From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.io!.POSTED.blaine.gmane.org!not-for-mail From: Gerd =?UTF-8?Q?M=C3=B6llmann?= Newsgroups: gmane.emacs.bugs Subject: bug#74879: 30.0.92; trusted-content-p and trusted-files cannot be used for non-file buffers Date: Sun, 15 Dec 2024 15:55:10 +0100 Message-ID: References: <87ed29ixu8.fsf@daniel-mendler.de> Mime-Version: 1.0 Content-Type: text/plain Injection-Info: ciao.gmane.io; posting-host="blaine.gmane.org:116.202.254.214"; logging-data="18240"; mail-complaints-to="usenet@ciao.gmane.io" User-Agent: Gnus/5.13 (Gnus v5.13) Cc: Daniel Mendler , 74879@debbugs.gnu.org To: Stefan Monnier Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane-mx.org@gnu.org Sun Dec 15 15:57:27 2024 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane-mx.org Original-Received: from lists.gnu.org ([209.51.188.17]) by ciao.gmane.io with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1tMq3j-0004Xe-2H for geb-bug-gnu-emacs@m.gmane-mx.org; Sun, 15 Dec 2024 15:57:27 +0100 Original-Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1tMq3U-0003cc-Md; Sun, 15 Dec 2024 09:57:14 -0500 Original-Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1tMq3N-0003bB-BK for bug-gnu-emacs@gnu.org; Sun, 15 Dec 2024 09:57:07 -0500 Original-Received: from debbugs.gnu.org ([2001:470:142:5::43]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1tMq3M-0001oD-QO for bug-gnu-emacs@gnu.org; Sun, 15 Dec 2024 09:57:05 -0500 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debbugs.gnu.org; s=debbugs-gnu-org; h=MIME-Version:Date:References:In-Reply-To:From:To:Subject; bh=ndrpSuoisH2gZqa0Urd67QYF0zw+ztyktGFoVc7DU8A=; b=aSh/BSvZdYurl0h4jx5/IUCusm3ocvbiHeweTnI3Sivr09qxEkzF3+J90UWU+fuZn7bm0qkdZWnBdRWlFuUzXGfdYCo00Ru934hq1d9NmvAEdVc0HQPrpd/FDVFwfBdxl3xT6KqE3xuCXonDmkPVRy3sgHcntNWsQdSdLL/YOv32zl75P6vzVOeWwj5gF6bdTTDkCBqcpWAlndaICyWYeLYAvvH9qRNK0+2h7eYoaa1XT3r3XqxMVMDUD0OjV77OHZL5wndmDzWk0Z8VzyN4dmjHu1bBBh4FQVMev93RlsIkH+cuF74pzZcpNuHWC8U0+nUSz7YlYY5VFG2B+sQWyg==; Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1tMq3K-0001u7-G1 for bug-gnu-emacs@gnu.org; Sun, 15 Dec 2024 09:57:04 -0500 X-Loop: help-debbugs@gnu.org Resent-From: Gerd =?UTF-8?Q?M=C3=B6llmann?= Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Sun, 15 Dec 2024 14:57:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 74879 X-GNU-PR-Package: emacs Original-Received: via spool by 74879-submit@debbugs.gnu.org id=B74879.17342745787292 (code B ref 74879); Sun, 15 Dec 2024 14:57:02 +0000 Original-Received: (at 74879) by debbugs.gnu.org; 15 Dec 2024 14:56:18 +0000 Original-Received: from localhost ([127.0.0.1]:51567 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1tMq2b-0001tY-Gj for submit@debbugs.gnu.org; Sun, 15 Dec 2024 09:56:17 -0500 Original-Received: from mail-ej1-f41.google.com ([209.85.218.41]:48267) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1tMq2Y-0001tQ-IC for 74879@debbugs.gnu.org; Sun, 15 Dec 2024 09:56:16 -0500 Original-Received: by mail-ej1-f41.google.com with SMTP id a640c23a62f3a-aa66ead88b3so616420166b.0 for <74879@debbugs.gnu.org>; Sun, 15 Dec 2024 06:56:14 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1734274513; x=1734879313; darn=debbugs.gnu.org; h=mime-version:user-agent:message-id:date:references:in-reply-to :subject:cc:to:from:from:to:cc:subject:date:message-id:reply-to; bh=ndrpSuoisH2gZqa0Urd67QYF0zw+ztyktGFoVc7DU8A=; b=gWKiKukocGVfr03DVP8SLhknqc7ZS2ElB9pmXitDf6zw+zk51HoSlGIqHfdZpS9SyP IIxfLTfy+kX/abXO7S5vFO6N39tNwvhjAQqfhrDkFG3cGlrDVRs91Fg7ZuBURSl9DK9G oMmsfYRhtkq6omvuUsi4z8ikbj59o2WEQ/RN+9nnvFJkAcCdXK5Wtno88PxEVETUKoBh 1Nr9SztRJeuZGTkPUQw/JU7VdBvNYKabminH9G8P8s13RpLx356SSpaq6gMOFBLuptFd UHFW/RUGZvySEhYpllt+wVDNAq9Ow9KMNNZY9ML+eFgmGHZaoEJmwSimxtRsb6tl27Ed Wrow== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1734274513; x=1734879313; h=mime-version:user-agent:message-id:date:references:in-reply-to :subject:cc:to:from:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=ndrpSuoisH2gZqa0Urd67QYF0zw+ztyktGFoVc7DU8A=; b=BAOOU7zm4+vY7oeAZXJquAdg4nX4jmdj/VbLp7xua8et/vX7Tup9Yn5dS3C4/YuFho 9NToHQCNchHigRka8Mj9ykRRV9KRODp9vnkvJe9iXDLnwGJl2RVvBKNMOPX/PhKP85jp RmIv0jYlLLZIjvXl4imBVfwdWT8DusJJuXOOO/uhIrbV9yvxNV5kou3sJ1BUbV8egGb7 APUlUkhSk43aaH7aaR+74hYx1EotOlhXywgpXgmBQmvYotm6+OhRFuo8N6PhTX9pUs7z dbXiZO70lvBYrsz0JMmc80RyC1sJpDXWd5xOKVaRhwbik/CU7RCoMVZGdMjRY2F5j4TA cauQ== X-Forwarded-Encrypted: i=1; AJvYcCUp2S+s1pDcrpbPIeUIa7+0GaAVWW9vX0xaahk8TA19ttLuC3Yn291S4rO7GPAXOsm2cQulXQ==@debbugs.gnu.org X-Gm-Message-State: AOJu0YwZ5EQ4a3YWCOYGcedkzAhjuyeHOqo83Kyu7GCzIpDCE9oYb4Zs lcxym1uWrvYyKZjMskVmnJrjhMAuBCsIkoqZ6Z05mJwIxfMxvDEaaxhCzQ== X-Gm-Gg: ASbGncsPDwi/hTQ6JM3Pp3cq7uk5QM1yG/RsizpvfXGn7C4TIGWhrVLUnvfokSpTgQ9 e5yoEdPUtARFREW6Kgt60e6hbzgR7CIdDOkwAvVi09qouAYbFHC+x8N/0NeO/CusvfqF9AX/MZD nXk3hHQ4tm2vDHeArdlbD0kaYYk50L35HvUgT2yP28kjWBLIpjMzCZEFQeZPbpg/aPT2BhzXR3A 7BOPQSr4pNrc6bhzV9oExuz/09UTRih+2AepT1MUwOoSHxPqjmjJdu1F80vti3vAKauhf9IDcwV tFyZXFvGLxemXCcVvY29JWoGs2q1zI584LfClwwEhm3FPGa11/4wslSWe9AL0OMFZw== X-Google-Smtp-Source: AGHT+IEqa3HEuv7U/H+/lvfdlSYKkm0TJih/tDyHXpYkNJ1RSVjMn5KDn/MfAJl969ArbJQMZyezSQ== X-Received: by 2002:a17:906:31c1:b0:aa6:8935:ae71 with SMTP id a640c23a62f3a-aab778c1e2dmr864719666b.12.1734274513253; Sun, 15 Dec 2024 06:55:13 -0800 (PST) Original-Received: from pro2 (p200300e0b7208800845360bbbfb3451f.dip0.t-ipconnect.de. [2003:e0:b720:8800:8453:60bb:bfb3:451f]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-aab96067edbsm216909066b.49.2024.12.15.06.55.11 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 15 Dec 2024 06:55:12 -0800 (PST) In-Reply-To: (Stefan Monnier's message of "Sun, 15 Dec 2024 09:03:18 -0500") X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane-mx.org@gnu.org Original-Sender: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane-mx.org@gnu.org Xref: news.gmane.io gmane.emacs.bugs:297109 Archived-At: Stefan Monnier writes: >> Thank you for the recent addition of `trusted-content-p'. Is there a >> possibility to use `trusted-content-p' in buffers which are not backed >> by a file? I use Flymake in *scratch* or similar buffers and it seems >> that this won't continue to work given that `trusted-content-p' needs a >> `buffer-file-truename'. > > Good question. > We don't really have a good answer yet, AFAIK, in large part because we > don't have enough experience with it. > Off the top of my head, here are some elements relevant to this > discussion, in random order: > > - The current setup is a kind of "minimal" change for Emacs-30 because > it's late in the pretest, so as much as possible we should separate > the discussion into what's a simple enough solution for Emacs-30 and > what we should use in the longer term. > > - You should be able to get fully-featured Flymake in *scratch* > with (setq-local trusted-files :all). > Maybe we should do that when we setup *scratch*? > Which other non-file buffers would need that? The minibuffer? > > - Trust sucks, so we really should work on better solutions where we > don't need to rely on trust, such as running code in `bwrap` or other > kinds of sandboxes. > > - I think we do want some kind of hook, with which we can have (for > instance) `emacs-lisp-mode` tell Emacs to trust the user init file, > the early-init file, the custom-file, and all the files in > `load-path`. > > - There is overlap with `safe-local-variable-directories`, > `enable-local-variables` and it would be nice to consolidate (which > can require delicate timing if we want the major mode to inform which > content to trust). > Random thought: - What if a user pastes text from a untrusted source to a trusted buffer? - Is taint checking relevant in this context? https://en.wikipedia.org/wiki/Taint_checking