GNU bug report logs - #74879
30.0.92; trusted-content-p and trusted-files cannot be used for non-file buffers

Previous Next

Package: emacs;

Reported by: Daniel Mendler <mail <at> daniel-mendler.de>

Date: Sun, 15 Dec 2024 00:40:02 UTC

Severity: normal

Found in version 30.0.92

Full log


Message #131 received at 74879 <at> debbugs.gnu.org (full text, mbox):

From: Richard Stallman <rms <at> gnu.org>
To: Stefan Kangas <stefankangas <at> gmail.com>
Cc: mail <at> daniel-mendler.de, 74879 <at> debbugs.gnu.org, monnier <at> iro.umontreal.ca,
 dmitry <at> gutov.dev
Subject: Re: bug#74879: 30.0.92;
 trusted-content-p and trusted-files cannot be used for non-file
 buffers
Date: Thu, 16 Jan 2025 17:53:55 -0500
[[[ To any NSA and FBI agents reading my email: please consider    ]]]
[[[ whether defending the US Constitution against all enemies,     ]]]
[[[ foreign or domestic, requires you to follow Snowden's example. ]]]

  > > 1. They come from known sources, from curated archives. Admittedly the
  > > archive review is not sufficient. I've suggested to add review
  > > facilities to package.el, see bug#74604. Furthermore I've suggested to
  > > add git commit signature checks to GNU/NonGNU ELPA, see bug#61277.

For the abstract question, "Why might I conclude I can trust a
package", that could be a good answer.  However, trust for some
specific purpose might make sense to judge on a different criterion.

For a feature that will load and run code from a package that you were
not expecting, I think it makes sense to judge the question more
strictly.

"trusted" is a good word to use in the option name because a clearer
alternative would be much longer and not much clearer.  But let's not
add features that would suggest bestowing turst very widely.

I continue to usge renaming of this file local variable to
`trusted-code' because that word precisely fits what gets trusted in
this way in the files that you mark with it.

-- 
Dr Richard Stallman (https://stallman.org)
Chief GNUisance of the GNU Project (https://gnu.org)
Founder, Free Software Foundation (https://fsf.org)
Internet Hall-of-Famer (https://internethalloffame.org)






This bug report was last modified 55 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.