#4976 HIGH Update.: Browse cannot launch Etoys when the user clicks on a .pr file.

Zarro Boogs per Child bugtracker at laptop.org
Fri Feb 8 02:18:08 EST 2008


#4976: Browse cannot launch Etoys when the user clicks on a .pr file.
------------------------------+---------------------------------------------
  Reporter:  ohshima          |       Owner:  erikos  
      Type:  defect           |      Status:  new     
  Priority:  high             |   Milestone:  Update.2
 Component:  browse-activity  |     Version:          
Resolution:                   |    Keywords:          
  Verified:  0                |    Blocking:          
 Blockedby:                   |  
------------------------------+---------------------------------------------

Comment(by ohshima):

 Replying to [comment:11 mstone]:
 > Basically, I don't [yet] know how to let activities launch other
 activities safely; therefore, I desire to prevent them from doing so;
 (noting, however, that they're free to run whatever child processes they
 please.)
 >
 > If you can help me figure out how to make it safe (i.e. so that it can't
 be used to realize the privacy threats recognized in Bitfrost) then I'd
 love to support it.

 I don't have enough knowledge but can the child process open a new X
 window?  If so, at least we can open and interact with the content.  (It
 sounds like the process cannot save data into Journal as it cannot see the
 directory under SUGAR_ACTIVITY_ROOT?)  This would be a compromize for
 Etoys' case.

 I'm so out of touch and don't know how much of
 http://wiki.laptop.org/go/OLPC_Bitfrost is relevant, but if Browse saves a
 data into Journal, and then if it could tell the Journal to launch the
 object, what kind of threat would that create?  (This is a plain question,
 not a rhetrical one.)

-- 
Ticket URL: <http://dev.laptop.org/ticket/4976#comment:12>
One Laptop Per Child <http://dev.laptop.org>
OLPC bug tracking system



More information about the Bugs mailing list