From james.gates@sun.com Wed Jul  9 09:59:12 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m69GxChv015611
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 9 Jul 2008 09:59:12 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m69Gx9fq017667;
	Wed, 9 Jul 2008 10:59:09 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3R006090IK3J00@nwk-avmta-2.sfbay.sun.com>; Wed,
 09 Jul 2008 09:59:08 -0700 (PDT)
Received: from dm-uk-02.uk.sun.com ([129.156.101.196])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3R00L040IH6NE0@nwk-avmta-2.sfbay.sun.com>; Wed,
 09 Jul 2008 09:59:06 -0700 (PDT)
Received: from serinus.UK.Sun.COM (serinus.UK.Sun.COM [129.156.173.208])
	by dm-uk-02.uk.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2)
 with ESMTP id m69Gx3Zk006636; Wed, 09 Jul 2008 17:59:03 +0100 (BST)
Received: from [192.168.1.100] (vpn-129-150-65-60.East.Sun.COM [129.150.65.60])
	by serinus.UK.Sun.COM (8.13.7+Sun/8.13.7/CTE 3.0)
 with ESMTP id m69Gw6Be025355; Wed, 09 Jul 2008 17:58:14 +0100 (BST)
Date: Wed, 09 Jul 2008 12:57:23 -0400
From: James Gates <james.gates@sun.com>
Subject: Integrate privoxy into Solaris [LSARC/2008/433 FastTrack timeout
 07/17/2008]
To: lsarc-ext@sun.com
Cc: Venky <venkytv@sun.com>, one-pager-list@sac.sfbay.sun.com,
        one-pager-log@sac.sfbay.sun.com, sac-bar@sac.sfbay.sun.com
Message-id: <4874EDF3.7040603@sun.com>
MIME-version: 1.0
Content-type: multipart/mixed; boundary="Boundary_(ID_OsgtLrIDVgeRIa+hGWjTGA)"
X-Accept-Language: en-us, en
X-PMX-Version: 5.4.1.325704
User-Agent: Mozilla/5.0 (X11; U; SunOS sun4u; en-US; rv:1.7.13) Gecko/20060509
Status: RO
Content-Length: 58124

This is a multi-part message in MIME format.

--Boundary_(ID_OsgtLrIDVgeRIa+hGWjTGA)
Content-type: text/plain; charset=us-ascii; format=flowed
Content-transfer-encoding: 7BIT

I'm sponsoring this fast-track case for Venky Tv. The case would have 
been automatically approved as a FOSS check list fast track if it were 
not for the following issue:

If yes do the components support IPv6?
 >        [ ] Yes
 >        [X] No - ARC review required

I'm not too sure what we can discuss here. As the community haven't 
really warmed to IPv6, I would have thought that lack of IPv6 support is 
the norm, not the exception. What would be the outcome of an ARC 
discussion - Would you insist that the community implement IPv6 support? 
Would integration be stalled until IPv6 support is enabled?

Anyway, the timer expires on 07/17/2008.

All associated docs are in the case materials directory (and attached here).


-- 
Jim Gates                    Sun Microsystems
Nashua, USA             http://sun.com/postgresql

--Boundary_(ID_OsgtLrIDVgeRIa+hGWjTGA)
Content-type: text/plain; name=privoxy-proposal.txt
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=privoxy-proposal.txt

Proposal:

        Integrate privoxy into Solaris.


Detail:
        
        Privoxy is a non-caching web proxy with advanced filtering
        capabilities for enhancing privacy, modifying web page data, managing
        HTTP cookies, controlling access, and removing ads, banners, pop-ups
        and other obnoxious Internet junk. Privoxy has a flexible
        configuration and can be customized to suit individual needs and
        tastes.  Privoxy has application for both stand-alone systems and
        multi-user networks.

        The current version of privoxy is 3.0.8 at the time of this case.


Exported Interfaces:

        SUNWprivoxy             Uncommitted             Package name
        /usr/sbin/privoxy       Committed               Executable location
        /lib/svc/method/privoxy Committed               SMF Service method
        privoxy                 Volatile                Commandline syntax
        privoxy output          -                       Not an interface

        A complete list of files delivered by the privoxy package is included
        in the privoxy-interfaces.txt file.


Imported Interfaces:

        Standard C Library Functions

References:

[1] http://www.privoxy.org/
    Authors of privoxy: Fabian Keil, David Schmidt, and others
[2] CR 6689953 Integrate Privoxy v3.0.8

--Boundary_(ID_OsgtLrIDVgeRIa+hGWjTGA)
Content-type: text/plain; name=privoxy-checklist.txt
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=privoxy-checklist.txt

FCL--FOSS Check List
0.  Introduction
0.1 Document History
    Version   Author             Changes					Date
    0.1       John Fischer       Initial Draft					01/11/2008
    0.2       John Fischer       Modified based upon feedback from ARC members	01/29/2008
    0.3       John Fischer       Modified based upon feedback during committee 	02/12/2008
                                 review
    0.4       John Fischer       Modified based upon SAC review feedback	04/01/2008
    0.5	      John Fischer	 Modified based upon LSARC business meeting	06/10/2008
                                 adding familiarity question and mod dates.
    0.6       John Fischer       Modified based upon user feedback about        06/20/2008
                                 sections that were unanswerable.

0.2 Purpose
    Architecture review at Sun has allowed the company to evolve our projects
    within multiple disjoint groups while still maintaining a cohesive product
    line.  Each architecture review was conducted within Sun's control.  With
    the advent of Free Open Source Software processes the control that Sun as
    a company can wield has been diminished.  Now that Sun is moving to a more
    fluid delivery mechanism with project Indiana we need to evolve the 
    architecture review process.  This document is meant to aid in the 
    architecture review process.  Each new project must complete this check list 
    to help ensure that the overall resulting product conforms to Sun product 
    standards.  If the project deviates from these standards further review 
    would be necessary by an architecture review committee.
    
    After the check list is completed the project team should be able to 
    determine if a project can be automatically approved.  This will occur
    if all checks result in no "ARC review required" answers.  A committee
    member will assist the project team in filing the automatically approved 
    fast track.  An automatically approved fast track is still required in order
    to record the interfaces for future reference.  If the project needs to 
    have further review then follow the regular process for getting projects 
    reviewed.

1.0 Project Information
1.1 Name of project/component
    Privoxy: A non-caching web proxy with advanced filtering capabilities

1.2 Author of document
    Venky TV

2.0 Project Summary
  2.1 Project Description
      Privoxy is a non-caching web proxy with advanced filtering capabilities
      for enhancing privacy, modifying web page data, managing HTTP cookies,
      controlling access, and removing ads, banners, pop-ups and other obnoxious
      Internet junk. Privoxy has a flexible configuration and can be customized
      to suit individual needs and tastes.  Privoxy has application for both
      stand-alone systems and multi-user networks.

      Privoxy applies to only HTTP and HTTPS traffic.
  
  2.2 Release binding
      What is is the release binding?
      (see http://opensolaris.org/os/community/arc/policies/release-taxonomy/)
      [ ] Major
      [X] Minor
      [ ] Patch or Micro
      [ ] Unknown -- ARC review required

  2.3 Type of project
      Is this case a Linux Familiarity project?
      [X] Yes
      [ ] No

  2.4 Originating Community
    2.4.1 Community Name
          Privoxy
    
    2.4.2 Community Involvement
      Indicate Sun's involvement in the community
      [ ] Maintainer
      [ ] Contributor
      [X] Monitoring
      
      Will the project team work with the upstream community to resolve
      architectural issues of interest to Sun?
      [X] Yes 
      [ ] No - briefly explain
      
      Will we or are we forking from the community?
      [ ] Yes - ARC review required prior to forking
      [X] No
      
3.0 Technical Description
  3.1 Installation & Sharable
    3.1.1S Solaris Installation - section only required for Solaris Software
      (see http://opensolaris.org/os/community/arc/policies/install-locations/ for details)
      Does this project follow the Install Locations best practice?
      [X] Yes 
      [ ] No - ARC review required
      
      Does this project install into /usr under [sbin|bin|lib|include|man|share]?
      [X] Yes
      [ ] No or N/A
      
      Does this project install into /opt?
      [ ] Yes - explain below
      [X] No or N/A
      
      Does this project install into a different directory structure?
      [ ] Yes - ARC review required
      [X] No or N/A
      
      Do any of the components of this project conflict with anything under /usr?
      (see http://opensolaris.org/os/community/arc/caselog/2007/047/ for details)
      [ ] Yes - explain below
      [X] No
      
      If conflicts exist then will this project install under /usr/gnu?
      [ ] Yes
      [ ] No - ARC review required
      [X] N/A
      
      Is this project installing into /usr/sfw?
      [ ] Yes - ARC review required
      [X] No
      
    3.1.1W Windows Installation - section only required for Windows Software
      (see http://sac.sfbay/WSARC/2002/494 for details)
      Does this project install software into a 
      <system drive>:\Program Files\Sun\<product> or <system drive>:\Sun\<product>
      directory?
      [ ] Yes
      [ ] No - ARC review required
      
      Does the project use the Windows registry?
      [ ] Yes
      [ ] No - ARC review required
      
      Does the project use 
      HKEY_LOCAL_MACHINE\SOFTWARE\Sun Microsystems\<product>\<version>
      for the registry key?
      [ ] Yes
      [ ] No - ARC review required
      
      Is the project's stored location
      HKEY_LOCAL_MACHINE\SOFTWARE\Sun Microsystems\<product id>\<version id>\Path?
      [ ] Yes
      [ ] No - ARC review required
      
    3.1.2 Share and Sharable
      Does the module include any components that are used or shared by 
      other projects?
      [ ] Yes
      [X] No
    
      If yes are these components packaged to be shared with the other FOSS?
      [ ] Yes
      [ ] No - ARC review required
      [X] N/A
    
      Are these components already in the Solaris WOS?
      [ ] Yes
      [X] No - continue with next section (section 3.2)
    
      If yes are these newer versions being delivered?
      [ ] Yes
      [ ] No - ARC review required
      
      If yes are the newer versions replacing the existing versions?
      [ ] Yes
      [ ] No - ARC review required

  3.2 Exported Libraries
      Are libraries being delivered by this project?
      [ ] Yes
      [X] No - continue with next section (section 3.3)
      
      Are 64-bit versions of the libraries being delivered?
      [ ] Yes
      [ ] No - ARC review required
    
      Are static versions of the libraries being delivered?
      [ ] Yes - ARC review required
      [ ] No 
      
  3.3 Services and the /etc Directory
      (see http://opensolaris.org/os/community/arc/policies/SMF-policy/)
      Does the project integrate anything into /etc/init.d or /etc/rc?.d?
      [ ] Yes - ARC review required
      [X] No
      
      Does the project integrate any new entries into /etc/inittab or
      /etc/inetd.conf?
      [ ] Yes - ARC review required
      [X] No
      
      Does the project integrate any private non-public files into /etc/default
      or /etc/ configuration files?
      [X] Yes - ARC review required
      [ ] No
      
      Does the service manifests method context grant rights above that
      of the noaccess user and basic privilege set?
      [ ] Yes - ARC review required
      [X] No
        
  3.4 Security
    3.4.1 Secure By Default 
      (see http://opensolaris.org/os/community/arc/policies/secure-by-default/ for details)
      (see http://www.opensolaris.org/os/community/arc/policies/NITS-policy/ for details)
      (see parts of http://opensolaris.org/os/community/arc/policies/SMF-policy/ for
       addtional details)
      Are there any network services provided by this project?
      [X] Yes
      [ ] No - continue with the next section (section 3.4.2)
      
      Are network services enabled by default?
      [ ] Yes - ARC review required
      [X] No
      [ ] N/A
      
      Are network services automatically enabled by the project during installation?
      [ ] Yes - ARC review required
      [X] No
      [ ] N/A
      
      Are inbound network communications denied by default?
      [ ] Yes
      [X] No - ARC review required
      [ ] N/A
      
      Is inbound data checked to prevent content-based attacks?
      [ ] Yes
      [ ] No - ARC review required
      [X] N/A
      
      Is the outbound receiver authenticated?
      [ ] Yes
      [ ] No - ARC review required
      [X] N/A
      
      Is the receiver authenticated prior to receiving any sensitive outbound communication?
      [ ] Yes
      [ ] No - ARC review required
      [X] N/A
      
    3.4.2 Authorization
      (see http://opensolaris.org/os/community/arc/bestpractices/rbac-intro/ and
	   http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/ and
	   http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/
           for details)
      Are there any setuid/setgid privileged binaries in the project?
      [ ] Yes - ARC review required
      [X] No - continue with next section (section 3.4.3)
      
      If yes then are the setuid/setgid privileges handled by the use of roles?
      [ ] Yes
      [ ] No - ARC review required

    3.4.3 Auditing
      (see http://opensolaris.org/os/community/arc/policies/audit-policy/ for details)
      (see http://opensolaris.org/os/community/arc/caselog/2003/397 for details)
      Does this component contain administrative or security enforcing software?
      [ ] Yes - ARC review required
      [X] No - continue to next section (section 3.4.4)
      
      (see http://opensolaris.org/os/community/arc/caselog/2003/397 for details)
      Do the components create audit logs detailing what took place including what event
      took place, who was involved, when the event took place?
      [ ] Yes - ARC contract and Audit project team review required
      [ ] No - ARC review required
        
        
    3.4.4 Authentication
      (see http://opensolaris.org/os/community/arc/policies/PAM/)
      Do the components contain any authentication code?
      [ ] Yes
      [X] No - continue to next section (section 3.4.5)
      
      If yes do the components use PAM (plugable authentication modules) for authentication?
      [ ] Yes
      [ ] No - ARC review required
      
      If yes is a single PAM session maintained during authentication?
      [ ] Yes
      [ ] No - ARC review required
      
      If yes are the components sufficiently privileged to allow the requested 
      operations (authentication, password change, process credential manipulation, 
      audit state initialization)?
      [ ] Yes - briefly describe below
      [ ] No - ARC review required
      
    3.4.5 Passwords
      (see http://opensolaris.org/os/community/arc/bestpractices/passwords-cli/ and
           http://opensolaris.org/os/community/arc/bestpractices/passwords-files/ for details)
      Do any of the components for the project deal with passwords?
      [ ] Yes
      [X] No - continue to next section (section 3.4.6)
      
      If yes are these passwords entered via the CLI or environment?
      [ ] Yes - ARC review required
      [ ] No
      
      Are passwords stored within the file system for the component?
      [ ] Yes
      [ ] No - continue to next section (section 3.4.6)
      
      If yes are the permissions on the file such to protect exposing the password(s)?
      [ ] Yes
      [ ] No - ARC review required
      
    3.4.6 General Security Questions
      (see http://opensolaris.org/os/community/arc/bestpractices/security-questions/ for details)
      Are there any network protocols used by this project?
      [X] Yes
      [ ] No - continue with the next section (section 3.5)
      
      Do the components use standard network protocols?
      [X] Yes
      [ ] No - ARC review required
      
      Do network services for the project make decisions based upon user, host or 
      service identities?
      [X] Yes - explain below
      [ ] No
      [ ] N/A

      ACLs based on hostnames and IP addresses can be used to restrict access to
      the Privoxy proxy server.
      
      Do the components make use of secret information during authentication and/or
      authorization?
      [ ] Yes - explain below
      [X] No
      [ ] N/A
  
  3.5 Networking
      Do the components access the network?
      [X] Yes
      [ ] No - continue with the next section (section 3.6)
      
      If yes do the components support IPv6?
      [ ] Yes 
      [X] No - ARC review required
          
  3.6 Core Solaris Components
      Do the components of this project compete with or duplicate core 
      Solaris components?
      [ ] Yes - ARC review required
      [X] No 
      
      Examples of Core Solaris Components include but are not limited to:
      
        Secure By Default
        Authorizations
        PAM -- Plugable Authentication Module
        Privilege
        PRM -- Process Rights Management -- Privilege
        Audit
        xVm -- Virtualization
        zones / Solaris Containers
        PRM -- Process Rights Management
        RBAC -- Role Based Access Control
        TX / Trusted Extensions
        ZFS
        SMF -- Service Management Facility
        FMA -- Fault Management Architecture
        SCF -- Smart Card Facility
        IPsec
        
4.0 Interfaces
  (see http://www.opensolaris.org/os/community/arc/policies/interface-taxonomy/ for details)
  4.1 Exported Interfaces
  
    Interface Name		Classification      Comments
    --------------------------- ------------------- ---------------------------
    SUNWprivoxy                 Uncommitted         Package name
    /usr/sbin/privoxy           Committed           Executable location
    /lib/svc/method/http-privoxy
                                Committed           SMF Service method
    /var/svc/manifest/network/http-privoxy.xml
                                Commited            SMF Manifest
                                                    Controls the privoxy daemon
    /etc/privoxy/config         Volatile            Main configuration file
    /etc/privoxy/*.action       Volatile            Configuration files -
                                                    Defines URL-based actions
    /etc/privoxy/*.filter       Volatile            Configuration files -
                                                    Header and content rewrite
                                                    rules
    /etc/privoxy/templates/*    Volatile            Template files for the
                                                    web-based user interface
    /etc/privoxy/trust          Volatile            Configuration file -
                                                    Whitelist of allowed sites
    /usr/share/doc/privoxy/*    Volatile            Documentation files
    /usr/share/man/man1/privoxy.1
                                Volatile            Manpage
    /var/log/privoxy/jarfile    Volatile            Stores intercepted browser
                                                    cookies
    /var/log/privoxy/logfile    Volatile            Log file
    privoxy                     Volatile            Commandline syntax
    privoxy output              -                   Not an interface

    A complete list of files delivered by the privoxy package is included
    in the privoxy-interfaces.txt file.
    
  4.2 Imported Interfaces
    Interface Name		         Classification       Comments
    ---------------------------  -------------------- --------------------------
    Standard C Library Functions Committed
          
  Brief Interface Classifications - See Appendix C for definitions
    Volatile - interfaces are fluid and will follow a rapidly changing community
    Uncommitted - interfaces are still evolving in the community and might follow
		  the community
    Committed - interfaces are stable in the community
    Project Private - no review required, just document in table
    Contracted (interface modifier) - further review required

Appendix A - References
  1.  Solaris Installation Locations Policy
      http://opensolaris.org/os/community/arc/policies/install-locations/
  2.  /usr/gnu Installation ARC case
      http://opensolaris.org/os/community/arc/caselog/2007/047/
  3.  Secure By Default Policy
      http://opensolaris.org/os/community/arc/policies/secure-by-default/
  4.  Network Install Time Securityuy Policy
      http://www.opensolaris.org/os/community/arc/policies/NITS-policy/
  5.  Adding RBAC Authorizations Policy
      http://opensolaris.org/os/community/arc/bestpractices/rbac-auths/
  6.  When to use setuid -vs- RBAC roles and profiles
      http://opensolaris.org/os/community/arc/bestpractices/rbac-intro/ and
  7.  Building RBAC Rights Profiles
      http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/
  8.  Solaris Audit Policy
      http://opensolaris.org/os/community/arc/policies/audit-policy/
  9.  Security questionaire
      http://opensolaris.org/os/community/arc/bestpractices/security-questions/
  10. Interface Taxonomy
      http://www.opensolaris.org/os/community/arc/policies/interface-taxonomy/
  11. Plugable Authentication Modules -- PAM
      http://opensolaris.org/os/community/arc/policies/PAM/
  12. Reusable Passwords In Command Line Arguments and Environment Variables
      http://opensolaris.org/os/community/arc/bestpractices/passwords-cli/
  13. Storing Reusable Passwords on a Filesystem
      http://opensolaris.org/os/community/arc/bestpractices/passwords-files/
  14. Release Taxonomy
      http://opensolaris.org/os/community/arc/policies/release-taxonomy/
  15. Service Management Facility (SMF) usage
      http://opensolaris.org/os/community/arc/policies/SMF-policy/

  
Appendix B - Suggested case materials
  1. man pages
  2. SMF manifests
  3. links to contracts
  
Appendix C - Definitions
Submitter
     an agent responsible for creation of an ARC project along with the
     materials describing that project.
Owner
     the ARC agent responsible for shepherding the case through review
     and ensuring a formal opinion is written where required.
Maintainer
     an agent responsible for releasing new versions of a program, typically
     the "main" contributor or person incharge of making Architectural
     decisions for the project
Contributor
     an agent who make contributions to a project, typically has a voice in
     making Architectural decisions for the project
Monitoring
     an agent who is only following the changes made in the community and
     has no Architectural input into the project
Volatile*
    interfaces that are very fluid and typically follow the originating 
    community.  Typically these interfaces can not be imported by other
    projects.
Uncommitted*
    interfaces that are still evolving but will most likely be present from
    release to release.
Committed*
    interfaces that are stable and with Sun guaranteeing some level of
    compatibility from release to release.
Project Private*
    interfaces that are exposed only to or intended to be used only by
    the project being reviewed.  These interfaces can not be imported by
    other projects.
Not-An-Interface*
    components that are not interfaces.
Contracted* (interface modifier) - ARC review of Contract required
    interfaces that do not allow another project to import can be 

*Note: see http://opensolaris.org/os/community/arc/policies/interface-taxonomy/ for details

--Boundary_(ID_OsgtLrIDVgeRIa+hGWjTGA)
Content-type: text/plain; name=privoxy-interfaces.txt
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=privoxy-interfaces.txt

/etc/privoxy/config                                              Volatile
/etc/privoxy/default.action                                      Volatile
/etc/privoxy/default.filter                                      Volatile
/etc/privoxy/standard.action                                     Volatile
/etc/privoxy/templates                                           Volatile
/etc/privoxy/templates/blocked                                   Volatile
/etc/privoxy/templates/cgi-error-404                             Volatile
/etc/privoxy/templates/cgi-error-bad-param                       Volatile
/etc/privoxy/templates/cgi-error-disabled                        Volatile
/etc/privoxy/templates/cgi-error-file                            Volatile
/etc/privoxy/templates/cgi-error-file-read-only                  Volatile
/etc/privoxy/templates/cgi-error-modified                        Volatile
/etc/privoxy/templates/cgi-error-parse                           Volatile
/etc/privoxy/templates/cgi-style.css                             Volatile
/etc/privoxy/templates/connect-failed                            Volatile
/etc/privoxy/templates/default                                   Volatile
/etc/privoxy/templates/edit-actions-add-url-form                 Volatile
/etc/privoxy/templates/edit-actions-for-url                      Volatile
/etc/privoxy/templates/edit-actions-for-url-filter               Volatile
/etc/privoxy/templates/edit-actions-list                         Volatile
/etc/privoxy/templates/edit-actions-list-button                  Volatile
/etc/privoxy/templates/edit-actions-list-section                 Volatile
/etc/privoxy/templates/edit-actions-list-url                     Volatile
/etc/privoxy/templates/edit-actions-remove-url-form              Volatile
/etc/privoxy/templates/edit-actions-url-form                     Volatile
/etc/privoxy/templates/forwarding-failed                         Volatile
/etc/privoxy/templates/mod-local-help                            Volatile
/etc/privoxy/templates/mod-support-and-service                   Volatile
/etc/privoxy/templates/mod-title                                 Volatile
/etc/privoxy/templates/mod-unstable-warning                      Volatile
/etc/privoxy/templates/no-such-domain                            Volatile
/etc/privoxy/templates/show-request                              Volatile
/etc/privoxy/templates/show-status                               Volatile
/etc/privoxy/templates/show-status-file                          Volatile
/etc/privoxy/templates/show-url-info                             Volatile
/etc/privoxy/templates/show-version                              Volatile
/etc/privoxy/templates/toggle                                    Volatile
/etc/privoxy/templates/toggle-mini                               Volatile
/etc/privoxy/templates/untrusted                                 Volatile
/etc/privoxy/trust                                               Volatile
/etc/privoxy/user.action                                         Volatile
/etc/privoxy/user.filter                                         Volatile
/lib/svc/method/http-privoxy                                     Committed
/usr/sbin/privoxy                                                Committed
/usr/share/doc/privoxy/AUTHORS                                   Project Private
/usr/share/doc/privoxy/ChangeLog                                 Project Private
/usr/share/doc/privoxy/LICENSE                                   Project Private
/usr/share/doc/privoxy/README                                    Project Private
/usr/share/doc/privoxy/developer-manual                          Project Private
/usr/share/doc/privoxy/developer-manual/coding.html              Project Private
/usr/share/doc/privoxy/developer-manual/contact.html             Project Private
/usr/share/doc/privoxy/developer-manual/copyright.html           Project Private
/usr/share/doc/privoxy/developer-manual/cvs.html                 Project Private
/usr/share/doc/privoxy/developer-manual/documentation.html       Project Private
/usr/share/doc/privoxy/developer-manual/index.html               Project Private
/usr/share/doc/privoxy/developer-manual/introduction.html        Project Private
/usr/share/doc/privoxy/developer-manual/newrelease.html          Project Private
/usr/share/doc/privoxy/developer-manual/quickstart.html          Project Private
/usr/share/doc/privoxy/developer-manual/seealso.html             Project Private
/usr/share/doc/privoxy/developer-manual/testing.html             Project Private
/usr/share/doc/privoxy/developer-manual/webserver-update.html    Project Private
/usr/share/doc/privoxy/faq                                       Project Private
/usr/share/doc/privoxy/faq/configuration.html                    Project Private
/usr/share/doc/privoxy/faq/contact.html                          Project Private
/usr/share/doc/privoxy/faq/copyright.html                        Project Private
/usr/share/doc/privoxy/faq/general.html                          Project Private
/usr/share/doc/privoxy/faq/index.html                            Project Private
/usr/share/doc/privoxy/faq/installation.html                     Project Private
/usr/share/doc/privoxy/faq/misc.html                             Project Private
/usr/share/doc/privoxy/faq/trouble.html                          Project Private
/usr/share/doc/privoxy/images                                    Project Private
/usr/share/doc/privoxy/index.html                                Project Private
/usr/share/doc/privoxy/man-page                                  Project Private
/usr/share/doc/privoxy/man-page/privoxy-man-page.html            Project Private
/usr/share/doc/privoxy/p_doc.css                                 Project Private
/usr/share/doc/privoxy/user-manual                               Project Private
/usr/share/doc/privoxy/user-manual/actions-file.html             Project Private
/usr/share/doc/privoxy/user-manual/appendix.html                 Project Private
/usr/share/doc/privoxy/user-manual/config.html                   Project Private
/usr/share/doc/privoxy/user-manual/configuration.html            Project Private
/usr/share/doc/privoxy/user-manual/contact.html                  Project Private
/usr/share/doc/privoxy/user-manual/copyright.html                Project Private
/usr/share/doc/privoxy/user-manual/files-in-use.jpg              Project Private
/usr/share/doc/privoxy/user-manual/filter-file.html              Project Private
/usr/share/doc/privoxy/user-manual/index.html                    Project Private
/usr/share/doc/privoxy/user-manual/installation.html             Project Private
/usr/share/doc/privoxy/user-manual/introduction.html             Project Private
/usr/share/doc/privoxy/user-manual/p_doc.css                     Project Private
/usr/share/doc/privoxy/user-manual/proxy2.jpg                    Project Private
/usr/share/doc/privoxy/user-manual/proxy_setup.jpg               Project Private
/usr/share/doc/privoxy/user-manual/quickstart.html               Project Private
/usr/share/doc/privoxy/user-manual/seealso.html                  Project Private
/usr/share/doc/privoxy/user-manual/startup.html                  Project Private
/usr/share/doc/privoxy/user-manual/templates.html                Project Private
/usr/share/doc/privoxy/user-manual/upgradersnote.html            Project Private
/usr/share/doc/privoxy/user-manual/whatsnew.html                 Project Private
/usr/share/man/man1/privoxy.1                                    Volatile
/var/log/privoxy/jarfile                                         Volatile
/var/log/privoxy/logfile                                         Volatile
/var/svc/manifest/network/http-privoxy.xml                       Committed

--Boundary_(ID_OsgtLrIDVgeRIa+hGWjTGA)
Content-type: text/xml; name=http-privoxy.xml
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=http-privoxy.xml

<?xml version="1.0"?>
<!--
CDDL HEADER START

The contents of this file are subject to the terms of the
Common Development and Distribution License (the "License").
You may not use this file except in compliance with the License.

You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
or http://www.opensolaris.org/os/licensing.
See the License for the specific language governing permissions
and limitations under the License.

When distributing Covered Code, include this CDDL HEADER in each
file and include the License file at usr/src/OPENSOLARIS.LICENSE.
If applicable, add the following below this CDDL HEADER, with the
fields enclosed by brackets "[]" replaced with your own identifying
information: Portions Copyright [yyyy] [name of copyright owner]

CDDL HEADER END
-->

<!DOCTYPE service_bundle SYSTEM "/usr/share/lib/xml/dtd/service_bundle.dtd.1">
<!--
    Copyright 2007 Sun Microsystems, Inc.  All rights reserved.
    Use is subject to license terms.

    ident	"@(#)http-privoxy.xml	1.2	08/01/16 SMI"
-->

<service_bundle type='manifest' name='SUNWprivoxy'>

<service
	name='network/http'
	type='service'
	version='1'>

	<!--
	  Because we may have multiple instances of network/http
	  provided by different implementations, we keep dependencies
	  and methods within the instance.
	-->

	<instance name='privoxy' enabled='false'>
		<!--
		  Wait for network interfaces to be initialized.
		-->
		<dependency name='network'
		    grouping='require_all'
		    restart_on='error'
		    type='service'>
		    <service_fmri value='svc:/milestone/network:default'/>
		</dependency>

		<!--
		  Wait for all local filesystems to be mounted.
		-->
		<dependency name='filesystem-local'
		    grouping='require_all'
		    restart_on='none'
		    type='service'>
		    <service_fmri
			value='svc:/system/filesystem/local:default'/>
		</dependency>

		<!--
		  Wait for automounting to be available, as we may be
		  serving data from home directories or other remote
		  filesystems.
		-->
		<dependency name='autofs'
		    grouping='optional_all'
		    restart_on='error'
		    type='service'>
		    <service_fmri
			value='svc:/system/filesystem/autofs:default'/>
		</dependency>

		<exec_method
			type='method'
			name='start'
			exec='/lib/svc/method/http-privoxy start'
			timeout_seconds='60' />

		<exec_method
			type='method'
			name='stop'
			exec='/lib/svc/method/http-privoxy stop'
			timeout_seconds='60' />

		<property_group name='startd' type='framework'>
			<!-- sub-process core dumps shouldn't restart
				session -->
			<propval name='ignore_error' type='astring'
				value='core,signal' />
		</property_group>

        <template>
            <common_name>
                <loctext xml:lang='C'>
                    Privoxy Web Proxy
                </loctext>
            </common_name>
            <documentation>
                <manpage title='privoxy' section='1'
                    manpath='/usr/share/man' />
                <doc_link name='privoxy.org'
                    uri='http://www.privoxy.org/' />
            </documentation>
        </template>
	</instance>

        <stability value='Evolving' />
</service>

</service_bundle>

--Boundary_(ID_OsgtLrIDVgeRIa+hGWjTGA)
Content-type: text/plain; name=privoxy.1
Content-transfer-encoding: 8BIT
Content-disposition: inline; filename=privoxy.1

.\" This manpage has been automatically generated by docbook2man 
.\" from a DocBook document.  This tool can be found at:
.\" <http://shell.ipoline.com/~elmert/comp/docbook2X/> 
.\" Please send any bug reports, improvements, comments, patches, 
.\" etc. to Steve Cheng <steve@ggi-project.org>.
.TH "PRIVOXY" "1" "19 January 2008" "Privoxy 3.0.8" ""
.SH NAME
privoxy \- Privacy Enhancing Proxy
.SH SYNOPSIS

\fBprivoxy\fR [\fB--help\fR ] [\fB--version\fR ] [\fB--no-daemon\fR ] [\fB--pidfile \fIpidfile\fB\fR ] [\fB--user \fIuser[.group]\fB\fR ] [\fB--chroot\fR ] [\fB--pre-chroot-nslookup \fIhostname\fB\fR ] [\fB\fIconfigfile\fB\fR ]

.SH "OPTIONS"
.PP
\fBPrivoxy\fR may be invoked with the following command line
options:
.TP
\fB--help\fR
Print brief usage info and exit.
.TP
\fB--version\fR
Print version info and exit.
.TP
\fB--no-daemon\fR
Don't  become  a daemon, i.e. don't fork and become process group
leader, don't detach from controlling tty, and do all logging there.
.TP
\fB--pidfile \fIpidfile\fB\fR
On startup, write the process ID to \fIpidfile\fR.
Delete the \fIpidfile\fR on exit.
Failure to create or delete the \fIpidfile\fR
is non-fatal. If no \fB--pidfile\fR option is given, no PID file will be used.
.TP
\fB--user \fIuser[.group]\fB\fR
After (optionally) writing the PID file, assume the user ID of
\fIuser\fR and the GID of
\fIgroup\fR, or, if the optional
\fIgroup\fR was not given, the default group of
\fIuser\fR. Exit if the privileges are not
sufficient to do so.
.TP
\fB--chroot\fR
Before changing to the user ID given in the --user option, chroot to
that user's home directory, i.e. make the kernel pretend to the
\fBPrivoxy\fR process that the directory tree starts
there. If set up carefully, this can limit the impact of possible
vulnerabilities in \fBPrivoxy\fR to the files contained in
that hierarchy. 
.TP
\fB--pre-chroot-nslookup \fIhostname\fB\fR
Initialize the resolver library using \fIhostname\fR
before chroot'ing. On some systems this reduces the number of files
that must be copied into the chroot tree.
.PP
If the \fIconfigfile\fR is not specified on  the  command  line,
\fBPrivoxy\fR  will  look for a file named
\fIconfig\fR in the current directory . If no
\fIconfigfile\fR is found, \fBPrivoxy\fR will 
fail to start.
.SH "DESCRIPTION"
.PP
Privoxy is a non-caching
web proxy
with advanced filtering capabilities for enhancing privacy,
modifying web page data, managing HTTP
cookies, 
controlling access, and removing ads, banners, pop-ups and other obnoxious
Internet junk. Privoxy has a flexible configuration and can be
customized to suit individual needs and tastes. Privoxy has application for
both stand-alone systems and multi-user networks.
.PP
Privoxy is based on Internet Junkbuster (tm).
.SH "INSTALLATION AND USAGE"
.PP
Browsers can either be individually configured to use
\fBPrivoxy\fR as a HTTP proxy (recommended),
or \fBPrivoxy\fR can be combined with a packet
filter to build an intercepting proxy
(see \fIconfig\fR).  The default setting is  for
localhost,  on port  8118 (configurable in the main config file).  To set the
HTTP proxy in Netscape and Mozilla, go through:  \fBEdit\fR;
\fBPreferences\fR;  \fBAdvanced\fR;
\fBProxies\fR;  \fBManual Proxy Configuration\fR;
\fBView\fR. 
.PP
For Firefox, go through: \fBTools\fR; 
\fBOptions\fR; \fBGeneral\fR;
\fBConnection Settings\fR;
\fBManual Proxy Configuration\fR. 
.PP
For Internet Explorer, go through: \fBTools\fR; 
\fBInternet Properties\fR; \fBConnections\fR;
\fBLAN Settings\fR. 
.PP
The Secure (SSL) Proxy should also be set to the same values, otherwise
https: URLs will not be proxied. Note: \fBPrivoxy\fR can only
proxy HTTP and HTTPS traffic. Do not try it with FTP or other protocols.
HTTPS presents some limitations, and not all features will work with HTTPS 
connections.
.PP
For other browsers, check the documentation.
.SH "CONFIGURATION"
.PP
\fBPrivoxy\fR can be configured with the various configuration
files. The default configuration files are: \fIconfig\fR,
\fIdefault.filter\fR, and
\fIdefault.action\fR. \fIuser.action\fR should 
be used for locally defined exceptions to the default rules of
\fIdefault.action\fR, and \fIuser.filter\fR for 
locally defined filters. These are well commented.  On Unix
and Unix-like systems, these are located in
\fI/etc/privoxy/\fR by default. 
.PP
\fBPrivoxy\fR uses the concept of \fBactions\fR 
in order to manipulate the data stream between the browser and remote sites.
There are various actions available with specific functions for such things 
as blocking web sites, managing cookies, etc. These actions can be invoked
individually or combined, and used against individual URLs, or groups of URLs 
that can be defined using wildcards and regular expressions. The result is
that the user has greatly enhanced control and freedom.
.PP
The actions list (ad blocks, etc) can also be configured with your
web browser at http://config.privoxy.org/ 
(assuming the configuration allows it).
\fBPrivoxy's\fR configuration parameters  can also  be viewed at
the same page. In addition, \fBPrivoxy\fR can be toggled on/off.
This is an internal page, and does not require Internet access.
.PP
See the \fIUser Manual\fR for a detailed
explanation of installation, general usage, all configuration options, new
features and notes on upgrading.
.SH "SAMPLE CONFIGURATION"
.PP
A brief example of what a simple \fIdefault.action\fR
configuration might look like:

.nf
 # Define a few useful custom aliases for later use
 {{alias}}

 # Useful aliases that combine more than one action
 +crunch-cookies = +crunch-incoming-cookies +crunch-outgoing-cookies
 -crunch-cookies = -crunch-incoming-cookies -crunch-outgoing-cookies
 +block-as-image = +block +handle-as-image

 # Fragile sites should have the minimum changes
 fragile     = -block -deanimate-gifs -fast-redirects -filter \\
               -hide-referer -prevent-cookies -kill-popups

 ## Turn some actions on ################################
 ## NOTE: Actions are off by default, unless explictily turned on 
 ## otherwise with the '+' operator.

{ \\
+deanimate-gifs{last} \\
+filter{refresh-tags} \\
+filter{img-reorder} \\
+filter{banners-by-size} \\
+filter{webbugs} \\
+filter{jumping-windows} \\
+filter{ie-exploits} \\
+hide-forwarded-for-headers \\
+hide-from-header{block} \\
+hide-referrer{conditional-block} \\
+session-cookies-only \\
+set-image-blocker{pattern} \\
}
/ # '/' Match *all* URL patterns

 
 # Block all URLs that match these patterns
 { +block }
  ad.
  ad[sv].
  .*ads.
  banner?.
  /.*count(er)?\\.(pl|cgi|exe|dll|asp|php[34]?)
  .hitbox.com 
  media./.*(ads|banner)

 # Block, and treat these URL patterns as if they were 'images'.
 # We would expect these to be ads.
 { +block-as-image }
  .ad.doubleclick.net
  .a[0-9].yimg.com/(?:(?!/i/).)*$
  ad.*.doubleclick.net

 # Make exceptions for these harmless ones that would be 
 # caught by our +block patterns just above.
 { -block }
  adsl.
  adobe.
  advice.
  .*downloads.
  # uploads or downloads
  /.*loads
.fi
.PP
Then for a \fIuser.action\fR, we would put local,
narrowly defined exceptions:

.nf
 # Re-define aliases as needed here
 {{alias}}

 # Useful aliases
 -crunch-cookies = -crunch-incoming-cookies -crunch-outgoing-cookies
 
 # Set personal exceptions to the policies in default.action #######

 # Sites where we want persistent cookies, so allow *all* cookies
 { -crunch-cookies -session-cookies-only }
  .redhat.com
  .sun.com
  .msdn.microsoft.com
 
 # These sites break easily. Use our "fragile" alias here.
 { fragile }
  .forbes.com
  mybank.example.com

 # Replace example.com's style sheet with one of my choosing
 { +redirect{http://localhost/css-replacements/example.com.css} }
  .example.com/stylesheet.css
.fi
.PP
See the comments in the configuration files themselves, or the 
\fIUser Manual\fR
for full explanations of the above syntax, and other \fBPrivoxy\fR
configuration options.
.SH "FILES"

.nf
 
 \fI/usr/sbin/privoxy\fR
 \fI/etc/privoxy/config\fR
 \fI/etc/privoxy/default.action\fR
 \fI/etc/privoxy/standard.action\fR
 \fI/etc/privoxy/user.action\fR
 \fI/etc/privoxy/default.filter\fR
 \fI/etc/privoxy/user.filter\fR
 \fI/etc/privoxy/trust\fR
 \fI/etc/privoxy/templates/*\fR
 \fI/var/log/privoxy/logfile\fR
.fi
.PP
Various other files should be included, but may vary depending on platform
and build configuration. Additional documentation should be included in the local
documentation directory.
.SH "SIGNALS"
.PP
\fBPrivoxy\fR terminates on the \fBSIGINT\fR,
\fBSIGTERM\fR and \fBSIGABRT\fR signals. Log
rotation scripts may cause a re-opening of the logfile by sending a 
\fBSIGHUP\fR to \fBPrivoxy\fR. Note that unlike
other daemons,  \fBPrivoxy\fR does not need to be made aware of
config file changes by \fBSIGHUP\fR -- it will detect them
automatically. 
.SH "NOTES"
.PP
Please see the \fIUser Manual\fR on how to contact the
developers, for feature requests, reporting problems, and other questions.
.SH "SEE ALSO"
.PP
Other references and sites of interest to \fBPrivoxy\fR
users:
.PP

http://www.privoxy.org/, 
the \fBPrivoxy\fR Home page. 

http://www.privoxy.org/faq/, 
the \fBPrivoxy\fR FAQ. 

http://sourceforge.net/projects/ijbswa/, 
the Project Page for \fBPrivoxy\fR on 
SourceForge.

http://config.privoxy.org/,
the web-based user interface. \fBPrivoxy\fR must be
running for this to work. Shortcut: http://p.p/

http://sourceforge.net/tracker/?group_id=11118&atid=460288, to submit ``misses'' and other
configuration related suggestions to the developers. 

http://www.junkbusters.com/ht/en/cookies.html,
an explanation how cookies are used to track web users.

http://www.junkbusters.com/ijb.html,
the original Internet Junkbuster.

http://privacy.net/, a useful site
to check what information about you is leaked while you browse the web.

http://www.squid-cache.org/, a popular
caching proxy, which is often used together with \fBPrivoxy\fR.

http://www.pps.jussieu.fr/~jch/software/polipo/,
\fBPolipo\fR is a caching proxy with advanced features
like pipelining, multiplexing and caching of partial instances. In many setups
it can be used as \fBSquid\fR replacement.

http://tor.eff.org/, 
\fBTor\fR can help anonymize web browsing, 
web publishing, instant messaging, IRC, SSH, and other applications.

http://www.privoxy.org/developer-manual/, 
the \fBPrivoxy\fR developer manual. 
.SH "DEVELOPMENT TEAM"

.nf
 Fabian Keil, lead developer
 David Schmidt, developer
 
 Hal Burgiss
 Gerry Murphy
 Roland Rosenfeld
 Jörg Strohmayer
.fi
.SH "COPYRIGHT AND LICENSE"
.SS "COPYRIGHT"
.PP
Copyright (C) 2001-2008 by Privoxy Developers <ijbswa-developers@lists.sourceforge.net>
.PP
Some source code is based on code Copyright (C) 1997 by Anonymous Coders
and Junkbusters, Inc. and licensed under the \fIGNU General Public
License\fR.
.SS "LICENSE"
.PP
\fBPrivoxy\fR is free software; you can
redistribute it and/or modify it under the terms of the 
\fIGNU General Public
License\fR, version 2, as published by the Free Software Foundation.
.PP
This program is distributed in the hope that it will be useful, but WITHOUT
ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
FITNESS FOR A PARTICULAR PURPOSE.  See the 
\fIGNU General Public License\fR for
more details, which is available from the Free Software Foundation, Inc, 
51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA
.PP
You should have received a copy of the  \fIGNU General Public License\fR
along with this program; if not, write to the  Free Software
Foundation, Inc. 51 Franklin Street, Fifth Floor
Boston, MA 02110-1301
USA 

--Boundary_(ID_OsgtLrIDVgeRIa+hGWjTGA)
Content-type: text/plain; name=privoxy.man
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=privoxy.man




User Commands					       PRIVOXY(1)



NAME
     privoxy - Privacy Enhancing Proxy

SYNOPSIS
     privoxy [--help ] [--version  ]  [--no-daemon  ]  [--pidfile
     pidfile  ]	[--user	user[.group] ] [--chroot ] [--pre-chroot-
     nslookup hostname ] [configfile ]


OPTIONS
     Privoxy may be  invoked  with  the	 following  command  line
     options:

     --help
	  Print	brief usage info and exit.

     --version
	  Print	version	info and exit.

     --no-daemon
	  Don't	 become	 a daemon, i.e.	 don't	fork  and  become
	  process  group  leader,  don't  detach from controlling
	  tty, and do all logging there.

     --pidfile pidfile
	  On startup, write the	process	ID  to	pidfile.   Delete
	  the  pidfile	on exit.  Failure to create or delete the
	  pidfile is non-fatal.	If no --pidfile	option is  given,
	  no PID file will be used.

     --user user[.group]
	  After	(optionally) writing the  PID  file,  assume  the
	  user	ID  of	user  and  the	GID  of	group, or, if the
	  optional group was not  given,  the  default	group  of
	  user.	 Exit  if the privileges are not sufficient to do
	  so.

     --chroot
	  Before changing to the user  ID  given  in  the  --user
	  option, chroot to that user's	home directory,	i.e. make
	  the kernel pretend to	 the  Privoxy  process	that  the
	  directory  tree starts there.	If set up carefully, this
	  can limit the	impact	of  possible  vulnerabilities  in
	  Privoxy to the files contained in that hierarchy.

     --pre-chroot-nslookup hostname
	  Initialize the resolver library using	 hostname  before
	  chroot'ing.  On some systems this reduces the	number of
	  files	that must be copied into the chroot tree.

     If	the configfile is not specified	on  the	  command   line,
     Privoxy   will   look for a file named config in the current



Privoxy	3.0.8	  Last change: 19 January 2008			1






User Commands					       PRIVOXY(1)



     directory . If no configfile is found, Privoxy will fail  to
     start.

DESCRIPTION
     Privoxy is	a non-caching web proxy	with  advanced	filtering
     capabilities for enhancing	privacy, modifying web page data,
     managing HTTP cookies, controlling	access,	and removing ads,
     banners,  pop-ups and other obnoxious Internet junk. Privoxy
     has a flexible configuration and can be customized	 to  suit
     individual	 needs	and  tastes.  Privoxy has application for
     both stand-alone systems and multi-user networks.

     Privoxy is	based on Internet Junkbuster (tm).

INSTALLATION AND USAGE
     Browsers  can  either  be	individually  configured  to  use
     Privoxy  as  a  HTTP  proxy (recommended),	or Privoxy can be
     combined with a packet filter to build an intercepting proxy
     (see  config).   The  default setting is  for localhost,  on
     port  8118	(configurable in the main config file).	  To  set
     the  HTTP	proxy in Netscape and Mozilla, go through:  Edit;
     Preferences;  Advanced; Proxies;	Manual	Proxy  Configura-
     tion; View.

     For Firefox, go through: Tools; Options; General; Connection
     Settings; Manual Proxy Configuration.

     For Internet Explorer, go through:	Tools;	Internet  Proper-
     ties; Connections;	LAN Settings.

     The Secure	(SSL) Proxy  should  also  be  set  to	the  same
     values,  otherwise	 https:	 URLs  will not	be proxied. Note:
     Privoxy can only proxy HTTP and HTTPS traffic. Do not try it
     with  FTP	or  other protocols.  HTTPS presents some limita-
     tions, and	not all	features will  work  with  HTTPS  connec-
     tions.

     For other browsers, check the documentation.

CONFIGURATION
     Privoxy can be configured	with  the  various  configuration
     files.   The   default   configuration  files  are:  config,
     default.filter, and default.action.  user.action  should  be
     used  for locally defined exceptions to the default rules of
     default.action, and user.filter for locally defined filters.
     These  are	 well  commented.  On Unix and Unix-like systems,
     these are located in /etc/privoxy/	by default.

     Privoxy uses the concept of actions in order  to  manipulate
     the data stream between the browser and remote sites.  There
     are various actions available with	 specific  functions  for
     such  things  as  blocking	web sites, managing cookies, etc.



Privoxy	3.0.8	  Last change: 19 January 2008			2






User Commands					       PRIVOXY(1)



     These actions can be invoked individually or  combined,  and
     used  against individual URLs, or groups of URLs that can be
     defined using wildcards and regular expressions. The  result
     is	that the user has greatly enhanced control and freedom.

     The actions list (ad blocks, etc)	can  also  be  configured
     with  your	web browser at http://config.privoxy.org/ (assum-
     ing the configuration allows it).	 Privoxy's  configuration
     parameters	  can  also  be	viewed at the same page. In addi-
     tion, Privoxy can be toggled on/off.  This	 is  an	 internal
     page, and does not	require	Internet access.

     See the User Manual for a detailed	explanation of	installa-
     tion, general usage, all configuration options, new features
     and notes on upgrading.

SAMPLE CONFIGURATION
     A brief example of	what a simple  default.action  configura-
     tion might	look like:

      #	Define a few useful custom aliases for later use
      {{alias}}

      #	Useful aliases that combine more than one action
      +crunch-cookies =	+crunch-incoming-cookies +crunch-outgoing-cookies
      -crunch-cookies =	-crunch-incoming-cookies -crunch-outgoing-cookies
      +block-as-image =	+block +handle-as-image

      #	Fragile	sites should have the minimum changes
      fragile	  = -block -deanimate-gifs -fast-redirects -filter \
		    -hide-referer -prevent-cookies -kill-popups

      ## Turn some actions on ################################
      ## NOTE: Actions are off by default, unless explictily turned on
      ## otherwise with	the '+'	operator.

     { \
     +deanimate-gifs{last} \
     +filter{refresh-tags} \
     +filter{img-reorder} \
     +filter{banners-by-size} \
     +filter{webbugs} \
     +filter{jumping-windows} \
     +filter{ie-exploits} \
     +hide-forwarded-for-headers \
     +hide-from-header{block} \
     +hide-referrer{conditional-block} \
     +session-cookies-only \
     +set-image-blocker{pattern} \
     }
     / # '/' Match *all* URL patterns




Privoxy	3.0.8	  Last change: 19 January 2008			3






User Commands					       PRIVOXY(1)




      #	Block all URLs that match these	patterns
      {	+block }
       ad.
       ad[sv].
       .*ads.
       banner?.
       /.*count(er)?\.(pl|cgi|exe|dll|asp|php[34]?)
       .hitbox.com
       media./.*(ads|banner)

      #	Block, and treat these URL patterns as if they were 'images'.
      #	We would expect	these to be ads.
      {	+block-as-image	}
       .ad.doubleclick.net
       .a[0-9].yimg.com/(?:(?!/i/).)*$
       ad.*.doubleclick.net

      #	Make exceptions	for these harmless ones	that would be
      #	caught by our +block patterns just above.
      {	-block }
       adsl.
       adobe.
       advice.
       .*downloads.
       # uploads or downloads
       /.*loads

     Then for a	user.action, we	would put local, narrowly defined
     exceptions:

      #	Re-define aliases as needed here
      {{alias}}

      #	Useful aliases
      -crunch-cookies =	-crunch-incoming-cookies -crunch-outgoing-cookies

      #	Set personal exceptions	to the policies	in default.action #######

      #	Sites where we want persistent cookies,	so allow *all* cookies
      {	-crunch-cookies	-session-cookies-only }
       .redhat.com
       .sun.com
       .msdn.microsoft.com

      #	These sites break easily. Use our "fragile" alias here.
      {	fragile	}
       .forbes.com
       mybank.example.com

      #	Replace	example.com's style sheet with one of my choosing
      {	+redirect{http://localhost/css-replacements/example.com.css} }



Privoxy	3.0.8	  Last change: 19 January 2008			4






User Commands					       PRIVOXY(1)



       .example.com/stylesheet.css

     See the comments in the configuration files  themselves,  or
     the  User	Manual for full	explanations of	the above syntax,
     and other Privoxy configuration options.

FILES

      /usr/sbin/privoxy
      /etc/privoxy/config
      /etc/privoxy/default.action
      /etc/privoxy/standard.action
      /etc/privoxy/user.action
      /etc/privoxy/default.filter
      /etc/privoxy/user.filter
      /etc/privoxy/trust
      /etc/privoxy/templates/*
      /var/log/privoxy/logfile

     Various other files should	be included, but may vary depend-
     ing on platform and build configuration. Additional documen-
     tation should be included in the local documentation  direc-
     tory.

SIGNALS
     Privoxy terminates	on the SIGINT, SIGTERM and  SIGABRT  sig-
     nals.  Log	 rotation  scripts  may	cause a	re-opening of the
     logfile by	sending	a SIGHUP to  Privoxy.  Note  that  unlike
     other  daemons,   Privoxy	does not need to be made aware of
     config file  changes  by  SIGHUP  --  it  will  detect  them
     automatically.

NOTES
     Please see	the User Manual	on how to contact the developers,
     for  feature  requests,  reporting	problems, and other ques-
     tions.

SEE ALSO
     Other references and sites	of interest to Privoxy users:

     http://www.privoxy.org/, the Privoxy Home page.

     http://www.privoxy.org/faq/, the Privoxy FAQ.

     http://sourceforge.net/projects/ijbswa/,  the  Project  Page
     for Privoxy on SourceForge.

     http://config.privoxy.org/, the  web-based	 user  interface.
     Privoxy   must  be	 running  for  this  to	 work.	Shortcut:
     http://p.p/

     http://sourceforge.net/tracker/?group_id=11118&atid=460288,



Privoxy	3.0.8	  Last change: 19 January 2008			5






User Commands					       PRIVOXY(1)



     to	submit ``misses'' and other configuration related sugges-
     tions to the developers.

     http://www.junkbusters.com/ht/en/cookies.html,  an	 explana-
     tion how cookies are used to track	web users.

     http://www.junkbusters.com/ijb.html, the  original	 Internet
     Junkbuster.

     http://privacy.net/, a useful site	to check what information
     about you is leaked while you browse the web.

     http://www.squid-cache.org/, a popular caching proxy,  which
     is	often used together with Privoxy.

     http://www.pps.jussieu.fr/~jch/software/polipo/, Polipo is	a
     caching proxy with	advanced features like pipelining, multi-
     plexing and caching of partial instances. In many setups  it
     can be used as Squid replacement.

     http://tor.eff.org/, Tor can help	anonymize  web	browsing,
     web  publishing,  instant	messaging,  IRC,  SSH,	and other
     applications.

     http://www.privoxy.org/developer-manual/,	  the	  Privoxy
     developer manual.

DEVELOPMENT TEAM
      Fabian Keil, lead	developer
      David Schmidt, developer

      Hal Burgiss
      Gerry Murphy
      Roland Rosenfeld
      Jrg Strohmayer

COPYRIGHT AND LICENSE
  COPYRIGHT
     Copyright	(C)  2001-2008	by  Privoxy  Developers	 <ijbswa-
     developers@lists.sourceforge.net>

     Some source code is based on  code	 Copyright  (C)	 1997  by
     Anonymous	Coders	and  Junkbusters, Inc. and licensed under
     the GNU General Public License.

  LICENSE
     Privoxy is	free software; you  can	 redistribute  it  and/or
     modify it under the terms of the GNU General Public License,
     version 2,	as published by	the Free Software Foundation.

     This program is distributed in the	hope that it will be use-
     ful,  but	WITHOUT	 ANY  WARRANTY;	 without even the implied



Privoxy	3.0.8	  Last change: 19 January 2008			6






User Commands					       PRIVOXY(1)



     warranty of MERCHANTABILITY or FITNESS FOR	A PARTICULAR PUR-
     POSE.   See the GNU General Public	License	for more details,
     which is available	from the Free Software	Foundation,  Inc,
     51	Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA

     You should	have received a	copy of	the  GNU  General  Public
     License  along with this program; if not, write to	the  Free
     Software Foundation, Inc. 51 Franklin  Street,  Fifth  Floor
     Boston, MA	02110-1301 USA














































Privoxy	3.0.8	  Last change: 19 January 2008			7




--Boundary_(ID_OsgtLrIDVgeRIa+hGWjTGA)--

From james.gates@sun.com Wed Jul  9 10:07:38 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m69H7cEX016505
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 9 Jul 2008 10:07:38 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m69H7XaU002739;
	Wed, 9 Jul 2008 10:07:35 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3R00C0J0WMLI00@brm-avmta-1.central.sun.com>; Wed,
 09 Jul 2008 11:07:34 -0600 (MDT)
Received: from dm-uk-01.uk.sun.com ([129.156.101.115])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3R000TH0WLGZD0@brm-avmta-1.central.sun.com>; Wed,
 09 Jul 2008 11:07:34 -0600 (MDT)
Received: from serinus.UK.Sun.COM (serinus.UK.Sun.COM [129.156.173.208])
	by dm-uk-01.uk.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2)
 with ESMTP id m69H7VkD014594; Wed, 09 Jul 2008 18:07:31 +0100 (BST)
Received: from [192.168.1.100] (vpn-129-150-65-60.East.Sun.COM [129.150.65.60])
	by serinus.UK.Sun.COM (8.13.7+Sun/8.13.7/CTE 3.0)
 with ESMTP id m69H709R025567; Wed, 09 Jul 2008 18:07:08 +0100 (BST)
Date: Wed, 09 Jul 2008 13:06:17 -0400
From: James Gates <james.gates@sun.com>
Subject: Re: Integrate privoxy into Solaris [LSARC/2008/433 FastTrack timeout
 07/17/2008]
In-reply-to: <4874EDF3.7040603@sun.com>
To: lsarc-ext@sun.com
Cc: Venky <venkytv@sun.com>, one-pager-list@sac.sfbay.sun.com,
        one-pager-log@sac.sfbay.sun.com, sac-bar@sac.sfbay.sun.com
Message-id: <4874F009.8090405@sun.com>
MIME-version: 1.0
Content-type: multipart/mixed; boundary="Boundary_(ID_nDZw3ChpS7M02/nBtn9pvg)"
X-Accept-Language: en-us, en
X-PMX-Version: 5.4.1.325704
References: <4874EDF3.7040603@sun.com>
User-Agent: Mozilla/5.0 (X11; U; SunOS sun4u; en-US; rv:1.7.13) Gecko/20060509
Status: RO
Content-Length: 21086

This is a multi-part message in MIME format.

--Boundary_(ID_nDZw3ChpS7M02/nBtn9pvg)
Content-type: text/plain; charset=us-ascii; format=flowed
Content-transfer-encoding: 7BIT

Sorry, attached is the correct checklist. The one I originally sent 
included a couple of incorrectly set "ARC review required" fields. The 
case materials directory is also updated.

James Gates wrote:
> I'm sponsoring this fast-track case for Venky Tv. The case would have 
> been automatically approved as a FOSS check list fast track if it were 
> not for the following issue:
> 
> If yes do the components support IPv6?
>  >        [ ] Yes
>  >        [X] No - ARC review required
> 
> I'm not too sure what we can discuss here. As the community haven't 
> really warmed to IPv6, I would have thought that lack of IPv6 support is 
> the norm, not the exception. What would be the outcome of an ARC 
> discussion - Would you insist that the community implement IPv6 support? 
> Would integration be stalled until IPv6 support is enabled?
> 
> Anyway, the timer expires on 07/17/2008.
> 
> All associated docs are in the case materials directory (and attached 
> here).

--Boundary_(ID_nDZw3ChpS7M02/nBtn9pvg)
Content-type: text/plain; name=privoxy-checklist.txt
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=privoxy-checklist.txt

FCL--FOSS Check List
0.  Introduction
0.1 Document History
    Version   Author             Changes					Date
    0.1       John Fischer       Initial Draft					01/11/2008
    0.2       John Fischer       Modified based upon feedback from ARC members	01/29/2008
    0.3       John Fischer       Modified based upon feedback during committee 	02/12/2008
                                 review
    0.4       John Fischer       Modified based upon SAC review feedback	04/01/2008
    0.5	      John Fischer	 Modified based upon LSARC business meeting	06/10/2008
                                 adding familiarity question and mod dates.
    0.6       John Fischer       Modified based upon user feedback about        06/20/2008
                                 sections that were unanswerable.

0.2 Purpose
    Architecture review at Sun has allowed the company to evolve our projects
    within multiple disjoint groups while still maintaining a cohesive product
    line.  Each architecture review was conducted within Sun's control.  With
    the advent of Free Open Source Software processes the control that Sun as
    a company can wield has been diminished.  Now that Sun is moving to a more
    fluid delivery mechanism with project Indiana we need to evolve the 
    architecture review process.  This document is meant to aid in the 
    architecture review process.  Each new project must complete this check list 
    to help ensure that the overall resulting product conforms to Sun product 
    standards.  If the project deviates from these standards further review 
    would be necessary by an architecture review committee.
    
    After the check list is completed the project team should be able to 
    determine if a project can be automatically approved.  This will occur
    if all checks result in no "ARC review required" answers.  A committee
    member will assist the project team in filing the automatically approved 
    fast track.  An automatically approved fast track is still required in order
    to record the interfaces for future reference.  If the project needs to 
    have further review then follow the regular process for getting projects 
    reviewed.

1.0 Project Information
1.1 Name of project/component
    Privoxy: A non-caching web proxy with advanced filtering capabilities

1.2 Author of document
    Venky TV

2.0 Project Summary
  2.1 Project Description
      Privoxy is a non-caching web proxy with advanced filtering capabilities
      for enhancing privacy, modifying web page data, managing HTTP cookies,
      controlling access, and removing ads, banners, pop-ups and other obnoxious
      Internet junk. Privoxy has a flexible configuration and can be customized
      to suit individual needs and tastes.  Privoxy has application for both
      stand-alone systems and multi-user networks.

      Privoxy applies to only HTTP and HTTPS traffic.
  
  2.2 Release binding
      What is is the release binding?
      (see http://opensolaris.org/os/community/arc/policies/release-taxonomy/)
      [ ] Major
      [X] Minor
      [ ] Patch or Micro
      [ ] Unknown -- ARC review required

  2.3 Type of project
      Is this case a Linux Familiarity project?
      [X] Yes
      [ ] No

  2.4 Originating Community
    2.4.1 Community Name
          Privoxy
    
    2.4.2 Community Involvement
      Indicate Sun's involvement in the community
      [ ] Maintainer
      [ ] Contributor
      [X] Monitoring
      
      Will the project team work with the upstream community to resolve
      architectural issues of interest to Sun?
      [X] Yes 
      [ ] No - briefly explain
      
      Will we or are we forking from the community?
      [ ] Yes - ARC review required prior to forking
      [X] No
      
3.0 Technical Description
  3.1 Installation & Sharable
    3.1.1S Solaris Installation - section only required for Solaris Software
      (see http://opensolaris.org/os/community/arc/policies/install-locations/ for details)
      Does this project follow the Install Locations best practice?
      [X] Yes 
      [ ] No - ARC review required
      
      Does this project install into /usr under [sbin|bin|lib|include|man|share]?
      [X] Yes
      [ ] No or N/A
      
      Does this project install into /opt?
      [ ] Yes - explain below
      [X] No or N/A
      
      Does this project install into a different directory structure?
      [ ] Yes - ARC review required
      [X] No or N/A
      
      Do any of the components of this project conflict with anything under /usr?
      (see http://opensolaris.org/os/community/arc/caselog/2007/047/ for details)
      [ ] Yes - explain below
      [X] No
      
      If conflicts exist then will this project install under /usr/gnu?
      [ ] Yes
      [ ] No - ARC review required
      [X] N/A
      
      Is this project installing into /usr/sfw?
      [ ] Yes - ARC review required
      [X] No
      
    3.1.1W Windows Installation - section only required for Windows Software
      (see http://sac.sfbay/WSARC/2002/494 for details)
      Does this project install software into a 
      <system drive>:\Program Files\Sun\<product> or <system drive>:\Sun\<product>
      directory?
      [ ] Yes
      [ ] No - ARC review required
      
      Does the project use the Windows registry?
      [ ] Yes
      [ ] No - ARC review required
      
      Does the project use 
      HKEY_LOCAL_MACHINE\SOFTWARE\Sun Microsystems\<product>\<version>
      for the registry key?
      [ ] Yes
      [ ] No - ARC review required
      
      Is the project's stored location
      HKEY_LOCAL_MACHINE\SOFTWARE\Sun Microsystems\<product id>\<version id>\Path?
      [ ] Yes
      [ ] No - ARC review required
      
    3.1.2 Share and Sharable
      Does the module include any components that are used or shared by 
      other projects?
      [ ] Yes
      [X] No
    
      If yes are these components packaged to be shared with the other FOSS?
      [ ] Yes
      [ ] No - ARC review required
      [X] N/A
    
      Are these components already in the Solaris WOS?
      [ ] Yes
      [X] No - continue with next section (section 3.2)
    
      If yes are these newer versions being delivered?
      [ ] Yes
      [ ] No - ARC review required
      
      If yes are the newer versions replacing the existing versions?
      [ ] Yes
      [ ] No - ARC review required

  3.2 Exported Libraries
      Are libraries being delivered by this project?
      [ ] Yes
      [X] No - continue with next section (section 3.3)
      
      Are 64-bit versions of the libraries being delivered?
      [ ] Yes
      [ ] No - ARC review required
    
      Are static versions of the libraries being delivered?
      [ ] Yes - ARC review required
      [ ] No 
      
  3.3 Services and the /etc Directory
      (see http://opensolaris.org/os/community/arc/policies/SMF-policy/)
      Does the project integrate anything into /etc/init.d or /etc/rc?.d?
      [ ] Yes - ARC review required
      [X] No
      
      Does the project integrate any new entries into /etc/inittab or
      /etc/inetd.conf?
      [ ] Yes - ARC review required
      [X] No
      
      Does the project integrate any private non-public files into /etc/default
      or /etc/ configuration files?
      [ ] Yes - ARC review required
      [X] No
      
      Does the service manifests method context grant rights above that
      of the noaccess user and basic privilege set?
      [ ] Yes - ARC review required
      [X] No
        
  3.4 Security
    3.4.1 Secure By Default 
      (see http://opensolaris.org/os/community/arc/policies/secure-by-default/ for details)
      (see http://www.opensolaris.org/os/community/arc/policies/NITS-policy/ for details)
      (see parts of http://opensolaris.org/os/community/arc/policies/SMF-policy/ for
       addtional details)
      Are there any network services provided by this project?
      [X] Yes
      [ ] No - continue with the next section (section 3.4.2)
      
      Are network services enabled by default?
      [ ] Yes - ARC review required
      [X] No
      [ ] N/A
      
      Are network services automatically enabled by the project during installation?
      [ ] Yes - ARC review required
      [X] No
      [ ] N/A
      
      Are inbound network communications denied by default?
      [X] Yes
      [ ] No - ARC review required
      [ ] N/A
      
      Is inbound data checked to prevent content-based attacks?
      [ ] Yes
      [ ] No - ARC review required
      [X] N/A
      
      Is the outbound receiver authenticated?
      [ ] Yes
      [ ] No - ARC review required
      [X] N/A
      
      Is the receiver authenticated prior to receiving any sensitive outbound communication?
      [ ] Yes
      [ ] No - ARC review required
      [X] N/A
      
    3.4.2 Authorization
      (see http://opensolaris.org/os/community/arc/bestpractices/rbac-intro/ and
	   http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/ and
	   http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/
           for details)
      Are there any setuid/setgid privileged binaries in the project?
      [ ] Yes - ARC review required
      [X] No - continue with next section (section 3.4.3)
      
      If yes then are the setuid/setgid privileges handled by the use of roles?
      [ ] Yes
      [ ] No - ARC review required

    3.4.3 Auditing
      (see http://opensolaris.org/os/community/arc/policies/audit-policy/ for details)
      (see http://opensolaris.org/os/community/arc/caselog/2003/397 for details)
      Does this component contain administrative or security enforcing software?
      [ ] Yes - ARC review required
      [X] No - continue to next section (section 3.4.4)
      
      (see http://opensolaris.org/os/community/arc/caselog/2003/397 for details)
      Do the components create audit logs detailing what took place including what event
      took place, who was involved, when the event took place?
      [ ] Yes - ARC contract and Audit project team review required
      [ ] No - ARC review required
        
        
    3.4.4 Authentication
      (see http://opensolaris.org/os/community/arc/policies/PAM/)
      Do the components contain any authentication code?
      [ ] Yes
      [X] No - continue to next section (section 3.4.5)
      
      If yes do the components use PAM (plugable authentication modules) for authentication?
      [ ] Yes
      [ ] No - ARC review required
      
      If yes is a single PAM session maintained during authentication?
      [ ] Yes
      [ ] No - ARC review required
      
      If yes are the components sufficiently privileged to allow the requested 
      operations (authentication, password change, process credential manipulation, 
      audit state initialization)?
      [ ] Yes - briefly describe below
      [ ] No - ARC review required
      
    3.4.5 Passwords
      (see http://opensolaris.org/os/community/arc/bestpractices/passwords-cli/ and
           http://opensolaris.org/os/community/arc/bestpractices/passwords-files/ for details)
      Do any of the components for the project deal with passwords?
      [ ] Yes
      [X] No - continue to next section (section 3.4.6)
      
      If yes are these passwords entered via the CLI or environment?
      [ ] Yes - ARC review required
      [ ] No
      
      Are passwords stored within the file system for the component?
      [ ] Yes
      [ ] No - continue to next section (section 3.4.6)
      
      If yes are the permissions on the file such to protect exposing the password(s)?
      [ ] Yes
      [ ] No - ARC review required
      
    3.4.6 General Security Questions
      (see http://opensolaris.org/os/community/arc/bestpractices/security-questions/ for details)
      Are there any network protocols used by this project?
      [X] Yes
      [ ] No - continue with the next section (section 3.5)
      
      Do the components use standard network protocols?
      [X] Yes
      [ ] No - ARC review required
      
      Do network services for the project make decisions based upon user, host or 
      service identities?
      [X] Yes - explain below
      [ ] No
      [ ] N/A

      ACLs based on hostnames and IP addresses can be used to restrict access to
      the Privoxy proxy server.
      
      Do the components make use of secret information during authentication and/or
      authorization?
      [ ] Yes - explain below
      [X] No
      [ ] N/A
  
  3.5 Networking
      Do the components access the network?
      [X] Yes
      [ ] No - continue with the next section (section 3.6)
      
      If yes do the components support IPv6?
      [ ] Yes 
      [X] No - ARC review required
          
  3.6 Core Solaris Components
      Do the components of this project compete with or duplicate core 
      Solaris components?
      [ ] Yes - ARC review required
      [X] No 
      
      Examples of Core Solaris Components include but are not limited to:
      
        Secure By Default
        Authorizations
        PAM -- Plugable Authentication Module
        Privilege
        PRM -- Process Rights Management -- Privilege
        Audit
        xVm -- Virtualization
        zones / Solaris Containers
        PRM -- Process Rights Management
        RBAC -- Role Based Access Control
        TX / Trusted Extensions
        ZFS
        SMF -- Service Management Facility
        FMA -- Fault Management Architecture
        SCF -- Smart Card Facility
        IPsec
        
4.0 Interfaces
  (see http://www.opensolaris.org/os/community/arc/policies/interface-taxonomy/ for details)
  4.1 Exported Interfaces
  
    Interface Name		Classification      Comments
    --------------------------- ------------------- ---------------------------
    SUNWprivoxy                 Uncommitted         Package name
    /usr/sbin/privoxy           Committed           Executable location
    /lib/svc/method/http-privoxy
                                Committed           SMF Service method
    /var/svc/manifest/network/http-privoxy.xml
                                Commited            SMF Manifest
                                                    Controls the privoxy daemon
    /etc/privoxy/config         Volatile            Main configuration file
    /etc/privoxy/*.action       Volatile            Configuration files -
                                                    Defines URL-based actions
    /etc/privoxy/*.filter       Volatile            Configuration files -
                                                    Header and content rewrite
                                                    rules
    /etc/privoxy/templates/*    Volatile            Template files for the
                                                    web-based user interface
    /etc/privoxy/trust          Volatile            Configuration file -
                                                    Whitelist of allowed sites
    /usr/share/doc/privoxy/*    Volatile            Documentation files
    /usr/share/man/man1/privoxy.1
                                Volatile            Manpage
    /var/log/privoxy/jarfile    Volatile            Stores intercepted browser
                                                    cookies
    /var/log/privoxy/logfile    Volatile            Log file
    privoxy                     Volatile            Commandline syntax
    privoxy output              -                   Not an interface

    A complete list of files delivered by the privoxy package is included
    in the privoxy-interfaces.txt file.
    
  4.2 Imported Interfaces
    Interface Name		         Classification       Comments
    ---------------------------  -------------------- --------------------------
    Standard C Library Functions Committed
          
  Brief Interface Classifications - See Appendix C for definitions
    Volatile - interfaces are fluid and will follow a rapidly changing community
    Uncommitted - interfaces are still evolving in the community and might follow
		  the community
    Committed - interfaces are stable in the community
    Project Private - no review required, just document in table
    Contracted (interface modifier) - further review required

Appendix A - References
  1.  Solaris Installation Locations Policy
      http://opensolaris.org/os/community/arc/policies/install-locations/
  2.  /usr/gnu Installation ARC case
      http://opensolaris.org/os/community/arc/caselog/2007/047/
  3.  Secure By Default Policy
      http://opensolaris.org/os/community/arc/policies/secure-by-default/
  4.  Network Install Time Securityuy Policy
      http://www.opensolaris.org/os/community/arc/policies/NITS-policy/
  5.  Adding RBAC Authorizations Policy
      http://opensolaris.org/os/community/arc/bestpractices/rbac-auths/
  6.  When to use setuid -vs- RBAC roles and profiles
      http://opensolaris.org/os/community/arc/bestpractices/rbac-intro/ and
  7.  Building RBAC Rights Profiles
      http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/
  8.  Solaris Audit Policy
      http://opensolaris.org/os/community/arc/policies/audit-policy/
  9.  Security questionaire
      http://opensolaris.org/os/community/arc/bestpractices/security-questions/
  10. Interface Taxonomy
      http://www.opensolaris.org/os/community/arc/policies/interface-taxonomy/
  11. Plugable Authentication Modules -- PAM
      http://opensolaris.org/os/community/arc/policies/PAM/
  12. Reusable Passwords In Command Line Arguments and Environment Variables
      http://opensolaris.org/os/community/arc/bestpractices/passwords-cli/
  13. Storing Reusable Passwords on a Filesystem
      http://opensolaris.org/os/community/arc/bestpractices/passwords-files/
  14. Release Taxonomy
      http://opensolaris.org/os/community/arc/policies/release-taxonomy/
  15. Service Management Facility (SMF) usage
      http://opensolaris.org/os/community/arc/policies/SMF-policy/

  
Appendix B - Suggested case materials
  1. man pages
  2. SMF manifests
  3. links to contracts
  
Appendix C - Definitions
Submitter
     an agent responsible for creation of an ARC project along with the
     materials describing that project.
Owner
     the ARC agent responsible for shepherding the case through review
     and ensuring a formal opinion is written where required.
Maintainer
     an agent responsible for releasing new versions of a program, typically
     the "main" contributor or person incharge of making Architectural
     decisions for the project
Contributor
     an agent who make contributions to a project, typically has a voice in
     making Architectural decisions for the project
Monitoring
     an agent who is only following the changes made in the community and
     has no Architectural input into the project
Volatile*
    interfaces that are very fluid and typically follow the originating 
    community.  Typically these interfaces can not be imported by other
    projects.
Uncommitted*
    interfaces that are still evolving but will most likely be present from
    release to release.
Committed*
    interfaces that are stable and with Sun guaranteeing some level of
    compatibility from release to release.
Project Private*
    interfaces that are exposed only to or intended to be used only by
    the project being reviewed.  These interfaces can not be imported by
    other projects.
Not-An-Interface*
    components that are not interfaces.
Contracted* (interface modifier) - ARC review of Contract required
    interfaces that do not allow another project to import can be 

*Note: see http://opensolaris.org/os/community/arc/policies/interface-taxonomy/ for details

--Boundary_(ID_nDZw3ChpS7M02/nBtn9pvg)--

From danek.duvall@Sun.COM Wed Jul  9 10:11:45 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m69HBjEk016591
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 9 Jul 2008 10:11:45 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m69HBglh004259;
	Wed, 9 Jul 2008 10:11:43 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3R00C0713JWF00@brm-avmta-1.central.sun.com>; Wed,
 09 Jul 2008 11:11:43 -0600 (MDT)
Received: from dm-sfbay-02.sfbay.sun.com ([129.146.11.31])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3R0002C13IGYE0@brm-avmta-1.central.sun.com>; Wed,
 09 Jul 2008 11:11:42 -0600 (MDT)
Received: from zruty.sfbay.sun.com (zruty.SFBay.Sun.COM [129.146.168.40])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id m69HBeZL025647; Wed, 09 Jul 2008 10:11:40 -0700 (PDT)
Received: from zruty.sfbay.sun.com (localhost [127.0.0.1])
	by zruty.sfbay.sun.com (8.14.2+Sun/8.14.2) with ESMTP id m69HBeJE013058; Wed,
 09 Jul 2008 10:11:40 -0700 (PDT)
Received: (from dduvall@localhost)
	by zruty.sfbay.sun.com (8.14.2+Sun/8.14.2/Submit) id m69HBeel013057; Wed,
 09 Jul 2008 10:11:40 -0700 (PDT)
Date: Wed, 09 Jul 2008 10:11:40 -0700
From: Danek Duvall <danek.duvall@Sun.COM>
Subject: Re: Integrate privoxy into Solaris [LSARC/2008/433 FastTrack	timeout
 07/17/2008]
In-reply-to: <4874EDF3.7040603@sun.com>
To: James Gates <james.gates@Sun.COM>
Cc: lsarc-ext@Sun.COM, Venky <venkytv@Sun.COM>
Message-id: <20080709171140.GG1920@zruty.sfbay.sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <4874EDF3.7040603@sun.com>
User-Agent: Mutt/1.5.16 (2007-06-27)
Status: RO
Content-Length: 673

On Wed, Jul 09, 2008 at 12:57:23PM -0400, James Gates wrote:

>         /usr/sbin/privoxy       Committed               Executable location

Why /usr/sbin rather than /usr/bin?  Would a user never run this
individually?

>         /lib/svc/method/privoxy Committed               SMF Service method

Why is this Committed, rather than just an Project Private implementation
detail?

Also note that the SMF FMRI (as well as any config vars it exports, though
it looks like there aren't any here) should be one of the interfaces you
note here.  Not the manifest file -- that's not an interface, either.  (Nor
is any documentation, though you have that listed as well).

Danek

From Nicolas.Williams@sun.com Wed Jul  9 10:20:59 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m69HKwCl017911
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 9 Jul 2008 10:20:59 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m69HKquG003473;
	Wed, 9 Jul 2008 18:20:54 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3R00D0F1ITL200@brm-avmta-1.central.sun.com>; Wed,
 09 Jul 2008 11:20:53 -0600 (MDT)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3R0000O1ISGYF0@brm-avmta-1.central.sun.com>; Wed,
 09 Jul 2008 11:20:52 -0600 (MDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1) with ESMTP id m69HKqcP015457;
 Wed, 09 Jul 2008 12:20:52 -0500 (CDT)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1/Submit) id m69HKqmM015456; Wed,
 09 Jul 2008 12:20:52 -0500 (CDT)
Date: Wed, 09 Jul 2008 12:20:51 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
Subject: Re: Integrate privoxy into Solaris [LSARC/2008/433 FastTrack	timeout
 07/17/2008]
In-reply-to: <20080709171140.GG1920@zruty.sfbay.sun.com>
To: Danek Duvall <danek.duvall@sun.com>
Cc: James Gates <james.gates@sun.com>, lsarc-ext@sun.com,
        Venky <venkytv@sun.com>
Message-id: <20080709172051.GH2735@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <4874EDF3.7040603@sun.com>
 <20080709171140.GG1920@zruty.sfbay.sun.com>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 345

On Wed, Jul 09, 2008 at 10:11:40AM -0700, Danek Duvall wrote:
> On Wed, Jul 09, 2008 at 12:57:23PM -0400, James Gates wrote:
> 
> >         /usr/sbin/privoxy       Committed               Executable location
> 
> Why /usr/sbin rather than /usr/bin?  Would a user never run this
> individually?

If it's a daemon then it should live in /usr/lib.

From Darren.Moffat@sun.com Wed Jul  9 10:23:48 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m69HNlEG018430
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 9 Jul 2008 10:23:48 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m69HNVWQ004935;
	Wed, 9 Jul 2008 18:23:45 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3R00G091NJM600@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 09 Jul 2008 10:23:43 -0700 (PDT)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3R00LTK1NIGDB0@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 09 Jul 2008 10:23:43 -0700 (PDT)
Received: from fe-emea-10.sun.com (gmp-eb-lb-2-fe3.eu.sun.com [192.18.6.12])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m69HNgNh013631; Wed,
 09 Jul 2008 17:23:42 +0000 (GMT)
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K3R00F011FDAJ00@fe-emea-10.sun.com>
 (original mail from Darren.Moffat@Sun.COM); Wed,
 09 Jul 2008 18:23:42 +0100 (BST)
Received: from [129.156.173.21] by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K3R00ALM1NGGA60@fe-emea-10.sun.com>; Wed,
 09 Jul 2008 18:23:41 +0100 (BST)
Date: Wed, 09 Jul 2008 18:23:40 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: Integrate privoxy into Solaris [LSARC/2008/433 FastTrack	timeout
 07/17/2008]
In-reply-to: <20080709171140.GG1920@zruty.sfbay.sun.com>
Sender: Darren.Moffat@sun.com
To: Danek Duvall <Danek.Duvall@sun.com>
Cc: James Gates <James.Gates@sun.com>, lsarc-ext@sun.com,
        Venky <venkytv@sun.com>
Message-id: <4874F41C.7070801@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <4874EDF3.7040603@sun.com>
 <20080709171140.GG1920@zruty.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.14 (X11/20080602)
Status: RO
Content-Length: 1045

Danek Duvall wrote:
> On Wed, Jul 09, 2008 at 12:57:23PM -0400, James Gates wrote:
> 
>>         /usr/sbin/privoxy       Committed               Executable location
> 
> Why /usr/sbin rather than /usr/bin?  Would a user never run this
> individually?


I was thinking that given there is an SMF service for this why shouldn't 
it be somewhere under /usr/lib/

>>         /lib/svc/method/privoxy Committed               SMF Service method
> 
> Why is this Committed, rather than just an Project Private implementation
> detail?
> 
> Also note that the SMF FMRI (as well as any config vars it exports, though
> it looks like there aren't any here) should be one of the interfaces you
> note here.  Not the manifest file -- that's not an interface, either.  (Nor
> is any documentation, though you have that listed as well).

Agreed it is the FMRI that is interest the method script as you said 
should almost always be Project Private [ particularly if it is 
something under /lib/svc/method rather than an existing command ]

-- 
Darren J Moffat

From danek.duvall@sun.com Wed Jul  9 11:03:00 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m69I3031019785
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 9 Jul 2008 11:03:00 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m69I2vjI039622;
	Wed, 9 Jul 2008 12:02:58 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3R0080T3GXKT00@nwk-avmta-2.sfbay.sun.com>; Wed,
 09 Jul 2008 11:02:57 -0700 (PDT)
Received: from dm-sfbay-01.sfbay.sun.com ([129.145.155.118])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3R0075A3GWD220@nwk-avmta-2.sfbay.sun.com>; Wed,
 09 Jul 2008 11:02:56 -0700 (PDT)
Received: from zruty.sfbay.sun.com (zruty.SFBay.Sun.COM [129.146.168.40])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id m69I2sWW020931; Wed, 09 Jul 2008 11:02:54 -0700 (PDT)
Received: from zruty.sfbay.sun.com (localhost [127.0.0.1])
	by zruty.sfbay.sun.com (8.14.2+Sun/8.14.2) with ESMTP id m69I2rGp014172; Wed,
 09 Jul 2008 11:02:54 -0700 (PDT)
Received: (from dduvall@localhost)
	by zruty.sfbay.sun.com (8.14.2+Sun/8.14.2/Submit) id m69I2rbq014171; Wed,
 09 Jul 2008 11:02:53 -0700 (PDT)
Date: Wed, 09 Jul 2008 11:02:53 -0700
From: Danek Duvall <danek.duvall@sun.com>
Subject: Re: Integrate privoxy into Solaris [LSARC/2008/433 FastTrack	timeout
 07/17/2008]
In-reply-to: <4874F41C.7070801@Sun.COM>
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: James Gates <James.Gates@sun.com>, lsarc-ext@sun.com,
        Venky <venkytv@sun.com>
Message-id: <20080709180253.GJ1920@zruty.sfbay.sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <4874EDF3.7040603@sun.com>
 <20080709171140.GG1920@zruty.sfbay.sun.com> <4874F41C.7070801@Sun.COM>
User-Agent: Mutt/1.5.16 (2007-06-27)
Status: RO
Content-Length: 627

On Wed, Jul 09, 2008 at 06:23:40PM +0100, Darren J Moffat wrote:

> I was thinking that given there is an SMF service for this why shouldn't
> it be somewhere under /usr/lib/

<shrug> Maybe.  If people are used to running it by hand, or from a startup
script (I run a similar daemon from my .xsession), then having it in
/usr/bin may be useful.  If it's strictly intended as a system-wide daemon,
then /usr/lib would be more appropriate.

Unfortunately, Linux apps go into /usr/sbin for two different reasons --
either they're intended for superuser use only, or they're daemons.  It's
not clear how to tell them apart.

Danek

From carlsonj@phorcys.east.sun.com Wed Jul  9 11:57:59 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m69IvxCD021345
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 9 Jul 2008 11:57:59 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m69IvtlS009004;
	Wed, 9 Jul 2008 11:57:55 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3R0030160J9B00@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 09 Jul 2008 11:57:55 -0700 (PDT)
Received: from phorcys.east.sun.com ([129.148.174.143])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3R000Y760IEW10@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 09 Jul 2008 11:57:55 -0700 (PDT)
Received: from phorcys.east.sun.com (localhost [127.0.0.1])
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3) with ESMTP id m69Ivstb023265; Wed,
 09 Jul 2008 14:57:54 -0400 (EDT)
Received: (from carlsonj@localhost)
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3/Submit) id m69IvpG9023262; Wed,
 09 Jul 2008 14:57:51 -0400 (EDT)
Date: Wed, 09 Jul 2008 14:57:51 -0400
From: James Carlson <james.d.carlson@sun.com>
Subject: Re: Integrate privoxy into Solaris [LSARC/2008/433 FastTrack timeout
 07/17/2008]
In-reply-to: <4874EDF3.7040603@sun.com>
To: James Gates <James.Gates@sun.com>
Cc: lsarc-ext@sun.com, Venky <venkytv@sun.com>
Message-id: <18549.2607.227371.463578@gargle.gargle.HOWL>
MIME-version: 1.0
X-Mailer: VM 7.01 under Emacs 21.3.1
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <4874EDF3.7040603@sun.com>
Status: RO
Content-Length: 2131

[Removed unusual cc-list.]

James Gates writes:
> I'm not too sure what we can discuss here. As the community haven't 
> really warmed to IPv6, I would have thought that lack of IPv6 support is 
> the norm, not the exception. What would be the outcome of an ARC 
> discussion - Would you insist that the community implement IPv6 support? 
> Would integration be stalled until IPv6 support is enabled?

Regardless of what "the community" may think of IPv6 (and perhaps what
I think of it as well), it's actually required in some markets,
including with US government customers, so integrating components that
don't support it poses potentially serious problems with at least
Sun's marketing and sales.

For that reason, the Solaris PAC had a "big rule" requiring IPv6
conformance for all Solaris components that include IP-related
networking.  The relevance of that (and perhaps all "big rules") is
somewhat unclear to me at this point, but the only 'reasonable'
exception was if the protocol being implemented was itself not defined
to work with IPv6.  (E.g., ARP doesn't work with IPv6, so an
ARP-related project wouldn't be forced into inventing something that
doesn't exist.)

Yes, I'm well aware that there are some groups and products that never
did IPv6 and possibly never will.  Driving compliance across something
as big as Sun is not easy.

I would at least offer _strong_ ARC advice that the project team
consider implementing that support and donating the results to the
community -- unless the application is just plain horrible, this
shouldn't really be hard to do -- and suggest that they get in touch
with Victor Nelson to find out more about the issues and risks that
may be caused by spotty IPv6 support.

(Including, in some cases, the risk of losing our IPv6 Logo.  Likely
not a risk with this one project, but certainly a cumulative risk over
time if we don't try to guard the commons.)

-- 
James Carlson, Solaris Networking              <james.d.carlson@sun.com>
Sun Microsystems / 35 Network Drive        71.232W   Vox +1 781 442 2084
MS UBUR02-212 / Burlington MA 01803-2757   42.496N   Fax +1 781 442 1677

From james.gates@sun.com Wed Jul  9 12:34:04 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m69JY3Hp021922
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 9 Jul 2008 12:34:04 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m69JXuLK006706;
	Wed, 9 Jul 2008 20:34:01 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3R0070N7OL0M00@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 09 Jul 2008 12:33:57 -0700 (PDT)
Received: from dm-uk-02.uk.sun.com ([129.156.101.196])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3R000WQ7OJES50@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 09 Jul 2008 12:33:56 -0700 (PDT)
Received: from serinus.UK.Sun.COM (serinus.UK.Sun.COM [129.156.173.208])
	by dm-uk-02.uk.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2)
 with ESMTP id m69JXs5M004884; Wed, 09 Jul 2008 20:33:54 +0100 (BST)
Received: from [192.168.1.100] (vpn-129-150-65-60.East.Sun.COM [129.150.65.60])
	by serinus.UK.Sun.COM (8.13.7+Sun/8.13.7/CTE 3.0)
 with ESMTP id m69JXRZO028674; Wed, 09 Jul 2008 20:33:38 +0100 (BST)
Date: Wed, 09 Jul 2008 15:32:46 -0400
From: James Gates <james.gates@sun.com>
Subject: Re: Integrate privoxy into Solaris [LSARC/2008/433 FastTrack timeout
 07/17/2008]
In-reply-to: <18549.2607.227371.463578@gargle.gargle.HOWL>
To: James Carlson <james.d.carlson@sun.com>,
        Lukas Rovensky <lukas.rovensky@sun.com>
Cc: lsarc-ext@sun.com, Venky <venkytv@sun.com>
Message-id: <4875125E.80506@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii; format=flowed
Content-transfer-encoding: 7BIT
X-Accept-Language: en-us, en
X-PMX-Version: 5.4.1.325704
References: <4874EDF3.7040603@sun.com>
 <18549.2607.227371.463578@gargle.gargle.HOWL>
User-Agent: Mozilla/5.0 (X11; U; SunOS sun4u; en-US; rv:1.7.13) Gecko/20060509
Status: RO
Content-Length: 3082

Thanks, that's useful advice.

This is part of the effort to integrate that huge list of FOSS into Open 
Solaris managed by Kelly Nishimura (See [1] & [2]). RPE was given a 
section of the list, and Venky volunteered (along with other RPE 
engineers) to perform the integration. I don't think he has any 
particular affiliation with the product or community, and there is no 
"project team" as such. So I don't know if anyone ever intended (or has 
the time) to work with the community on such things as IPv6 support.

Lukas Rovensky is the RPE OSS manager, maybe he can add something? 
Lukas, are there are plans/resources to improve these FOSS products 
beyond integration?

If not, we may be faced with a familiar but simple FOSS choice - 
integrate it as is (because we have no resources to improve it), or 
don't integrate it.


[1] http://infoshare.sfbay/twiki/bin/view/Main/OpenSolarisCabinet
[2] http://infoshare.sfbay/twiki/pub/Main/OpenSolarisCabinet/OS.1120.V60.ods

James Carlson wrote:
> [Removed unusual cc-list.]
> 
> James Gates writes:
> 
>>I'm not too sure what we can discuss here. As the community haven't 
>>really warmed to IPv6, I would have thought that lack of IPv6 support is 
>>the norm, not the exception. What would be the outcome of an ARC 
>>discussion - Would you insist that the community implement IPv6 support? 
>>Would integration be stalled until IPv6 support is enabled?
> 
> 
> Regardless of what "the community" may think of IPv6 (and perhaps what
> I think of it as well), it's actually required in some markets,
> including with US government customers, so integrating components that
> don't support it poses potentially serious problems with at least
> Sun's marketing and sales.
> 
> For that reason, the Solaris PAC had a "big rule" requiring IPv6
> conformance for all Solaris components that include IP-related
> networking.  The relevance of that (and perhaps all "big rules") is
> somewhat unclear to me at this point, but the only 'reasonable'
> exception was if the protocol being implemented was itself not defined
> to work with IPv6.  (E.g., ARP doesn't work with IPv6, so an
> ARP-related project wouldn't be forced into inventing something that
> doesn't exist.)
> 
> Yes, I'm well aware that there are some groups and products that never
> did IPv6 and possibly never will.  Driving compliance across something
> as big as Sun is not easy.
> 
> I would at least offer _strong_ ARC advice that the project team
> consider implementing that support and donating the results to the
> community -- unless the application is just plain horrible, this
> shouldn't really be hard to do -- and suggest that they get in touch
> with Victor Nelson to find out more about the issues and risks that
> may be caused by spotty IPv6 support.
> 
> (Including, in some cases, the risk of losing our IPv6 Logo.  Likely
> not a risk with this one project, but certainly a cumulative risk over
> time if we don't try to guard the commons.)
> 

-- 
Jim Gates                    Sun Microsystems
Nashua, USA             http://sun.com/postgresql

From carlsonj@phorcys.east.sun.com Wed Jul  9 12:44:21 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m69JiKQ0022064
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 9 Jul 2008 12:44:21 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m69JiFXm011057;
	Wed, 9 Jul 2008 20:44:17 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3R0010785R2B00@brm-avmta-1.central.sun.com>; Wed,
 09 Jul 2008 13:44:15 -0600 (MDT)
Received: from phorcys.east.sun.com ([129.148.174.143])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3R00E5I85QCNC0@brm-avmta-1.central.sun.com>; Wed,
 09 Jul 2008 13:44:14 -0600 (MDT)
Received: from phorcys.east.sun.com (localhost [127.0.0.1])
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3) with ESMTP id m69JiEh6023489; Wed,
 09 Jul 2008 15:44:14 -0400 (EDT)
Received: (from carlsonj@localhost)
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3/Submit) id m69JiEBx023486; Wed,
 09 Jul 2008 15:44:14 -0400 (EDT)
Date: Wed, 09 Jul 2008 15:44:14 -0400
From: James Carlson <james.d.carlson@sun.com>
Subject: Re: Integrate privoxy into Solaris [LSARC/2008/433 FastTrack timeout
 07/17/2008]
In-reply-to: <4875125E.80506@sun.com>
To: James Gates <James.Gates@sun.com>
Cc: Lukas Rovensky <Lukas.Rovensky@sun.com>, lsarc-ext@sun.com,
        Venky <venkytv@sun.com>
Message-id: <18549.5390.442740.760449@gargle.gargle.HOWL>
MIME-version: 1.0
X-Mailer: VM 7.01 under Emacs 21.3.1
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <4874EDF3.7040603@sun.com>
 <18549.2607.227371.463578@gargle.gargle.HOWL> <4875125E.80506@sun.com>
Status: RO
Content-Length: 1373

James Gates writes:
> This is part of the effort to integrate that huge list of FOSS into Open 
> Solaris managed by Kelly Nishimura (See [1] & [2]). RPE was given a 
> section of the list, and Venky volunteered (along with other RPE 
> engineers) to perform the integration. I don't think he has any 
> particular affiliation with the product or community, and there is no 
> "project team" as such. So I don't know if anyone ever intended (or has 
> the time) to work with the community on such things as IPv6 support.

Not trying to be a pessimist, but what are the odds if we can't
participate even minimally in the source community that we'll be able
to update and maintain this software over time?

Building and shipping new versions (and keeping up with occasional
upstream portability blunders) also takes non-zero effort.  History
has shown that we do a pretty good job of integrating random things
into (for example) the Companion CD, but then a spotty job of
preventing them from accumulating dust ... to the point where many of
them are much more of a distraction than a feature.

I hope it's not an effort to get something for nothing.

-- 
James Carlson, Solaris Networking              <james.d.carlson@sun.com>
Sun Microsystems / 35 Network Drive        71.232W   Vox +1 781 442 2084
MS UBUR02-212 / Burlington MA 01803-2757   42.496N   Fax +1 781 442 1677

From Alan.Coopersmith@sun.com Wed Jul  9 13:01:33 2008
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m69K1XVb022829
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 9 Jul 2008 13:01:33 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m69K1TRX023162;
	Wed, 9 Jul 2008 13:01:31 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3R00D118YJAJ00@nwk-avmta-2.sfbay.sun.com>; Wed,
 09 Jul 2008 13:01:31 -0700 (PDT)
Received: from sca-es-mail-2.sun.com ([192.18.43.133])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3R007EI8YGDG90@nwk-avmta-2.sfbay.sun.com>; Wed,
 09 Jul 2008 13:01:28 -0700 (PDT)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m69K1Rgl021326;
 Wed, 09 Jul 2008 13:01:27 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K3R00B018N9JC00@fe-sfbay-09.sun.com>
 (original mail from Alan.Coopersmith@Sun.COM); Wed,
 09 Jul 2008 13:01:27 -0700 (PDT)
Received: from almas.sfbay.sun.com ([129.146.106.93])
 by fe-sfbay-09.sun.com (Sun Java System Messaging Server 6.2-8.04 (built Feb
 28 2007)) with ESMTPSA id <0K3R007DX8YF4F40@fe-sfbay-09.sun.com>; Wed,
 09 Jul 2008 13:01:27 -0700 (PDT)
Date: Wed, 09 Jul 2008 13:01:23 -0700
From: Alan Coopersmith <Alan.Coopersmith@sun.com>
Subject: Re: Integrate privoxy into Solaris [LSARC/2008/433 FastTrack timeout
 07/17/2008]
In-reply-to: <4875125E.80506@sun.com>
Sender: Alan.Coopersmith@sun.com
To: James Gates <James.Gates@sun.com>
Cc: James Carlson <James.D.Carlson@sun.com>,
        Lukas Rovensky <Lukas.Rovensky@sun.com>, lsarc-ext@sun.com,
        Venky <venkytv@sun.com>
Message-id: <48751913.7070803@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Enigmail-Version: 0.95.1
References: <4874EDF3.7040603@sun.com>
 <18549.2607.227371.463578@gargle.gargle.HOWL> <4875125E.80506@sun.com>
User-Agent: Thunderbird 2.0.0.6 (X11/20071203)
Status: RO
Content-Length: 1586

James Gates wrote:
> This is part of the effort to integrate that huge list of FOSS into Open
> Solaris managed by Kelly Nishimura (See [1] & [2]). RPE was given a
> section of the list, and Venky volunteered (along with other RPE
> engineers) to perform the integration. I don't think he has any
> particular affiliation with the product or community, and there is no
> "project team" as such. So I don't know if anyone ever intended (or has
> the time) to work with the community on such things as IPv6 support.

This is straying into internal Sun management issues that don't really belong
on lsarc-ext, but the message from management I've heard has clearly been that
by accepting items from that list you are accepting long term maintenance and
the responsibility of working with the community on enhancements like this.
Just dropping it in "as is" and never doing anything more with it is not
acceptable - you've signed up to own it, not just do a one time integration.

Having been the person who worked with X.Org & XFree86 about 5 years ago
to add IPv6 support, my experience is the opposite of your original assertion,
those communities, and most others I've seen, are very willing to accept IPv6
enhancements and encouraging of them.   Most open source projects had IPv6
support before their commercial brethren.   Especially when using the common
IPv6 socket APIs, so that changes work equally well on Solaris, Linux & BSD,
there is little to lose for them.

-- 
	-Alan Coopersmith-           alan.coopersmith@sun.com
	 Sun Microsystems, Inc. - X Window System Engineering


From venkytv@Sun.COM Thu Jul 10 02:34:40 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m6A9Yeuf018409
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 10 Jul 2008 02:34:40 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m6A9Ydvx019141
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Thu, 10 Jul 2008 03:34:40 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K3S0090JALRC700@nwk-avmta-1.sfbay.Sun.COM> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@sun.com); Thu, 10 Jul 2008 02:34:39 -0700 (PDT)
Received: from dm-india-02.singapore.sun.com ([129.158.71.104])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K3S0048XALPF290@nwk-avmta-1.sfbay.Sun.COM> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Thu,
 10 Jul 2008 02:34:38 -0700 (PDT)
Received: from rattlehead.sun.com (rattlehead.India.Sun.COM [129.158.227.201])
	by dm-india-02.singapore.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id m6A9YROZ021214; Thu, 10 Jul 2008 17:34:27 +0800 (SGT)
Received: by rattlehead.sun.com (Postfix, from userid 116884)
	id D56175F535; Thu, 10 Jul 2008 15:04:26 +0530 (IST)
Date: Thu, 10 Jul 2008 15:04:26 +0530
From: Venky <venkytv@Sun.COM>
Subject: Re: Integrate privoxy into Solaris [LSARC/2008/433 FastTrack	timeout
 07/17/2008]
In-reply-to: <4874F41C.7070801@Sun.COM>
To: Darren J Moffat <darren.moffat@Sun.COM>
Cc: Danek Duvall <Danek.Duvall@Sun.COM>, James Gates <James.Gates@Sun.COM>,
        lsarc-ext@Sun.COM
Message-id: <20080710093426.GF22701@india.sun.com>
MIME-version: 1.0
Content-type: multipart/mixed; boundary="Boundary_(ID_jt3OMVT/lk0oQrICXOYP8w)"
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <4874EDF3.7040603@sun.com>
 <20080709171140.GG1920@zruty.sfbay.sun.com> <4874F41C.7070801@Sun.COM>
User-Agent: Mutt/1.5.17 (2007-11-01)
Status: RO
Content-Length: 27690


--Boundary_(ID_jt3OMVT/lk0oQrICXOYP8w)
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline

On Wed, Jul 09, 2008 at 06:23:40PM +0100, Darren J Moffat wrote:
> Danek Duvall wrote:
>> On Wed, Jul 09, 2008 at 12:57:23PM -0400, James Gates wrote:
>>
>>>         /usr/sbin/privoxy       Committed               Executable location
>>
>> Why /usr/sbin rather than /usr/bin?  Would a user never run this
>> individually?
>
>
> I was thinking that given there is an SMF service for this why shouldn't it 
> be somewhere under /usr/lib/

Right.  The default location privoxy installs in is /usr/sbin, but
I think /usr/lib makes better sense.  Have updated the interface
table.

>>>         /lib/svc/method/privoxy Committed               SMF Service method
>>
>> Why is this Committed, rather than just an Project Private implementation
>> detail?
>>
>> Also note that the SMF FMRI (as well as any config vars it exports, though
>> it looks like there aren't any here) should be one of the interfaces you
>> note here.  Not the manifest file -- that's not an interface, either.  (Nor
>> is any documentation, though you have that listed as well).
>
> Agreed it is the FMRI that is interest the method script as you said should 
> almost always be Project Private [ particularly if it is something under 
> /lib/svc/method rather than an existing command ]

Have cleaned up the interface table, removed the documentation and
log files and added the SMF FMRI.

Have also added an explanation for the lack of IPv6 support to the
proposal which in effect commits to working with the community on
adding IPv6 support while integrating the current version as is for
now.  Hope that's okay.

Have attached the modified files.

Thanks,
Venky.

--Boundary_(ID_jt3OMVT/lk0oQrICXOYP8w)
Content-type: text/plain; NAME=privoxy-proposal.txt; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: attachment; filename=privoxy-proposal.txt

Proposal:

        Integrate privoxy into Solaris.


Detail:
        
        Privoxy is a non-caching web proxy with advanced filtering
        capabilities for enhancing privacy, modifying web page data, managing
        HTTP cookies, controlling access, and removing ads, banners, pop-ups
        and other obnoxious Internet junk. Privoxy has a flexible
        configuration and can be customized to suit individual needs and
        tastes.  Privoxy has application for both stand-alone systems and
        multi-user networks.

        The current version of privoxy is 3.0.8 at the time of this case.

        Privoxy 3.0.8 does not include IPv6 support.  The plan is integrate the
        package as it right now and then work with the community on adding IPv6
        support.

Exported Interfaces:

    SUNWprivoxy                 Uncommitted         Package name
    /usr/lib/privoxy            Committed           Executable location
    /lib/svc/method/http-privoxy
                                Project Private     SMF Service Method
    svc:/network/http:privoxy   Committed           SMF FMRI
                                                    Controls the privoxy daemon
    /etc/privoxy/config         Volatile            Main configuration file
    /etc/privoxy/*.action       Volatile            Configuration files -
                                                    Defines URL-based actions
    /etc/privoxy/*.filter       Volatile            Configuration files -
                                                    Header and content rewrite
                                                    rules
    /etc/privoxy/templates/*
                                Volatile            Template files for the
                                                    web-based user interface
    /etc/privoxy/trust          Volatile            Configuration file -
                                                    Whitelist of allowed sites
    /usr/share/man/man1/privoxy.1
                                Volatile            Manpage
    privoxy                     Volatile            Commandline syntax
    privoxy output              -                   Not an interface

    A complete list of interfaces delivered by the privoxy package is included
    in the privoxy-interfaces.txt file.


Imported Interfaces:

    Standard C Library Functions

References:

[1] http://www.privoxy.org/
    Authors of privoxy: Fabian Keil, David Schmidt, and others
[2] CR 6689953 Integrate Privoxy v3.0.8

--Boundary_(ID_jt3OMVT/lk0oQrICXOYP8w)
Content-type: text/plain; NAME=privoxy-checklist.txt; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: attachment; filename=privoxy-checklist.txt

FCL--FOSS Check List
0.  Introduction
0.1 Document History
    Version   Author             Changes					Date
    0.1       John Fischer       Initial Draft					01/11/2008
    0.2       John Fischer       Modified based upon feedback from ARC members	01/29/2008
    0.3       John Fischer       Modified based upon feedback during committee 	02/12/2008
                                 review
    0.4       John Fischer       Modified based upon SAC review feedback	04/01/2008
    0.5	      John Fischer	 Modified based upon LSARC business meeting	06/10/2008
                                 adding familiarity question and mod dates.
    0.6       John Fischer       Modified based upon user feedback about        06/20/2008
                                 sections that were unanswerable.

0.2 Purpose
    Architecture review at Sun has allowed the company to evolve our projects
    within multiple disjoint groups while still maintaining a cohesive product
    line.  Each architecture review was conducted within Sun's control.  With
    the advent of Free Open Source Software processes the control that Sun as
    a company can wield has been diminished.  Now that Sun is moving to a more
    fluid delivery mechanism with project Indiana we need to evolve the 
    architecture review process.  This document is meant to aid in the 
    architecture review process.  Each new project must complete this check list 
    to help ensure that the overall resulting product conforms to Sun product 
    standards.  If the project deviates from these standards further review 
    would be necessary by an architecture review committee.
    
    After the check list is completed the project team should be able to 
    determine if a project can be automatically approved.  This will occur
    if all checks result in no "ARC review required" answers.  A committee
    member will assist the project team in filing the automatically approved 
    fast track.  An automatically approved fast track is still required in order
    to record the interfaces for future reference.  If the project needs to 
    have further review then follow the regular process for getting projects 
    reviewed.

1.0 Project Information
1.1 Name of project/component
    Privoxy: A non-caching web proxy with advanced filtering capabilities

1.2 Author of document
    Venky TV

2.0 Project Summary
  2.1 Project Description
      Privoxy is a non-caching web proxy with advanced filtering capabilities
      for enhancing privacy, modifying web page data, managing HTTP cookies,
      controlling access, and removing ads, banners, pop-ups and other obnoxious
      Internet junk. Privoxy has a flexible configuration and can be customized
      to suit individual needs and tastes.  Privoxy has application for both
      stand-alone systems and multi-user networks.

      Privoxy applies to only HTTP and HTTPS traffic.
  
  2.2 Release binding
      What is is the release binding?
      (see http://opensolaris.org/os/community/arc/policies/release-taxonomy/)
      [ ] Major
      [X] Minor
      [ ] Patch or Micro
      [ ] Unknown -- ARC review required

  2.3 Type of project
      Is this case a Linux Familiarity project?
      [X] Yes
      [ ] No

  2.4 Originating Community
    2.4.1 Community Name
          Privoxy
    
    2.4.2 Community Involvement
      Indicate Sun's involvement in the community
      [ ] Maintainer
      [ ] Contributor
      [X] Monitoring
      
      Will the project team work with the upstream community to resolve
      architectural issues of interest to Sun?
      [X] Yes 
      [ ] No - briefly explain
      
      Will we or are we forking from the community?
      [ ] Yes - ARC review required prior to forking
      [X] No
      
3.0 Technical Description
  3.1 Installation & Sharable
    3.1.1S Solaris Installation - section only required for Solaris Software
      (see http://opensolaris.org/os/community/arc/policies/install-locations/ for details)
      Does this project follow the Install Locations best practice?
      [X] Yes 
      [ ] No - ARC review required
      
      Does this project install into /usr under [sbin|bin|lib|include|man|share]?
      [X] Yes
      [ ] No or N/A
      
      Does this project install into /opt?
      [ ] Yes - explain below
      [X] No or N/A
      
      Does this project install into a different directory structure?
      [ ] Yes - ARC review required
      [X] No or N/A
      
      Do any of the components of this project conflict with anything under /usr?
      (see http://opensolaris.org/os/community/arc/caselog/2007/047/ for details)
      [ ] Yes - explain below
      [X] No
      
      If conflicts exist then will this project install under /usr/gnu?
      [ ] Yes
      [ ] No - ARC review required
      [X] N/A
      
      Is this project installing into /usr/sfw?
      [ ] Yes - ARC review required
      [X] No
      
    3.1.1W Windows Installation - section only required for Windows Software
      (see http://sac.sfbay/WSARC/2002/494 for details)
      Does this project install software into a 
      <system drive>:\Program Files\Sun\<product> or <system drive>:\Sun\<product>
      directory?
      [ ] Yes
      [ ] No - ARC review required
      
      Does the project use the Windows registry?
      [ ] Yes
      [ ] No - ARC review required
      
      Does the project use 
      HKEY_LOCAL_MACHINE\SOFTWARE\Sun Microsystems\<product>\<version>
      for the registry key?
      [ ] Yes
      [ ] No - ARC review required
      
      Is the project's stored location
      HKEY_LOCAL_MACHINE\SOFTWARE\Sun Microsystems\<product id>\<version id>\Path?
      [ ] Yes
      [ ] No - ARC review required
      
    3.1.2 Share and Sharable
      Does the module include any components that are used or shared by 
      other projects?
      [ ] Yes
      [X] No
    
      If yes are these components packaged to be shared with the other FOSS?
      [ ] Yes
      [ ] No - ARC review required
      [X] N/A
    
      Are these components already in the Solaris WOS?
      [ ] Yes
      [X] No - continue with next section (section 3.2)
    
      If yes are these newer versions being delivered?
      [ ] Yes
      [ ] No - ARC review required
      
      If yes are the newer versions replacing the existing versions?
      [ ] Yes
      [ ] No - ARC review required

  3.2 Exported Libraries
      Are libraries being delivered by this project?
      [ ] Yes
      [X] No - continue with next section (section 3.3)
      
      Are 64-bit versions of the libraries being delivered?
      [ ] Yes
      [ ] No - ARC review required
    
      Are static versions of the libraries being delivered?
      [ ] Yes - ARC review required
      [ ] No 
      
  3.3 Services and the /etc Directory
      (see http://opensolaris.org/os/community/arc/policies/SMF-policy/)
      Does the project integrate anything into /etc/init.d or /etc/rc?.d?
      [ ] Yes - ARC review required
      [X] No
      
      Does the project integrate any new entries into /etc/inittab or
      /etc/inetd.conf?
      [ ] Yes - ARC review required
      [X] No
      
      Does the project integrate any private non-public files into /etc/default
      or /etc/ configuration files?
      [ ] Yes - ARC review required
      [X] No
      
      Does the service manifests method context grant rights above that
      of the noaccess user and basic privilege set?
      [ ] Yes - ARC review required
      [X] No
        
  3.4 Security
    3.4.1 Secure By Default 
      (see http://opensolaris.org/os/community/arc/policies/secure-by-default/ for details)
      (see http://www.opensolaris.org/os/community/arc/policies/NITS-policy/ for details)
      (see parts of http://opensolaris.org/os/community/arc/policies/SMF-policy/ for
       addtional details)
      Are there any network services provided by this project?
      [X] Yes
      [ ] No - continue with the next section (section 3.4.2)
      
      Are network services enabled by default?
      [ ] Yes - ARC review required
      [X] No
      [ ] N/A
      
      Are network services automatically enabled by the project during installation?
      [ ] Yes - ARC review required
      [X] No
      [ ] N/A
      
      Are inbound network communications denied by default?
      [ ] Yes
      [ ] No - ARC review required
      [X] N/A
      
      Is inbound data checked to prevent content-based attacks?
      [ ] Yes
      [ ] No - ARC review required
      [X] N/A
      
      Is the outbound receiver authenticated?
      [ ] Yes
      [ ] No - ARC review required
      [X] N/A
      
      Is the receiver authenticated prior to receiving any sensitive outbound communication?
      [ ] Yes
      [ ] No - ARC review required
      [X] N/A
      
    3.4.2 Authorization
      (see http://opensolaris.org/os/community/arc/bestpractices/rbac-intro/ and
	   http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/ and
	   http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/
           for details)
      Are there any setuid/setgid privileged binaries in the project?
      [ ] Yes - ARC review required
      [X] No - continue with next section (section 3.4.3)
      
      If yes then are the setuid/setgid privileges handled by the use of roles?
      [ ] Yes
      [ ] No - ARC review required

    3.4.3 Auditing
      (see http://opensolaris.org/os/community/arc/policies/audit-policy/ for details)
      (see http://opensolaris.org/os/community/arc/caselog/2003/397 for details)
      Does this component contain administrative or security enforcing software?
      [ ] Yes - ARC review required
      [X] No - continue to next section (section 3.4.4)
      
      (see http://opensolaris.org/os/community/arc/caselog/2003/397 for details)
      Do the components create audit logs detailing what took place including what event
      took place, who was involved, when the event took place?
      [ ] Yes - ARC contract and Audit project team review required
      [ ] No - ARC review required
        
        
    3.4.4 Authentication
      (see http://opensolaris.org/os/community/arc/policies/PAM/)
      Do the components contain any authentication code?
      [ ] Yes
      [X] No - continue to next section (section 3.4.5)
      
      If yes do the components use PAM (plugable authentication modules) for authentication?
      [ ] Yes
      [ ] No - ARC review required
      
      If yes is a single PAM session maintained during authentication?
      [ ] Yes
      [ ] No - ARC review required
      
      If yes are the components sufficiently privileged to allow the requested 
      operations (authentication, password change, process credential manipulation, 
      audit state initialization)?
      [ ] Yes - briefly describe below
      [ ] No - ARC review required
      
    3.4.5 Passwords
      (see http://opensolaris.org/os/community/arc/bestpractices/passwords-cli/ and
           http://opensolaris.org/os/community/arc/bestpractices/passwords-files/ for details)
      Do any of the components for the project deal with passwords?
      [ ] Yes
      [X] No - continue to next section (section 3.4.6)
      
      If yes are these passwords entered via the CLI or environment?
      [ ] Yes - ARC review required
      [ ] No
      
      Are passwords stored within the file system for the component?
      [ ] Yes
      [ ] No - continue to next section (section 3.4.6)
      
      If yes are the permissions on the file such to protect exposing the password(s)?
      [ ] Yes
      [ ] No - ARC review required
      
    3.4.6 General Security Questions
      (see http://opensolaris.org/os/community/arc/bestpractices/security-questions/ for details)
      Are there any network protocols used by this project?
      [X] Yes
      [ ] No - continue with the next section (section 3.5)
      
      Do the components use standard network protocols?
      [X] Yes
      [ ] No - ARC review required
      
      Do network services for the project make decisions based upon user, host or 
      service identities?
      [X] Yes - explain below
      [ ] No
      [ ] N/A

      ACLs based on hostnames and IP addresses can be used to restrict access to
      the Privoxy proxy server.
      
      Do the components make use of secret information during authentication and/or
      authorization?
      [ ] Yes - explain below
      [X] No
      [ ] N/A
  
  3.5 Networking
      Do the components access the network?
      [X] Yes
      [ ] No - continue with the next section (section 3.6)
      
      If yes do the components support IPv6?
      [ ] Yes 
      [X] No - ARC review required
          
  3.6 Core Solaris Components
      Do the components of this project compete with or duplicate core 
      Solaris components?
      [ ] Yes - ARC review required
      [X] No 
      
      Examples of Core Solaris Components include but are not limited to:
      
        Secure By Default
        Authorizations
        PAM -- Plugable Authentication Module
        Privilege
        PRM -- Process Rights Management -- Privilege
        Audit
        xVm -- Virtualization
        zones / Solaris Containers
        PRM -- Process Rights Management
        RBAC -- Role Based Access Control
        TX / Trusted Extensions
        ZFS
        SMF -- Service Management Facility
        FMA -- Fault Management Architecture
        SCF -- Smart Card Facility
        IPsec
        
4.0 Interfaces
  (see http://www.opensolaris.org/os/community/arc/policies/interface-taxonomy/ for details)
  4.1 Exported Interfaces
  
    Interface Name		Classification      Comments
    --------------------------- ------------------- ---------------------------
    SUNWprivoxy                 Uncommitted         Package name
    /usr/lib/privoxy            Committed           Executable location
    /lib/svc/method/http-privoxy
                                Project Private     SMF Service method
    svc:/network/http:privoxy   Commited            SMF FMRI
    /etc/privoxy/config         Volatile            Main configuration file
    /etc/privoxy/*.action       Volatile            Configuration files -
                                                    Defines URL-based actions
    /etc/privoxy/*.filter       Volatile            Configuration files -
                                                    Header and content rewrite
                                                    rules
    /etc/privoxy/templates/*    Volatile            Template files for the
                                                    web-based user interface
    /etc/privoxy/trust          Volatile            Configuration file -
                                                    Whitelist of allowed sites
    /usr/share/man/man1/privoxy.1
                                Volatile            Manpage
    privoxy                     Volatile            Commandline syntax
    privoxy output              -                   Not an interface

    A complete list of interfaces delivered by the privoxy package is included
    in the privoxy-interfaces.txt file.
    
  4.2 Imported Interfaces
    Interface Name		         Classification       Comments
    ---------------------------  -------------------- --------------------------
    Standard C Library Functions Committed
          
  Brief Interface Classifications - See Appendix C for definitions
    Volatile - interfaces are fluid and will follow a rapidly changing community
    Uncommitted - interfaces are still evolving in the community and might follow
		  the community
    Committed - interfaces are stable in the community
    Project Private - no review required, just document in table
    Contracted (interface modifier) - further review required

Appendix A - References
  1.  Solaris Installation Locations Policy
      http://opensolaris.org/os/community/arc/policies/install-locations/
  2.  /usr/gnu Installation ARC case
      http://opensolaris.org/os/community/arc/caselog/2007/047/
  3.  Secure By Default Policy
      http://opensolaris.org/os/community/arc/policies/secure-by-default/
  4.  Network Install Time Securityuy Policy
      http://www.opensolaris.org/os/community/arc/policies/NITS-policy/
  5.  Adding RBAC Authorizations Policy
      http://opensolaris.org/os/community/arc/bestpractices/rbac-auths/
  6.  When to use setuid -vs- RBAC roles and profiles
      http://opensolaris.org/os/community/arc/bestpractices/rbac-intro/ and
  7.  Building RBAC Rights Profiles
      http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/
  8.  Solaris Audit Policy
      http://opensolaris.org/os/community/arc/policies/audit-policy/
  9.  Security questionaire
      http://opensolaris.org/os/community/arc/bestpractices/security-questions/
  10. Interface Taxonomy
      http://www.opensolaris.org/os/community/arc/policies/interface-taxonomy/
  11. Plugable Authentication Modules -- PAM
      http://opensolaris.org/os/community/arc/policies/PAM/
  12. Reusable Passwords In Command Line Arguments and Environment Variables
      http://opensolaris.org/os/community/arc/bestpractices/passwords-cli/
  13. Storing Reusable Passwords on a Filesystem
      http://opensolaris.org/os/community/arc/bestpractices/passwords-files/
  14. Release Taxonomy
      http://opensolaris.org/os/community/arc/policies/release-taxonomy/
  15. Service Management Facility (SMF) usage
      http://opensolaris.org/os/community/arc/policies/SMF-policy/

  
Appendix B - Suggested case materials
  1. man pages
  2. SMF manifests
  3. links to contracts
  
Appendix C - Definitions
Submitter
     an agent responsible for creation of an ARC project along with the
     materials describing that project.
Owner
     the ARC agent responsible for shepherding the case through review
     and ensuring a formal opinion is written where required.
Maintainer
     an agent responsible for releasing new versions of a program, typically
     the "main" contributor or person incharge of making Architectural
     decisions for the project
Contributor
     an agent who make contributions to a project, typically has a voice in
     making Architectural decisions for the project
Monitoring
     an agent who is only following the changes made in the community and
     has no Architectural input into the project
Volatile*
    interfaces that are very fluid and typically follow the originating 
    community.  Typically these interfaces can not be imported by other
    projects.
Uncommitted*
    interfaces that are still evolving but will most likely be present from
    release to release.
Committed*
    interfaces that are stable and with Sun guaranteeing some level of
    compatibility from release to release.
Project Private*
    interfaces that are exposed only to or intended to be used only by
    the project being reviewed.  These interfaces can not be imported by
    other projects.
Not-An-Interface*
    components that are not interfaces.
Contracted* (interface modifier) - ARC review of Contract required
    interfaces that do not allow another project to import can be 

*Note: see http://opensolaris.org/os/community/arc/policies/interface-taxonomy/ for details

--Boundary_(ID_jt3OMVT/lk0oQrICXOYP8w)
Content-type: text/plain; NAME=privoxy-interfaces.txt; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: attachment; filename=privoxy-interfaces.txt

/etc/privoxy/config                                              Volatile
/etc/privoxy/default.action                                      Volatile
/etc/privoxy/default.filter                                      Volatile
/etc/privoxy/standard.action                                     Volatile
/etc/privoxy/templates                                           Volatile
/etc/privoxy/templates/blocked                                   Volatile
/etc/privoxy/templates/cgi-error-404                             Volatile
/etc/privoxy/templates/cgi-error-bad-param                       Volatile
/etc/privoxy/templates/cgi-error-disabled                        Volatile
/etc/privoxy/templates/cgi-error-file                            Volatile
/etc/privoxy/templates/cgi-error-file-read-only                  Volatile
/etc/privoxy/templates/cgi-error-modified                        Volatile
/etc/privoxy/templates/cgi-error-parse                           Volatile
/etc/privoxy/templates/cgi-style.css                             Volatile
/etc/privoxy/templates/connect-failed                            Volatile
/etc/privoxy/templates/default                                   Volatile
/etc/privoxy/templates/edit-actions-add-url-form                 Volatile
/etc/privoxy/templates/edit-actions-for-url                      Volatile
/etc/privoxy/templates/edit-actions-for-url-filter               Volatile
/etc/privoxy/templates/edit-actions-list                         Volatile
/etc/privoxy/templates/edit-actions-list-button                  Volatile
/etc/privoxy/templates/edit-actions-list-section                 Volatile
/etc/privoxy/templates/edit-actions-list-url                     Volatile
/etc/privoxy/templates/edit-actions-remove-url-form              Volatile
/etc/privoxy/templates/edit-actions-url-form                     Volatile
/etc/privoxy/templates/forwarding-failed                         Volatile
/etc/privoxy/templates/mod-local-help                            Volatile
/etc/privoxy/templates/mod-support-and-service                   Volatile
/etc/privoxy/templates/mod-title                                 Volatile
/etc/privoxy/templates/mod-unstable-warning                      Volatile
/etc/privoxy/templates/no-such-domain                            Volatile
/etc/privoxy/templates/show-request                              Volatile
/etc/privoxy/templates/show-status                               Volatile
/etc/privoxy/templates/show-status-file                          Volatile
/etc/privoxy/templates/show-url-info                             Volatile
/etc/privoxy/templates/show-version                              Volatile
/etc/privoxy/templates/toggle                                    Volatile
/etc/privoxy/templates/toggle-mini                               Volatile
/etc/privoxy/templates/untrusted                                 Volatile
/etc/privoxy/trust                                               Volatile
/etc/privoxy/user.action                                         Volatile
/etc/privoxy/user.filter                                         Volatile

/usr/lib/privoxy                                                 Committed
/usr/share/man/man1/privoxy.1                                    Volatile

svc:/network/http:privoxy                                        Committed
/lib/svc/method/http-privoxy                                     Project Private

--Boundary_(ID_jt3OMVT/lk0oQrICXOYP8w)--

From james.gates@sun.com Tue Jul 15 13:28:56 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m6FKSuAk024543
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 15 Jul 2008 13:28:56 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m6FKSsVQ014573;
	Tue, 15 Jul 2008 13:28:54 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K4200K03E84QB00@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 15 Jul 2008 13:28:52 -0700 (PDT)
Received: from dm-uk-02.uk.sun.com ([129.156.101.196])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K42009GJE83TRA0@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 15 Jul 2008 13:28:52 -0700 (PDT)
Received: from serinus.UK.Sun.COM (serinus.UK.Sun.COM [129.156.173.208])
	by dm-uk-02.uk.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2)
 with ESMTP id m6FKSom3005585; Tue, 15 Jul 2008 21:28:50 +0100 (BST)
Received: from [192.168.1.100]
 (vpn-129-150-65-230.East.Sun.COM [129.150.65.230])
	by serinus.UK.Sun.COM (8.13.7+Sun/8.13.7/CTE 3.0)
 with ESMTP id m6FKSZgB026766; Tue, 15 Jul 2008 21:28:42 +0100 (BST)
Date: Tue, 15 Jul 2008 16:27:53 -0400
From: James Gates <james.gates@sun.com>
Subject: LSARC case approved 07/15/2008 (2008/433)
To: lsarc-ext@sun.com, Venky <venkytv@sun.com>
Cc: Peter Dennis - Solaris Sustaining Engineering <peter.dennis@sun.com>,
        Lukas Rovensky <lukas.rovensky@sun.com>
Message-id: <487D0849.4040802@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii; format=flowed
Content-transfer-encoding: 7BIT
X-Accept-Language: en-us, en
X-PMX-Version: 5.4.1.325704
User-Agent: Mozilla/5.0 (X11; U; SunOS sun4u; en-US; rv:1.7.13) Gecko/20060509
Status: RO
Content-Length: 550

All outstanding issues regarding working with the community to implement 
support for IPv6 have been resloved by email - The submitter has agreed 
to do this, and maintain the product going forward. The case was 
approved in today's open LSARC meeting.


Name:           Integrate privoxy into Solaris
Submitter:      Venky Tv
Owner:          James Gates
Interest:
Status:         closed approved fast-track 07/17/2008
Exposure:       open
Comment:

-- 
Jim Gates                    Sun Microsystems
Nashua, USA             http://sun.com/postgresql

