SteamOS bypasses Wayland's input isolation by granting uaccess to keyboards
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 48/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- linux
- Domain
- operating-systems, security
Research direction
Review /usr/lib/udev/rules.d/70-steamos-power-button.rules and 70-steam-jupiter-input.rules, then reproduce the report with evtest as an unprivileged user. Trace which keyboard devices receive uaccess and compare that with the intended Wayland input isolation. Done means the reported keyboards are no longer readable through /dev/input by unprivileged processes without breaking the relevant SteamOS input behavior.
Written by the indexing model from the issue text.
Description
Your system information
- Steam client version: 1789781627
- SteamOS version: SteamOS 3.9.1 Build: 20260914.100
- Opted into Steam client beta?: Yes
- Opted into SteamOS beta?: Yes
- Have you checked for updates in Settings > System?: Yes
- Device: Steam Deck LCD
Please describe your issue in as much detail as possible:
Expected behavior: Unprivileged users should not be able to read keyboard inputs through /dev/input. This is particularly important under Wayland because only focused foreground apps are expected to access the keyboard on Wayland sessions.
Actual behavior: Due to the way SteamOS grants uaccess via udev rules, many keyboards are exposed to unprivileged user processes. As far as I understand, this is caused by /usr/lib/udev/rules.d/70-steamos-power-button.rules for any Bluetooth or USB input device that is correctly or incorrectly labeled as a power button, which includes my Logitech K380s. Furthermore, there is another rule in /usr/lib/udev/rules.d/70-steam-jupiter-input.rules that grants uaccess to any USB device.
Steps for reproducing this issue:
- Switch to desktop mode.
- Connect a keyboard via Bluetooth or USB.
- Launch Konsole.
- Run
evtestwithout sudo/root privileges. - Select the device event number corresponding to the keyboard.
- Press any key on the keyboard to see the keystroke printed.
- Dominant language
- No language data
- Stars
- 2.6k
- Forks
- 83
- Avg merge
- 4m
- Merged PRs (30d)
- 3
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from ValveSoftware/SteamOS
-
steam-short-session-tracker: incorrect registry backup path resets settings during automatic repair Open
Difficulty 2/5 1-3 hours Newbie friendliness 80/100
ValveSoftware/SteamOS#2829 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 68/100
ValveSoftware/SteamOS#1743 · 1 comment · 2 reactions ·
-
Difficulty 4/5 3-5 days Newbie friendliness 45/100
ValveSoftware/SteamOS#2828 ·
-
Difficulty 5/5 Over a week Newbie friendliness 30/100
ValveSoftware/SteamOS#2827 ·
-
Difficulty 4/5 3-5 days Newbie friendliness 38/100
ValveSoftware/SteamOS#2822 ·
All issues in ValveSoftware/SteamOS
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
module/agent platform/macos type/bug/regression
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Azure/WALinuxAgent#3686 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100