Pimp My IDE / terminal X-ray
Back to garage
October 4, 2026 | terminals / ncurses / trust boundaries

Your terminal profile can count.

Terminfo is usually described as a terminal database. Its parameterized strings also have arithmetic, conditionals, output, and persistent registers. A host that expands them supplies the clock.

Do not panic over a Fibonacci stunt. Do stop treating terminal capability strings as inert labels. Inspect who controls the entry, which process loads it, when it expands, and which bytes reach the terminal.

The metadata has instructions.

Terminfo maps terminal capabilities to Boolean values, numbers, and strings. Screen programs use those records to pick the right control sequence for cursor movement, color, clearing, and other terminal operations. The ncurses manual documents the database and the API that reads it.[2]

The string form is more than a byte lookup. Parameter expansion can push constants and arguments, store values in registers, perform arithmetic, choose conditional branches, and print results. Uppercase registers can persist across expansions inside one process.[1]

A terminal capability can be data at rest and a small program when expanded.

The host process supplies the loop.

Nicolas Seriot compiled a two-counter Minsky machine into the cup cursor-addressing capability. One expansion executes one machine step. Repeated calls provide the clock that the capability language does not contain itself.[1]

The showpiece changes the terminal type and runs /usr/bin/top. On Seriot's setup, a cursor movement used during the clock redraw advances a Fibonacci calculation. The capability also writes the current result into the terminal window title. The exact cursor coordinate depends on the layout and terminal size, so this is a constructed demonstration rather than a portable feature of top.

The ncurses API explains the handoff. An application loads a terminal description, passes parameterized strings through tparm, then sends the result to the terminal with an output function such as tputs.[3] That path gives the inspection order: loaded entry, expanded capability, host trigger, emitted bytes.

The stunt is not a shell.

Seriot is explicit about the security boundary. His Fibonacci capability does not open files, execute commands, or make system calls. It produces terminal output through the operations that terminfo expansion already supports. He does not present it as a privilege-escalation exploit.[1]

The useful lesson is narrower. A user-controlled terminfo record can be interpreted repeatedly inside another process. A parser or evaluator flaw would be a separate issue. Terminal output can also change visible state such as a title. Keep those facts separate from claims about command execution or elevated access.

Inspect the lookup before the spectacle.

The terminfo manual says TERM names the terminal type. Seriot notes that tic commonly installs a user entry under ~/.terminfo, while TERMINFO can point lookup at another directory. That means the profile name alone is not a complete record. Capture the resolved entry and the environment that selected it.

Start with read-only commands. Print TERM, inspect the compiled entry with infocmp, and record the host program that consumes it. If an agent changes terminal setup, review the source entry before compiling it. Do not execute a downloaded demo merely to prove that the syntax exists.

Interactive makeover / capability expansion bay

Follow one tick through the host.

This replaces the vague question "is terminfo code?" with three execution cases, four review gates, a visible expansion route, and a copyable inspection card. It models the route. It does not parse a terminfo file or inspect your machine.

Clock selector

Route model

Choose the event that asks ncurses to expand a capability. The selector changes every mirrored label on the right.

Expansion case
Inspection gates

Expansion route

No host inspected
MOVELOADcupBYTES
0 of 4 inspection gates selected

The cursor movement route is selected. No machine evidence has been recorded.

Selected gates are review requirements. They do not prove which terminfo entry was loaded, which function ran, what bytes were emitted, or whether any vulnerability exists.
Read-only inspection / copyable start

Open the hood without running a demo.

These commands print the selected terminal type and reconstruct its resolved terminfo entry. They do not compile a new entry. Review the output before changing TERM, TERMINFO, or any user terminfo directory.

printf 'TERM=%s\n' "$TERM"
printf 'TERMINFO=%s\n' "${TERMINFO:-[unset]}"
printf 'TERMINFO_DIRS=%s\n' "${TERMINFO_DIRS:-[unset]}"
infocmp "$TERM"
infocmp -1 "$TERM"

Next check: record which program loads the entry. Then map the suspicious string capability to the host call that expands it.

Sources read

Source log and evidence boundary
  1. Nicolas Seriot, "A Minsky Machine in ncurses terminfo", published October 2 and read October 4, 2026. It supplies the construction, instruction mapping, addition and Fibonacci examples, top redraw demonstration, practical limits, and security boundary.
  2. ncurses 6.6, terminfo(5), dated September 19 and read October 4, 2026. It documents the database, entry syntax, capability types, parameterized strings, user-defined capabilities, and standard capability records.
  3. ncurses 6.6, curs_terminfo(3x), dated August 22 and read October 4, 2026. It documents terminal initialization, loading through setupterm, parameter expansion through tparm, and terminal output through tputs.
  4. Hacker News discussion 49935250, read October 4, 2026 after the exact item ID was verified through the Hacker News API. It led to Seriot's article. It does not verify the implementation or security claims.

Evidence boundary. Seriot ran the Minsky-machine and top demonstrations on his setup. The ncurses manuals define the documented interfaces. Pimp My IDE designed the inspection route and read-only recipe. This page did not execute the downloaded terminfo programs or audit ncurses for vulnerabilities.