拉起自己,以只读方式打开设备。然后清除提权用户,携带打开的设备描述符,降回原用户身份正常运行。

这样无需为 /dev/input 设置持久 ACL,也不必将用户加入 input 组。

实现细节

  • 在 SDL、配置、UI 和模型初始化之前执行。
  • 以只读、非阻塞且禁止跟随符号链接的方式打开设备。
  • 校验继承的设备描述符,并设置执行时关闭标志。
  • 降权后通过 /proc/self/exe 重新执行当前程序。
  • 使用可信的 sudo 绝对路径,并可通过 BONGO_CAT_SUDO_EXECUTABLE 编译期配置。
  • 仅监听启动时存在的设备,暂不支持热插拔。
  • 不影响 Windows、macOS、原生 X11,以及未显式启用该变量的 Wayland 启动流程。
  • Wayland evdev 会话仅使用 XWayland/GLX,因为随 Cubism 构建的 GLEW 加载器在原生 Wayland/EGL中存在异常。

安全说明

  • 不修改 ACL、不安装 udev 规则、不独占设备,也不注入输入。
  • 原始 evdev 输入可能包含密码,且不会在锁屏或切换会话时自动暂停。
  • 自动提权适用于可执行文件受保护的情况,如通过包管理器安装,仅root有写入权限。

ChinaWeJen and others added 30 commits September 1, 2026 15:25
Add Traditional Chinese README with project details and setup instructions.
Create README in Traditional Chinese
Add French README translation
docs: add French README translation
260901
Added Japanese README with installation and usage instructions.
Ciallo~(∠・ω< )⌒★
Create Japanese README for BongoCat.   Ciallo~(∠・ω< )⌒★
docs: add Korean README translation
@vladelaina
vladelaina force-pushed the main branch 3 times, most recently from 858ac6f to 7fb927c Compare October 1, 2026 12:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.