From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.io!.POSTED.blaine.gmane.org!not-for-mail From: "Basil L. Contovounesios" Newsgroups: gmane.emacs.bugs Subject: bug#44018: Don't consider play-sound-file to be a 'safe' function Date: Mon, 26 Oct 2020 17:05:56 +0000 Message-ID: <87eelkgbnv.fsf@tcd.ie> References: <5A2CDAEA-03CF-4F92-AF9D-40421A9B362E@acm.org> <83zh4nwgbs.fsf@gnu.org> <87mu0mrapy.fsf@gnus.org> <83k0vqwuxf.fsf@gnu.org> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Injection-Info: ciao.gmane.io; posting-host="blaine.gmane.org:116.202.254.214"; logging-data="30837"; mail-complaints-to="usenet@ciao.gmane.io" User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/28.0.50 (gnu/linux) Cc: mattiase@acm.org, Lars Ingebrigtsen , 44018@debbugs.gnu.org To: Eli Zaretskii Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane-mx.org@gnu.org Mon Oct 26 18:10:59 2020 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane-mx.org Original-Received: from lists.gnu.org ([209.51.188.17]) by ciao.gmane.io with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1kX61K-0007tX-2A for geb-bug-gnu-emacs@m.gmane-mx.org; Mon, 26 Oct 2020 18:10:58 +0100 Original-Received: from localhost ([::1]:60426 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1kX61J-0005tv-1U for geb-bug-gnu-emacs@m.gmane-mx.org; Mon, 26 Oct 2020 13:10:57 -0400 Original-Received: from eggs.gnu.org ([2001:470:142:3::10]:45748) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1kX5xW-0001SG-NO for bug-gnu-emacs@gnu.org; Mon, 26 Oct 2020 13:07:02 -0400 Original-Received: from debbugs.gnu.org ([209.51.188.43]:57824) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1kX5xW-0006j2-Cs for bug-gnu-emacs@gnu.org; Mon, 26 Oct 2020 13:07:02 -0400 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1kX5xW-0008Vw-7F for bug-gnu-emacs@gnu.org; Mon, 26 Oct 2020 13:07:02 -0400 X-Loop: help-debbugs@gnu.org Resent-From: "Basil L. Contovounesios" Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Mon, 26 Oct 2020 17:07:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 44018 X-GNU-PR-Package: emacs Original-Received: via spool by 44018-submit@debbugs.gnu.org id=B44018.160373196632621 (code B ref 44018); Mon, 26 Oct 2020 17:07:02 +0000 Original-Received: (at 44018) by debbugs.gnu.org; 26 Oct 2020 17:06:06 +0000 Original-Received: from localhost ([127.0.0.1]:41129 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1kX5wc-0008U5-3u for submit@debbugs.gnu.org; Mon, 26 Oct 2020 13:06:06 -0400 Original-Received: from mail-wm1-f54.google.com ([209.85.128.54]:51485) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1kX5wa-0008TX-2B for 44018@debbugs.gnu.org; Mon, 26 Oct 2020 13:06:04 -0400 Original-Received: by mail-wm1-f54.google.com with SMTP id v5so12423834wmh.1 for <44018@debbugs.gnu.org>; Mon, 26 Oct 2020 10:06:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=tcd-ie.20150623.gappssmtp.com; s=20150623; h=from:to:cc:subject:references:date:in-reply-to:message-id :user-agent:mime-version:content-transfer-encoding; bh=zbTDMPxcnVHWNj+tqpnc3y6gU6aA8fmp7ePlrBOW2dc=; b=AKihmrFaIoWketM6M1Dj4fCloTPV7+3HVFssYCw3+vEtlstyK9SFg7/rBO6HU+DFG+ fV5jv3Yzor/coytGck2NasRzK13KH6tnvyAsqOEKQP6Xn73yqICCil9ORNqOwIRaraH8 Mi59xEBNpfV1JOBOi9jrzc6DNqDqjoBZAuIifQhBp9AlgoBvUxgJq71h47VPckLX1OpF VpJ6C3p6wnMT4JSRqkUZ88FdKX3RF3vNQGI6sl7pUh39/jn+dzV6/pKrjWSreaaz4k0J 3Sa3RJXJ4Lau7sZTgDcmIKswXMIgtIgoAGCCxi8UpIK7dYYY4WxTxu+JgnZAGF7LM/tY 4+0A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:references:date:in-reply-to :message-id:user-agent:mime-version:content-transfer-encoding; bh=zbTDMPxcnVHWNj+tqpnc3y6gU6aA8fmp7ePlrBOW2dc=; b=ojSM7bCQHWAi/TZL48SJNtsWnVqnmq7Fs/iKbceFNKVjGgsuJJPvykK+HGNgrJaAj2 Pv/PC8H41+/AxdNVISkmK3QsAIZqf7+Wc6sJZRhhbUkpjJfPuDtd8uVk8370lCQqoVXF zmogc6gI0HiJjGZS8srMVNqNvq2zcy6ZdNKRCdfMLqwKRV6blFHB4REoeouCQodNho0E pBsJ6kkgvQr+7KlilSkuBvV9MlYT2jZGtBjAIaHJEPKLXOS5IUPBPkINEKeRd1CFjoMW fW0gVRnFXI5xMaogKLBQg5i5/XwnlY1FJd0Guhz+qaOpDcm+WwOiYE3U64ARTXNLmde7 tkXg== X-Gm-Message-State: AOAM531ekQmwLzbuAfHr5cpjI6vflQe/afH1T4RBElSjy9iB6/chfmLz F5V9IE/lOMzXzac0PVhZQOXGuQ== X-Google-Smtp-Source: ABdhPJzhoO5T2pBBesq80BJFmefC2oYpc637wDv8vQFvZ14FO1tTy927aMA+ALu5tsfSNo5BDRCPmA== X-Received: by 2002:a7b:c3d3:: with SMTP id t19mr12496371wmj.139.1603731958340; Mon, 26 Oct 2020 10:05:58 -0700 (PDT) Original-Received: from localhost ([109.78.145.8]) by smtp.gmail.com with ESMTPSA id g5sm20952075wmi.4.2020.10.26.10.05.57 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 26 Oct 2020 10:05:57 -0700 (PDT) In-Reply-To: <83k0vqwuxf.fsf@gnu.org> (Eli Zaretskii's message of "Fri, 16 Oct 2020 09:23:40 +0300") X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane-mx.org@gnu.org Original-Sender: "bug-gnu-emacs" Xref: news.gmane.io gmane.emacs.bugs:191614 Archived-At: Eli Zaretskii writes: >> From: Lars Ingebrigtsen >> Cc: Mattias Engdeg=C3=A5rd , >> 44018@debbugs.gnu.org >> Date: Fri, 16 Oct 2020 07:39:05 +0200 >>=20 >> My understanding of unsafep.el isn't that it's trying to protect against >> any particular exploits, but just give a list of things that are totally >> and utterly OK to eval. So you have stuff like: >>=20 >> commit a8c41b4c0d3b0a3e87f17bbcdd8ac12dae296b3a >> Author: Chong Yidong >> AuthorDate: Mon Oct 18 13:28:20 2010 -0400 >>=20 >> Don't allow functions that display messages in unsafep. >>=20 >> So even `message' isn't "safe" in this context. I think it's odd to >> have `play-sound-file' marked as "safe" if `message' isn't. > > Do you understand why 'message' was removed? I don't, and couldn't > find any discussion on Emacs lists that discussed that; I may have > missed something. I have no idea why 'message' could be unsafe. > unsafep.el doesn't provide a high-level definition of what is > considered "safe", unfortunately, and was evidently written for SES, > so may have some bias due to that context. Still, it is not clear to > me why 'message' was removed. FWIW, there's an @ignored section in doc/lispref/functions.texi that I guess was intended to provide a higher-level description, but the following paragraph is the best it currently manages to do: What is a safe Lisp expression? Basically, it's an expression that calls only built-in functions with no side effects (or only innocuous ones). Innocuous side effects include displaying messages and altering non-risky buffer-local variables (but not global variables). --=20 Basil