From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!.POSTED.blaine.gmane.org!not-for-mail From: Michael Albinus Newsgroups: gmane.emacs.devel Subject: Re: master 3df7d06: Added `comint-password-function' hook Date: Mon, 23 Dec 2019 11:24:56 +0100 Message-ID: <87woanjq4n.fsf@gmx.de> References: <20191223050615.10479.33674@vcs0.savannah.gnu.org> <20191223050617.2BA89212AC@vcs0.savannah.gnu.org> Mime-Version: 1.0 Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Injection-Info: blaine.gmane.org; posting-host="blaine.gmane.org:195.159.176.226"; logging-data="142515"; mail-complaints-to="usenet@blaine.gmane.org" User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.0.50 (gnu/linux) Cc: "Michael R. Mauger" To: emacs-devel@gnu.org Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Mon Dec 23 11:26:15 2019 Return-path: Envelope-to: ged-emacs-devel@m.gmane.org Original-Received: from lists.gnu.org ([209.51.188.17]) by blaine.gmane.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.89) (envelope-from ) id 1ijKul-000att-Il for ged-emacs-devel@m.gmane.org; Mon, 23 Dec 2019 11:26:15 +0100 Original-Received: from localhost ([::1]:55514 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1ijKuj-0000nk-QB for ged-emacs-devel@m.gmane.org; Mon, 23 Dec 2019 05:26:14 -0500 Original-Received: from eggs.gnu.org ([2001:470:142:3::10]:54162) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1ijKtc-0008P4-52 for emacs-devel@gnu.org; Mon, 23 Dec 2019 05:25:05 -0500 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1ijKtb-0002YO-2P for emacs-devel@gnu.org; Mon, 23 Dec 2019 05:25:04 -0500 Original-Received: from mout.gmx.net ([212.227.17.22]:56393) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1ijKta-0002Xd-PL for emacs-devel@gnu.org; Mon, 23 Dec 2019 05:25:03 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=gmx.net; s=badeba3b8450; t=1577096698; bh=5q0jOczZBGuHJ28/Zmwiz5SiQPoKPM0l1RtZGZhtivQ=; h=X-UI-Sender-Class:From:To:Cc:Subject:References:Date:In-Reply-To; b=iQwcXmqurhDgfyRvWyrUvm/ijzoNKwAgs5Npax7DlGEOtB1Hgwwz4J18nFkN7Gu1K 2JCvhOVivLs/xZqkQxnYaxsuB24K6+Hg34mUyhOC+PamhDoFaUEvC7NNCp1kbo8/kZ CCOAgbDlAZ909tizRG8eVNOKPuEfMA6PMSCa1E/U= X-UI-Sender-Class: 01bb95c1-4bf8-414a-932a-4f6e2808ef9c Original-Received: from detlef.gmx.de ([212.86.47.138]) by mail.gmx.com (mrgmx104 [212.227.17.168]) with ESMTPSA (Nemesis) id 1MQ5rU-1j5Nz00aJc-00M4hW; Mon, 23 Dec 2019 11:24:58 +0100 In-Reply-To: <20191223050617.2BA89212AC@vcs0.savannah.gnu.org> (mmaug's message of "Mon, 23 Dec 2019 00:06:16 -0500 (EST)") X-Provags-ID: V03:K1:VNcaKP3cUoYiw9RvHHK9HAt/RysWxu3/pRm4H6ozhqPi6rBEAJt mVkMzYHJ4YjPkGFwTAsJ9wMXNBDhxdwNTC/Q69naLFm8qgwixSluLH4i+JYi4wS/+kwnkqK ZwH6pcxDZUavIXjHbTQdWcOk2jjRZzZkkwk3+Tymr7vcvVjyWtpnBE/VD6bbeST2bKDwHQG fkhRJSEKmuEYn39Jo6h7A== X-UI-Out-Filterresults: notjunk:1;V03:K0:OPlxnUMjtf0=:kafUcdI5dmFIkM9z7s5yL3 GJGTRRYYmJnss05HejXtTfHMI8Sft831kFMWBr24yQW1X6tFI+e/KTuR3GlDZhmAtgb20/gL3 qEJvVSE0qt/qcizrA697yPxclPlcyIK0tTlVvv1HubiRn8a1RJGMWjvs5baGHsWTJcklPdMnV q1nKJIsJNxEKbPQ79Ul4TKmpujIdD/H2KextK174nT0+dCSzF/iyGkgnVECkvdCVV2iWyl/o+ d8mhx0Y7tEjlOUsyH0XX0OVl3iUU2mdsKNLXZQEHu4nFwPe6BoafZwWDveeA/GiY6F2NvWIo9 T6Jnl3GericcgeDGPIgafYzAoUEQrF3P2+mmxGYaaxMVFGBGMkkYkYM5TZfYCYdmBpiiQbvzT JV1aIL3UtSdLfUZgFTm0/3hs+3gr7OiQmOhPsiXoK7IV4ZD4q5FqEoPW40qLuy0ywlXBARVuC NLqv1zIef17F9yCObwtuk+ua4WNKuppo9T+uP2cDl8NYhnl79a1qnlJ1HMxmBj7SnjE0irg4M c+HQz4aG3tBVFKZ4ikbqAT6SNR1gPbytArkeg457AiRs1DcYT6fpHZeKjI71bnz6TmXHCtYHO mNif59zLbmUeOrWI5+BmxzCc6M1L9VogfyY6Noa8VadLeDs5ZSX5ov9CnsHu0Nq7iMivlZCxI zPNL9fj4h4KA0MieDPnKaEpKkyRUZ1ZLAnH2jAR/R83FzLZF8qmLEKLd4/4JJ5IcANl9HQIK8 l2cEMATP1D/sEqmKmqRmwnFXmhdxYCiwv3IVsLhGWunQ2haDTgutREM9Lb1vjQxauENleXab X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] [fuzzy] X-Received-From: 212.227.17.22 X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Original-Sender: "Emacs-devel" Xref: news.gmane.org gmane.emacs.devel:243579 Archived-At: mmaug--- via Mailing list for Emacs changes writes: Hi Michael, > --- a/etc/NEWS > +++ b/etc/NEWS > @@ -1131,6 +1131,19 @@ end. > *** 'comint-run' can now accept a list of switches to pass to the progr= am. > 'C-u M-x comint-run' will prompt for the switches interactively. > > +*** Abnormal hook `comint-password-function' has been added. > +This hook permits a derived mode to supply a password for the > +underlying command interpreter without prompting the user. For > +example, in sql-mode, the password for connecting to the database may > +be stored in the connection wallet and may be passed on the command > +line to start the SQL interpreter. This is a potential security flaw > +that could expose user's database passwords on the command line > +through the use of a process list (Bug#8427). With this hook, it is > +possible to not pass the password on the command line and wait for the > +program to prompt for the password. When it does so, the password cam > +be supplied to the SQL interpreter without involving the user just as > +if it had been supplied on the command line. Shouldn't this be documented in the manual, or at least in the docstring? etc/NEWS is not the preferred place to look for documentation, except when a new Emacs release arrives. Furthermore, we don't mention bug numbers in etc/NEWS. Best regards, Michael.