From sh162551@sac.sfbay.sun.com Mon Aug 11 23:49:54 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7C6nrKF004739
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 11 Aug 2008 23:49:53 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m7C6npBK001038;
	Tue, 12 Aug 2008 07:49:52 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5H00E036Z30B00@nwk-avmta-1.sfbay.Sun.COM>; Mon,
 11 Aug 2008 23:49:51 -0700 (PDT)
Received: from dm-sfbay-01.sfbay.sun.com ([129.145.155.118])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5H0059A6Z393E0@nwk-avmta-1.sfbay.Sun.COM>; Mon,
 11 Aug 2008 23:49:51 -0700 (PDT)
Received: from sac.sfbay.sun.com (new-sac.SFBay.Sun.COM [129.146.175.65])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id m7C6nnMa052568; Mon, 11 Aug 2008 23:49:49 -0700 (PDT)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7C6nm6L004733; Mon,
 11 Aug 2008 23:49:48 -0700 (PDT)
Received: (from sh162551@localhost)
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit) id m7C6nmwB004728; Mon,
 11 Aug 2008 23:49:48 -0700 (PDT)
Date: Mon, 11 Aug 2008 23:49:48 -0700 (PDT)
From: Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>
Subject: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout 08/19/2008]
To: lsarc-ext@sun.com
Cc: hua.zhang@sun.com
Message-id: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 9457


Template Version: @(#)sac_nextcase 1.66 04/17/08 SMI
This information is Copyright 2008 Sun Microsystems
1. Introduction
    1.1. Project/Component Working Name:
	 Gkrellm for OpenSolaris
    1.2. Name of Document Author/Supplier:
	 Author:  Henry Zhang
    1.3  Date of This Document:
	11 August, 2008
4. Technical Description
1. Introduction

  1.1. Project/Component Working Name:

       GKrellM 2.3.1

  1.2. Name of Document Author/Supplier:

       Henry Zhang     (hua.zhang@sun.com)

  1.3. Date of This Document:

       30/07/08

  1.4. Name of Major Document Customer(s)/Consumer(s):

    1.4.1. The PAC or CPT you expect to review your project:

           Solaris PAC

    1.4.2. The ARC(s) you expect to review your project:

           LSARC

    1.4.3. The Director/VP who is "Sponsoring" this project:

           Robert.Odea@Sun.Com

    1.4.4. The name of your business unit:

           JDS Desktop Engineering, OPG

  1.5. Email Aliases:
       1.5.1. Responsible Manager:     leo.binchy@Sun.COM
       1.5.2. Responsible Engineer:    hua.zhang@Sun.COM
       1.5.3. Marketing Manager:       jeff.mcmeekin@sun.com
       1.5.4. Interest List:           gkrellm@sun.com

2. Project Summary

  2.1. Project Description:
        
       GKrellM, GNU (or Gtk) Krell Monitors (or Meters), is a single process 
       stack of system monitors which supports applying themes to match its 
       appearance to your window manager, Gtk, or any other theme. The current
       version is 2.3.1

2.2. Risks and Assumptions:
    
    1. Temperature, fan, and voltage sensor monitors not support since missing
       libsensors.

    2. APM laptop battery meter not support since no APM.
    
    3. This application will depend on libgtop, which isn't engineered to fully
       or best support Solaris interfaces for getting system information because
       it was written from a more Linux perspective on system resources, and some
       system information can't get since not fully support from kernel, e.g. 
       some sensor monitor interfaces.

3. Business Summary

  3.1. Problem Area:

       GKrell is a computer program based on the GTK+ toolkit that creates a 
       single process stack of system monitors. It can be used to monitor the 
       status of CPUs, main memory, hard disks, network interfaces, local and 
       remote mailboxes, and many other things. Plugin is supported.

  3.2. Market/Requester:

       JDS Desktop group

  3.3. Business Justification:

       For many users, it's nice to be able to see, real-time, what is happening
       on their system. There are ways to display memory usage, cpu usage, network
       traffic, available and used disk space, and a whole lot of other similar 
       system statistics. This makes it easier to troubleshoot and notice problems
       as they come up. To be display these monitors, you will need gkrellm.

       It's a very useful monitoring tool, can replace a lots of the dock 
       applets, what's even better is that gkrellm supports a plugin interface,
       allowing vast expandability, it's also infinitely configurable and 
       themeable.

       Additionally Gkrellm is very easy on the CPU and packs a lot of information
       into a little bit of space. 

  3.4. Competitive Analysis:

       Windows XP has SysMetrix, Windows Vista has this type of side bar, 
       and GKrellM can run in Linux and other Unix-like operating systems.

  3.5. Opportunity Window/Exposure:

       It is expected that this project will be integrated into Nevada B100

       Note: this tool has GPL V3 license, it will not integrated into 
       Nevada until the license issue is solved.

  3.6. How will you know when you are done?:

       When it is ported to Nevada and runs correctly.  

       The project will be complete when there are no stoppers, P1 or P2 bugs.

4. Technical Description:

  4.1. Details:
       
       GKrellM is a GTK-based stacked monitor program that charts SMP CPUs, 
       disks, load, active net interfaces, and internet connections. There are
       also builtin monitors for memory and swap, file systems with mount/umount
       feature, mailbox checking including POP3 and IMAP, clock/calendar, laptop
       battery, sensors (temperatures, voltages, and fans), and uptime. It has 
       LEDs for the net monitors and an on/off button and online timer for PPP. 
       Multiple monitors managed by a single process to reduce system load.
       There is a GUI popup for configuration, plugin extensions can be installed, 
       and many themes are available. It also features a client/server monitoring 
       capability.

       If you want to configure GkrellM, you can right-click on the monitor and 
       select Configuration from the drop-down menu, or press the F1 key at  
       anytime while GKrellM has the focus. The configuration menu lets you 
       modify general options, built-in monitors, plug-ins, and themes.
       
       GKrellM consists of the gkrellm client and the gkrellmd server. Gkrellm can 
       run in client mode and collect data from gkrellmd server running on a remote
       machine. In this way, the user can remotely monitor different characteristics  
       of all the machines on their LAN, such as hits and load on the web server,  
       disk usage on the mail server, and port traffic on the NAT. 

       The gkrellm client gets data from gkrellmd through SSH. By default gkrellmd
       will not run by default, so the user need to start gkrellmd manually, 
       and optionally add options to configure gkrellmd.  For example,
       you can configure which port gkrellmd will use and which IP addresses or
       hostnames are allowed to connect to gkrellmd. gkrellm client will also be 
       configured to use some port, this port is used to create the SSH connection
       with the gkrellmd server given port. Then you can start gkrellm on another
       system and get the remote data from gkrellmd.


  4.2. Bug/RFE Number(s):

        RFE 6732524

  4.3. In Scope:

       The system information we can get from Solaris 

  4.4. Out of Scope:

       The system information Solaris can't support, e.g. temperature.
       All plugins that are installed by users themselves.

   4.5. Interfaces:
    
      Imported Interfaces
      Interface               Stability    Comments
      -------------------     -----------  -----------------------------------

       /usr/lib/libkstat.so.1   Committed         standard library
       SUNWgettext              Uncommitted
       libgtop                  Volatile          LSARC/2006/347/
       libOpenSSL               Contract Private  PSARC/2006/019/ 
       GNOME Committed Platform Libraries Committed LSARC/2007/520 GTK+ library
                                                        GNOME 2.20 

      Exported Interfaces        Stability      Comments
      -------------------------  -------------  ---------------------------------

       /usr/bin/gkrellm          Volatile       
       SUNWgkrellm               Uncommitted    Package name
       SUNWgkrellm-devel         Uncommitted    Package name

  4.6. Doc Impact:

       Man page will need to be added

  4.7. Admin/Config Impact:

       There are no changes to the system administration and configuration. 

  4.8. HA Impact:

       N/A

  4.9. I18N/L10N Impact:

       The JDS team and the G11N are working together to evaluate and provide
       I18N/L10N support.
       

  4.10. Packaging & Delivery:

        The new packages are:

              -  SUNWgkrellm
              -  SUNWgkrellm-devel 

  4.11. Security Impact:

        There is no additional security impact for Solaris.

  4.12. Dependencies:

        SUNWgettext.spec
        Gtk+ 2.0 >= 2.0 
        gdk 2.0
        glib 2.0 >= 2.0
        libgtop
        libssl

5. Reference Documents:

   GKrellM main project page:   
        http://gkrellm.net

   GKrellM Wiki:
        http://en.wikipedia.org/wiki/GKrellM

   GKrellM themes site:
        http://www.muhri.net/gkrellm/


6. Resources and Schedule:

  6.1. Projected Availability:
       
       Expect to integrated into Nevada in build 100 in Q3 2008

  6.2. Cost of Effort:

       Development     1.0 Engineers - 1 Months
       Testing         0.5 Engineers - 1 Week
       RE              0.5 Engineers - 1 Week

  6.3. Cost of Capital Resources:

       N/A

  6.4. Product Approval Committee requested information:

       6.4.1. Consolidation or Component Name:

              JDS / OpenSolaris
 
       6.4.3. Type of CPT Review and Approval expected:

              Standard

       6.4.4. Project Boundary Conditions:

              None

       6.4.5. Is this a necessary project for OEM agreements:

              No

       6.4.6. Notes:

              N/A

       6.4.7. Target RTI Date/Release:

              Nevada B100 - Sep. 2008

       6.4.8. Target Code Design Review Date:

              Sep. 2008

       6.4.9. Update approval addition:

              New project, no Solaris PAC approval yet

  6.5. ARC review type:

       FastTrack

7. Prototype Availability:

  7.1. Prototype Availability:

       Sep. 2008   

  7.2. Prototype Cost:

       1 engineer
       1 QA
       1 RE

6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		Desktop
    6.5. ARC review type: FastTrack
    6.6. ARC Exposure: open


From Irene.Huang@sun.com Mon Aug 11 23:58:43 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7C6whCM005294
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 11 Aug 2008 23:58:43 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m7C6wZ8M003929
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Tue, 12 Aug 2008 07:58:42 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5H00F057DS1D00@nwk-avmta-1.sfbay.Sun.COM> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@sun.com); Mon, 11 Aug 2008 23:58:40 -0700 (PDT)
Received: from sineb-mail-2.sun.com ([192.18.19.7])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5H005AH7DR95D0@nwk-avmta-1.sfbay.Sun.COM> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Mon,
 11 Aug 2008 23:58:40 -0700 (PDT)
Received: from fe-apac-06.sun.com
 (fe-apac-06.sun.com [192.18.19.177] (may be forged))
	by sineb-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7C6wdb9006992	for
 <lsarc-ext@sun.com>; Tue, 12 Aug 2008 06:58:39 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0K5H00G01764BL00@mail-apac.sun.com>
 (original mail from Irene.Huang@Sun.COM)
 for lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Tue,
 12 Aug 2008 14:58:39 +0800 (SGT)
Received: from [129.158.217.138] by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0K5H00FQ97DOQY5H@mail-apac.sun.com>; Tue,
 12 Aug 2008 14:58:37 +0800 (SGT)
Date: Tue, 12 Aug 2008 14:59:40 +0800
From: Irene Huang <Irene.Huang@sun.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
	08/19/2008]
In-reply-to: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
Sender: Irene.Huang@sun.com
To: Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>
Cc: lsarc-ext@sun.com, hua.zhang@sun.com
Message-id: <1218524380.19381.26.camel@goalie>
MIME-version: 1.0
X-Mailer: Evolution 2.22.2
Content-type: text/plain
Content-transfer-encoding: 8BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
Status: RO
Content-Length: 10346

Hi, all 

additional materials are available at
Internally: 
http://sac.eng/Archives/CaseLog/arc/LSARC/2008/513/materials/

Externally
﻿http://www.opensolaris.org/os/community/arc/caselog/2008/513

--Irene
On Mon, 2008-08-11 at 23:49 -0700, Shi-Ying Irene Huang wrote:
> Template Version: @(#)sac_nextcase 1.66 04/17/08 SMI
> This information is Copyright 2008 Sun Microsystems
> 1. Introduction
>     1.1. Project/Component Working Name:
> 	 Gkrellm for OpenSolaris
>     1.2. Name of Document Author/Supplier:
> 	 Author:  Henry Zhang
>     1.3  Date of This Document:
> 	11 August, 2008
> 4. Technical Description
> 1. Introduction
> 
>   1.1. Project/Component Working Name:
> 
>        GKrellM 2.3.1
> 
>   1.2. Name of Document Author/Supplier:
> 
>        Henry Zhang     (hua.zhang@sun.com)
> 
>   1.3. Date of This Document:
> 
>        30/07/08
> 
>   1.4. Name of Major Document Customer(s)/Consumer(s):
> 
>     1.4.1. The PAC or CPT you expect to review your project:
> 
>            Solaris PAC
> 
>     1.4.2. The ARC(s) you expect to review your project:
> 
>            LSARC
> 
>     1.4.3. The Director/VP who is "Sponsoring" this project:
> 
>            Robert.Odea@Sun.Com
> 
>     1.4.4. The name of your business unit:
> 
>            JDS Desktop Engineering, OPG
> 
>   1.5. Email Aliases:
>        1.5.1. Responsible Manager:     leo.binchy@Sun.COM
>        1.5.2. Responsible Engineer:    hua.zhang@Sun.COM
>        1.5.3. Marketing Manager:       jeff.mcmeekin@sun.com
>        1.5.4. Interest List:           gkrellm@sun.com
> 
> 2. Project Summary
> 
>   2.1. Project Description:
>         
>        GKrellM, GNU (or Gtk) Krell Monitors (or Meters), is a single process 
>        stack of system monitors which supports applying themes to match its 
>        appearance to your window manager, Gtk, or any other theme. The current
>        version is 2.3.1
> 
> 2.2. Risks and Assumptions:
>     
>     1. Temperature, fan, and voltage sensor monitors not support since missing
>        libsensors.
> 
>     2. APM laptop battery meter not support since no APM.
>     
>     3. This application will depend on libgtop, which isn't engineered to fully
>        or best support Solaris interfaces for getting system information because
>        it was written from a more Linux perspective on system resources, and some
>        system information can't get since not fully support from kernel, e.g. 
>        some sensor monitor interfaces.
> 
> 3. Business Summary
> 
>   3.1. Problem Area:
> 
>        GKrell is a computer program based on the GTK+ toolkit that creates a 
>        single process stack of system monitors. It can be used to monitor the 
>        status of CPUs, main memory, hard disks, network interfaces, local and 
>        remote mailboxes, and many other things. Plugin is supported.
> 
>   3.2. Market/Requester:
> 
>        JDS Desktop group
> 
>   3.3. Business Justification:
> 
>        For many users, it's nice to be able to see, real-time, what is happening
>        on their system. There are ways to display memory usage, cpu usage, network
>        traffic, available and used disk space, and a whole lot of other similar 
>        system statistics. This makes it easier to troubleshoot and notice problems
>        as they come up. To be display these monitors, you will need gkrellm.
> 
>        It's a very useful monitoring tool, can replace a lots of the dock 
>        applets, what's even better is that gkrellm supports a plugin interface,
>        allowing vast expandability, it's also infinitely configurable and 
>        themeable.
> 
>        Additionally Gkrellm is very easy on the CPU and packs a lot of information
>        into a little bit of space. 
> 
>   3.4. Competitive Analysis:
> 
>        Windows XP has SysMetrix, Windows Vista has this type of side bar, 
>        and GKrellM can run in Linux and other Unix-like operating systems.
> 
>   3.5. Opportunity Window/Exposure:
> 
>        It is expected that this project will be integrated into Nevada B100
> 
>        Note: this tool has GPL V3 license, it will not integrated into 
>        Nevada until the license issue is solved.
> 
>   3.6. How will you know when you are done?:
> 
>        When it is ported to Nevada and runs correctly.  
> 
>        The project will be complete when there are no stoppers, P1 or P2 bugs.
> 
> 4. Technical Description:
> 
>   4.1. Details:
>        
>        GKrellM is a GTK-based stacked monitor program that charts SMP CPUs, 
>        disks, load, active net interfaces, and internet connections. There are
>        also builtin monitors for memory and swap, file systems with mount/umount
>        feature, mailbox checking including POP3 and IMAP, clock/calendar, laptop
>        battery, sensors (temperatures, voltages, and fans), and uptime. It has 
>        LEDs for the net monitors and an on/off button and online timer for PPP. 
>        Multiple monitors managed by a single process to reduce system load.
>        There is a GUI popup for configuration, plugin extensions can be installed, 
>        and many themes are available. It also features a client/server monitoring 
>        capability.
> 
>        If you want to configure GkrellM, you can right-click on the monitor and 
>        select Configuration from the drop-down menu, or press the F1 key at  
>        anytime while GKrellM has the focus. The configuration menu lets you 
>        modify general options, built-in monitors, plug-ins, and themes.
>        
>        GKrellM consists of the gkrellm client and the gkrellmd server. Gkrellm can 
>        run in client mode and collect data from gkrellmd server running on a remote
>        machine. In this way, the user can remotely monitor different characteristics  
>        of all the machines on their LAN, such as hits and load on the web server,  
>        disk usage on the mail server, and port traffic on the NAT. 
> 
>        The gkrellm client gets data from gkrellmd through SSH. By default gkrellmd
>        will not run by default, so the user need to start gkrellmd manually, 
>        and optionally add options to configure gkrellmd.  For example,
>        you can configure which port gkrellmd will use and which IP addresses or
>        hostnames are allowed to connect to gkrellmd. gkrellm client will also be 
>        configured to use some port, this port is used to create the SSH connection
>        with the gkrellmd server given port. Then you can start gkrellm on another
>        system and get the remote data from gkrellmd.
> 
> 
>   4.2. Bug/RFE Number(s):
> 
>         RFE 6732524
> 
>   4.3. In Scope:
> 
>        The system information we can get from Solaris 
> 
>   4.4. Out of Scope:
> 
>        The system information Solaris can't support, e.g. temperature.
>        All plugins that are installed by users themselves.
> 
>    4.5. Interfaces:
>     
>       Imported Interfaces
>       Interface               Stability    Comments
>       -------------------     -----------  -----------------------------------
> 
>        /usr/lib/libkstat.so.1   Committed         standard library
>        SUNWgettext              Uncommitted
>        libgtop                  Volatile          LSARC/2006/347/
>        libOpenSSL               Contract Private  PSARC/2006/019/ 
>        GNOME Committed Platform Libraries Committed LSARC/2007/520 GTK+ library
>                                                         GNOME 2.20 
> 
>       Exported Interfaces        Stability      Comments
>       -------------------------  -------------  ---------------------------------
> 
>        /usr/bin/gkrellm          Volatile       
>        SUNWgkrellm               Uncommitted    Package name
>        SUNWgkrellm-devel         Uncommitted    Package name
> 
>   4.6. Doc Impact:
> 
>        Man page will need to be added
> 
>   4.7. Admin/Config Impact:
> 
>        There are no changes to the system administration and configuration. 
> 
>   4.8. HA Impact:
> 
>        N/A
> 
>   4.9. I18N/L10N Impact:
> 
>        The JDS team and the G11N are working together to evaluate and provide
>        I18N/L10N support.
>        
> 
>   4.10. Packaging & Delivery:
> 
>         The new packages are:
> 
>               -  SUNWgkrellm
>               -  SUNWgkrellm-devel 
> 
>   4.11. Security Impact:
> 
>         There is no additional security impact for Solaris.
> 
>   4.12. Dependencies:
> 
>         SUNWgettext.spec
>         Gtk+ 2.0 >= 2.0 
>         gdk 2.0
>         glib 2.0 >= 2.0
>         libgtop
>         libssl
> 
> 5. Reference Documents:
> 
>    GKrellM main project page:   
>         http://gkrellm.net
> 
>    GKrellM Wiki:
>         http://en.wikipedia.org/wiki/GKrellM
> 
>    GKrellM themes site:
>         http://www.muhri.net/gkrellm/
> 
> 
> 6. Resources and Schedule:
> 
>   6.1. Projected Availability:
>        
>        Expect to integrated into Nevada in build 100 in Q3 2008
> 
>   6.2. Cost of Effort:
> 
>        Development     1.0 Engineers - 1 Months
>        Testing         0.5 Engineers - 1 Week
>        RE              0.5 Engineers - 1 Week
> 
>   6.3. Cost of Capital Resources:
> 
>        N/A
> 
>   6.4. Product Approval Committee requested information:
> 
>        6.4.1. Consolidation or Component Name:
> 
>               JDS / OpenSolaris
>  
>        6.4.3. Type of CPT Review and Approval expected:
> 
>               Standard
> 
>        6.4.4. Project Boundary Conditions:
> 
>               None
> 
>        6.4.5. Is this a necessary project for OEM agreements:
> 
>               No
> 
>        6.4.6. Notes:
> 
>               N/A
> 
>        6.4.7. Target RTI Date/Release:
> 
>               Nevada B100 - Sep. 2008
> 
>        6.4.8. Target Code Design Review Date:
> 
>               Sep. 2008
> 
>        6.4.9. Update approval addition:
> 
>               New project, no Solaris PAC approval yet
> 
>   6.5. ARC review type:
> 
>        FastTrack
> 
> 7. Prototype Availability:
> 
>   7.1. Prototype Availability:
> 
>        Sep. 2008   
> 
>   7.2. Prototype Cost:
> 
>        1 engineer
>        1 QA
>        1 RE
> 
> 6. Resources and Schedule
>     6.4. Steering Committee requested information
>    	6.4.1. Consolidation C-team Name:
> 		Desktop
>     6.5. ARC review type: FastTrack
>     6.6. ARC Exposure: open
> 


From Darren.Moffat@Sun.COM Tue Aug 12 02:44:55 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7C9itj2010879
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 12 Aug 2008 02:44:55 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m7C9if64010011
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Tue, 12 Aug 2008 10:44:54 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5H00J05F2S3Z00@nwk-avmta-2.sfbay.sun.com> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@sun.com); Tue, 12 Aug 2008 02:44:52 -0700 (PDT)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5H009NPF2R87A0@nwk-avmta-2.sfbay.sun.com> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Tue,
 12 Aug 2008 02:44:51 -0700 (PDT)
Received: from fe-emea-10.sun.com (gmp-eb-lb-2-fe3.eu.sun.com [192.18.6.12])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m7C9io8O005245	for
 <lsarc-ext@sun.com>; Tue, 12 Aug 2008 09:44:50 +0000 (GMT)
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K5H00D01EXUK700@fe-emea-10.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Tue,
 12 Aug 2008 10:44:50 +0100 (BST)
Received: from [129.156.173.21] by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K5H00KPVF2HYA90@fe-emea-10.sun.com>; Tue,
 12 Aug 2008 10:44:42 +0100 (BST)
Date: Tue, 12 Aug 2008 10:44:41 +0100
From: Darren J Moffat <Darren.Moffat@Sun.COM>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
 08/19/2008]
In-reply-to: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
Sender: Darren.Moffat@Sun.COM
To: Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>
Cc: lsarc-ext@Sun.COM, Hua.Zhang@Sun.COM
Message-id: <48A15B89.7040302@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.14 (X11/20080630)
Status: RO
Content-Length: 379

When using gkrellmd is the assumption that it should only run as a real 
end user rather than a system service ?

For the battery support we do have interfaces to battery information in 
OpenSolaris just as the material says not APM.  I highly recommend that 
this project fix gkrellm so that it can use the APIs available on 
OpenSolaris for battery status.

--
Darren J Moffat

From Hua.Zhang@sun.com Tue Aug 12 04:58:15 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7CBwEYN012879
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 12 Aug 2008 04:58:14 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m7CBw86n016343
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Tue, 12 Aug 2008 19:58:13 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5H00I05L90TT00@brm-avmta-1.central.sun.com> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@sun.com); Tue, 12 Aug 2008 05:58:12 -0600 (MDT)
Received: from sineb-mail-1.sun.com ([192.18.19.6])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5H008RRL8YX660@brm-avmta-1.central.sun.com> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Tue,
 12 Aug 2008 05:58:11 -0600 (MDT)
Received: from fe-apac-05.sun.com
 (fe-apac-05.sun.com [192.18.19.176] (may be forged))
	by sineb-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7CBwAtk015422	for
 <lsarc-ext@sun.com>; Tue, 12 Aug 2008 11:58:10 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0K5H00M01L81P000@mail-apac.sun.com> (original mail from Hua.Zhang@Sun.COM)
 for lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Tue,
 12 Aug 2008 19:58:10 +0800 (SGT)
Received: from [129.158.217.156] by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0K5H00M2IL8X9U2Q@mail-apac.sun.com>; Tue,
 12 Aug 2008 19:58:10 +0800 (SGT)
Date: Tue, 12 Aug 2008 20:02:14 +0800
From: Henry Zhang <Hua.Zhang@sun.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
 08/19/2008]
In-reply-to: <48A15B89.7040302@Sun.COM>
Sender: Hua.Zhang@sun.com
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>, lsarc-ext@sun.com
Message-id: <48A17BC6.7010000@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 8BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A15B89.7040302@Sun.COM>
User-Agent: Thunderbird 2.0.0.6 (X11/20071119)
Status: RO
Content-Length: 567



Darren J Moffat 写道:
> When using gkrellmd is the assumption that it should only run as a real 
> end user rather than a system service ?
yes, gkrellmd works only with the gkrellm client, whose IP is provided 
to gkrellmd.

> 
> For the battery support we do have interfaces to battery information in 
> OpenSolaris just as the material says not APM.  I highly recommend that 
> this project fix gkrellm so that it can use the APIs available on 
> OpenSolaris for battery status.
Do you mean "the API available on OpenSolaris" is APM?
> 
> -- 
> Darren J Moffat

From Darren.Moffat@sun.com Tue Aug 12 05:13:58 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7CCDvfO013720
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 12 Aug 2008 05:13:57 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m7CCDFHA021342
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Tue, 12 Aug 2008 20:13:56 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5H00203LZ6WU00@nwk-avmta-2.sfbay.sun.com> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@sun.com); Tue, 12 Aug 2008 05:13:54 -0700 (PDT)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5H001PELZ5R9B0@nwk-avmta-2.sfbay.sun.com> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Tue,
 12 Aug 2008 05:13:53 -0700 (PDT)
Received: from fe-emea-09.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m7CCDqjl025746	for
 <lsarc-ext@sun.com>; Tue, 12 Aug 2008 12:13:52 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K5H00K01LMRI500@fe-emea-09.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Tue,
 12 Aug 2008 13:13:52 +0100 (BST)
Received: from [129.156.173.21] by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K5H00HVJLYSFD40@fe-emea-09.sun.com>; Tue,
 12 Aug 2008 13:13:40 +0100 (BST)
Date: Tue, 12 Aug 2008 13:13:40 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
 08/19/2008]
In-reply-to: <48A17BC6.7010000@sun.com>
Sender: Darren.Moffat@sun.com
To: Henry Zhang <Hua.Zhang@sun.com>
Cc: Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>, lsarc-ext@sun.com
Message-id: <48A17E74.5030703@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 8BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A15B89.7040302@Sun.COM> <48A17BC6.7010000@sun.com>
User-Agent: Thunderbird 2.0.0.14 (X11/20080630)
Status: RO
Content-Length: 762

Henry Zhang wrote:
> 
> 
> Darren J Moffat 写道:
>> When using gkrellmd is the assumption that it should only run as a 
>> real end user rather than a system service ?
> yes, gkrellmd works only with the gkrellm client, whose IP is provided 
> to gkrellmd.
> 
>>
>> For the battery support we do have interfaces to battery information 
>> in OpenSolaris just as the material says not APM.  I highly recommend 
>> that this project fix gkrellm so that it can use the APIs available on 
>> OpenSolaris for battery status.
> Do you mean "the API available on OpenSolaris" is APM?

No I mean there is an API available for getting that information.  It is 
used by existing GNOME applets.

This case should update gkrellmd to use the same API.

-- 
Darren J Moffat

From Hua.Zhang@sun.com Tue Aug 12 05:18:56 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7CCIuUJ013802
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 12 Aug 2008 05:18:56 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m7CCItFe016456
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Tue, 12 Aug 2008 05:18:56 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5H00K05M7J9000@brm-avmta-1.central.sun.com> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@sun.com); Tue, 12 Aug 2008 06:18:55 -0600 (MDT)
Received: from sineb-mail-2.sun.com ([192.18.19.7])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5H0082KM7HX680@brm-avmta-1.central.sun.com> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Tue,
 12 Aug 2008 06:18:54 -0600 (MDT)
Received: from fe-apac-05.sun.com
 (fe-apac-05.sun.com [192.18.19.176] (may be forged))
	by sineb-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7CCIrMb025870	for
 <lsarc-ext@sun.com>; Tue, 12 Aug 2008 12:18:53 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0K5H00801M4DK100@mail-apac.sun.com> (original mail from Hua.Zhang@Sun.COM)
 for lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Tue,
 12 Aug 2008 20:18:53 +0800 (SGT)
Received: from [129.158.217.156] by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0K5H003KUM7GJPL7@mail-apac.sun.com>; Tue,
 12 Aug 2008 20:18:53 +0800 (SGT)
Date: Tue, 12 Aug 2008 20:22:56 +0800
From: Henry Zhang <Hua.Zhang@sun.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
 08/19/2008]
In-reply-to: <48A17E74.5030703@Sun.COM>
Sender: Hua.Zhang@sun.com
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>, lsarc-ext@sun.com
Message-id: <48A180A0.4030503@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 8BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A15B89.7040302@Sun.COM> <48A17BC6.7010000@sun.com>
 <48A17E74.5030703@Sun.COM>
User-Agent: Thunderbird 2.0.0.6 (X11/20071119)
Status: RO
Content-Length: 964



Darren J Moffat 写道:
> Henry Zhang wrote:
>>
>>
>> Darren J Moffat 写道:
>>> When using gkrellmd is the assumption that it should only run as a 
>>> real end user rather than a system service ?
>> yes, gkrellmd works only with the gkrellm client, whose IP is provided 
>> to gkrellmd.
>>
>>>
>>> For the battery support we do have interfaces to battery information 
>>> in OpenSolaris just as the material says not APM.  I highly recommend 
>>> that this project fix gkrellm so that it can use the APIs available 
>>> on OpenSolaris for battery status.
>> Do you mean "the API available on OpenSolaris" is APM?
> 
> No I mean there is an API available for getting that information.  It is 
> used by existing GNOME applets.
> 
> This case should update gkrellmd to use the same API.

As I know, we have ACPI in 2008.5, but not APM, need to dig into the 
codes to see if all is OK to call it to implement the battery support, 
if so, will add.. Thanks...
> 

From Darren.Moffat@sun.com Tue Aug 12 06:03:33 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7CD3WDS015545
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 12 Aug 2008 06:03:33 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m7CD3S2U009506
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Tue, 12 Aug 2008 21:03:29 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5H00009O9R6A00@brm-avmta-1.central.sun.com> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@Sun.COM); Tue, 12 Aug 2008 07:03:27 -0600 (MDT)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5H008QUO9QXBA0@brm-avmta-1.central.sun.com> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@Sun.COM); Tue,
 12 Aug 2008 07:03:26 -0600 (MDT)
Received: from fe-emea-10.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m7CD3PO6002881	for
 <lsarc-ext@Sun.COM>; Tue, 12 Aug 2008 13:03:26 +0000 (GMT)
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K5H00I01O2B2900@fe-emea-10.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for lsarc-ext@Sun.COM (ORCPT lsarc-ext@Sun.COM); Tue,
 12 Aug 2008 14:03:25 +0100 (BST)
Received: from [129.156.173.21] by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K5H00CJJO9KDV40@fe-emea-10.sun.com>; Tue,
 12 Aug 2008 14:03:21 +0100 (BST)
Date: Tue, 12 Aug 2008 14:03:20 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
 08/19/2008]
In-reply-to: <48A180A0.4030503@sun.com>
Sender: Darren.Moffat@sun.com
To: Henry Zhang <Hua.Zhang@sun.com>
Cc: Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>, lsarc-ext@sun.com
Message-id: <48A18A18.8020106@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 8BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A15B89.7040302@Sun.COM> <48A17BC6.7010000@sun.com>
 <48A17E74.5030703@Sun.COM> <48A180A0.4030503@sun.com>
User-Agent: Thunderbird 2.0.0.14 (X11/20080630)
Status: RO
Content-Length: 1100

Henry Zhang wrote:
> 
> 
> Darren J Moffat 写道:
>> Henry Zhang wrote:
>>>
>>>
>>> Darren J Moffat 写道:
>>>> When using gkrellmd is the assumption that it should only run as a 
>>>> real end user rather than a system service ?
>>> yes, gkrellmd works only with the gkrellm client, whose IP is 
>>> provided to gkrellmd.
>>>
>>>>
>>>> For the battery support we do have interfaces to battery information 
>>>> in OpenSolaris just as the material says not APM.  I highly 
>>>> recommend that this project fix gkrellm so that it can use the APIs 
>>>> available on OpenSolaris for battery status.
>>> Do you mean "the API available on OpenSolaris" is APM?
>>
>> No I mean there is an API available for getting that information.  It 
>> is used by existing GNOME applets.
>>
>> This case should update gkrellmd to use the same API.
> 
> As I know, we have ACPI in 2008.5, but not APM, need to dig into the 
> codes to see if all is OK to call it to implement the battery support, 
> if so, will add.. Thanks...

This case should be "waiting need spec" until that is discovered.

-- 
Darren J Moffat

From Harry.Lu@sun.com Tue Aug 12 06:41:45 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7CDfieK015834
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 12 Aug 2008 06:41:44 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m7CDfgaE014636
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Tue, 12 Aug 2008 14:41:43 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5H00D03Q1IA700@nwk-avmta-1.sfbay.Sun.COM> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@Sun.COM); Tue, 12 Aug 2008 06:41:42 -0700 (PDT)
Received: from sineb-mail-2.sun.com ([192.18.19.7])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5H005PGQ1H2F50@nwk-avmta-1.sfbay.Sun.COM> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@Sun.COM); Tue,
 12 Aug 2008 06:41:42 -0700 (PDT)
Received: from fe-apac-06.sun.com
 (fe-apac-06.sun.com [192.18.19.177] (may be forged))
	by sineb-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7CDffCW028036	for
 <lsarc-ext@Sun.COM>; Tue, 12 Aug 2008 13:41:41 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0K5H00601PSTF400@mail-apac.sun.com> (original mail from Harry.Lu@Sun.COM)
 for lsarc-ext@Sun.COM (ORCPT lsarc-ext@Sun.COM); Tue,
 12 Aug 2008 21:41:41 +0800 (SGT)
Received: from [192.168.1.3] ([125.34.1.152])
 by mail-apac.sun.com (Sun Java System Messaging Server 6.2-6.01 (built Apr  3
 2006)) with ESMTPSA id <0K5H00BMZQ1CRFEA@mail-apac.sun.com>; Tue,
 12 Aug 2008 21:41:40 +0800 (SGT)
Date: Tue, 12 Aug 2008 21:41:28 +0800
From: Harry Lu <Harry.Lu@sun.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
 08/19/2008]
In-reply-to: <48A180A0.4030503@sun.com>
Sender: Harry.Lu@sun.com
To: Henry Zhang <Hua.Zhang@sun.com>
Cc: Darren J Moffat <Darren.Moffat@sun.com>,
        Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>, lsarc-ext@sun.com
Message-id: <48A19308.5090809@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A15B89.7040302@Sun.COM> <48A17BC6.7010000@sun.com>
 <48A17E74.5030703@Sun.COM> <48A180A0.4030503@sun.com>
User-Agent: Thunderbird 2.0.0.16 (Windows/20080708)
Status: RO
Content-Length: 334


>
> As I know, we have ACPI in 2008.5, but not APM, need to dig into the 
> codes to see if all is OK to call it to implement the battery support, 
> if so, will add.. Thanks...
>>

Henry,

    There is a HAL interface used by G-P-M and battery status applet for 
the battery info. Please talk with Simon and Jeff about that.

Harry

From Brian.Cameron@Sun.COM Tue Aug 12 15:56:55 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7CMusNW004536
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 12 Aug 2008 15:56:54 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m7CMukwu003090
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Tue, 12 Aug 2008 23:56:53 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5I0050BFQQFT00@nwk-avmta-2.sfbay.sun.com> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@sun.com); Tue, 12 Aug 2008 15:56:50 -0700 (PDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5I00KM2FQP4L90@nwk-avmta-2.sfbay.sun.com> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Tue,
 12 Aug 2008 15:56:49 -0700 (PDT)
Received: from fe-amer-09.sun.com ([192.18.109.79])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7CMundm024234	for
 <lsarc-ext@sun.com>; Tue, 12 Aug 2008 22:56:49 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K5I00E01FNNMF00@mail-amer.sun.com>
 (original mail from Brian.Cameron@Sun.COM)
 for lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Tue,
 12 Aug 2008 16:56:49 -0600 (MDT)
Received: from [192.168.1.108] ([67.167.213.227])
 by mail-amer.sun.com (Sun Java System Messaging Server 6.2-8.04 (built Feb 28
 2007)) with ESMTPSA id <0K5I00LM4FQO51C0@mail-amer.sun.com>; Tue,
 12 Aug 2008 16:56:48 -0600 (MDT)
Date: Tue, 12 Aug 2008 17:56:51 -0500
From: Brian Cameron <Brian.Cameron@Sun.COM>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
 08/19/2008]
In-reply-to: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
Sender: Brian.Cameron@Sun.COM
To: Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>
Cc: lsarc-ext@Sun.COM, Hua.Zhang@Sun.COM
Message-id: <48A21533.7020806@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.16 (X11/20080731)
Status: RO
Content-Length: 480


Irene:

Sections 3.1, 3.4, 4.1, and 4.4 all discuss that Gkrellm supports
plugins, but there is no information about plugins in the exported
interface table.  How can it support a plugin framework without
exporting any related interfaces?

>   4.11. Security Impact:
> 
>         There is no additional security impact for Solaris.

How can something which uses OpenSSL, has a plugin framework, and allows
remote observation of a network's health have no security impact?

Brian

From Irene.Huang@sun.com Wed Aug 13 01:42:14 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7D8gDhv020747
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 13 Aug 2008 01:42:13 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m7D8g3Nu009073
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Wed, 13 Aug 2008 16:42:11 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5J000016U9J200@nwk-avmta-1.sfbay.Sun.COM> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@sun.com); Wed, 13 Aug 2008 01:42:09 -0700 (PDT)
Received: from sineb-mail-2.sun.com ([192.18.19.7])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5J002E16U8MEC0@nwk-avmta-1.sfbay.Sun.COM> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Wed,
 13 Aug 2008 01:42:09 -0700 (PDT)
Received: from fe-apac-05.sun.com
 (fe-apac-05.sun.com [192.18.19.176] (may be forged))
	by sineb-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7D8g8Gl010860	for
 <lsarc-ext@sun.com>; Wed, 13 Aug 2008 08:42:08 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0K5J00B016Q5JS00@mail-apac.sun.com>
 (original mail from Irene.Huang@Sun.COM)
 for lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Wed,
 13 Aug 2008 16:42:08 +0800 (SGT)
Received: from [129.158.146.215] by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0K5J00MYG6U69USS@mail-apac.sun.com>; Wed,
 13 Aug 2008 16:42:07 +0800 (SGT)
Date: Wed, 13 Aug 2008 16:42:06 +0800
From: Irene Huang <Irene.Huang@sun.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
 08/19/2008]
In-reply-to: <48A18A18.8020106@Sun.COM>
Sender: Irene.Huang@sun.com
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Henry Zhang <Hua.Zhang@sun.com>,
        Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>, lsarc-ext@sun.com
Message-id: <48A29E5E.3040105@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 8BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A15B89.7040302@Sun.COM> <48A17BC6.7010000@sun.com>
 <48A17E74.5030703@Sun.COM> <48A180A0.4030503@sun.com>
 <48A18A18.8020106@Sun.COM>
User-Agent: Thunderbird 2.0.0.16 (Windows/20080708)
Status: RO
Content-Length: 1177

Status set to "waiting need spec"

--irene
Darren J Moffat wrote:
> Henry Zhang wrote:
>>
>>
>> Darren J Moffat 写道:
>>> Henry Zhang wrote:
>>>>
>>>>
>>>> Darren J Moffat 写道:
>>>>> When using gkrellmd is the assumption that it should only run as a 
>>>>> real end user rather than a system service ?
>>>> yes, gkrellmd works only with the gkrellm client, whose IP is 
>>>> provided to gkrellmd.
>>>>
>>>>>
>>>>> For the battery support we do have interfaces to battery 
>>>>> information in OpenSolaris just as the material says not APM.  I 
>>>>> highly recommend that this project fix gkrellm so that it can use 
>>>>> the APIs available on OpenSolaris for battery status.
>>>> Do you mean "the API available on OpenSolaris" is APM?
>>>
>>> No I mean there is an API available for getting that information.  
>>> It is used by existing GNOME applets.
>>>
>>> This case should update gkrellmd to use the same API.
>>
>> As I know, we have ACPI in 2008.5, but not APM, need to dig into the 
>> codes to see if all is OK to call it to implement the battery 
>> support, if so, will add.. Thanks...
>
> This case should be "waiting need spec" until that is discovered.
>


From Hua.Zhang@Sun.COM Wed Aug 13 02:16:12 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7D9GBlf022737
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 13 Aug 2008 02:16:11 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m7D9G9Wx028038
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Wed, 13 Aug 2008 10:16:10 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5J004078EXCF00@nwk-avmta-1.sfbay.Sun.COM> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@sun.com); Wed, 13 Aug 2008 02:16:09 -0700 (PDT)
Received: from sineb-mail-1.sun.com ([192.18.19.6])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5J0037S8EWY000@nwk-avmta-1.sfbay.Sun.COM> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Wed,
 13 Aug 2008 02:16:09 -0700 (PDT)
Received: from fe-apac-06.sun.com
 (fe-apac-06.sun.com [192.18.19.177] (may be forged))
	by sineb-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7D9G7Gt006785	for
 <lsarc-ext@sun.com>; Wed, 13 Aug 2008 09:16:07 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0K5J001018EVJN00@mail-apac.sun.com> (original mail from Hua.Zhang@Sun.COM)
 for lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Wed,
 13 Aug 2008 17:16:07 +0800 (SGT)
Received: from [129.158.217.156] by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0K5J00BZE8EURG40@mail-apac.sun.com>; Wed,
 13 Aug 2008 17:16:07 +0800 (SGT)
Date: Wed, 13 Aug 2008 17:20:12 +0800
From: Henry Zhang <Hua.Zhang@Sun.COM>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
 08/19/2008]
In-reply-to: <48A21533.7020806@sun.com>
Sender: Hua.Zhang@Sun.COM
To: Brian Cameron <Brian.Cameron@Sun.COM>
Cc: Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>, lsarc-ext@Sun.COM
Message-id: <48A2A74C.80905@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 8BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com>
User-Agent: Thunderbird 2.0.0.6 (X11/20071119)
Status: RO
Content-Length: 1008



Brian Cameron 写道:
> 
> Irene:
> 
> Sections 3.1, 3.4, 4.1, and 4.4 all discuss that Gkrellm supports
> plugins, but there is no information about plugins in the exported
> interface table.  How can it support a plugin framework without
> exporting any related interfaces?
Sure, it export /usr/include/gkrellm2/gkrellm.h, in which the structure 
GkrellmMonitor is listed, it's used to record all plugin relative 
functions. I will add it to export interface of the proposal.
> 
>>   4.11. Security Impact:
>>
>>         There is no additional security impact for Solaris.
> 
> How can something which uses OpenSSL, has a plugin framework, and allows
> remote observation of a network's health have no security impact?
I think there is some general security problem when an application 
connect to network, it may exist all applications using OpenSSL/plugin.
I will add some words to identify that this application is using 
OpenSSL, and support plugin to transfer system status information.

> 
> Brian

From Darren.Moffat@sun.com Wed Aug 13 05:35:50 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7DCZnHV026190
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 13 Aug 2008 05:35:50 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m7DCZf83027890
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Wed, 13 Aug 2008 20:35:49 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5J00B03HNOGP00@brm-avmta-1.central.sun.com> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@sun.com); Wed, 13 Aug 2008 06:35:48 -0600 (MDT)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5J007KTHNMAC30@brm-avmta-1.central.sun.com> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Wed,
 13 Aug 2008 06:35:47 -0600 (MDT)
Received: from fe-emea-09.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m7DCZkrp001320	for
 <lsarc-ext@sun.com>; Wed, 13 Aug 2008 12:35:46 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K5J00J01HJFJS00@fe-emea-09.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Wed,
 13 Aug 2008 13:35:46 +0100 (BST)
Received: from [129.156.173.21] by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K5J00JCXHNKOM70@fe-emea-09.sun.com>; Wed,
 13 Aug 2008 13:35:46 +0100 (BST)
Date: Wed, 13 Aug 2008 13:35:44 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
	08/19/2008]
In-reply-to: <48A2A74C.80905@sun.com>
Sender: Darren.Moffat@sun.com
To: Henry Zhang <Hua.Zhang@sun.com>
Cc: Brian Cameron <Brian.Cameron@sun.com>, lsarc-ext@sun.com,
        Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>
Message-id: <48A2D520.1010902@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com>
User-Agent: Thunderbird 2.0.0.14 (X11/20080630)
Status: RO
Content-Length: 213

If it is using OpenSSL for SSL/TLS then there needs to be certificates 
in use somewhere, so where are they stored for the "server side" and 
where are the trust anchors for the "client side".

--
Darren J Moffat

From Brian.Cameron@sun.com Wed Aug 13 11:57:43 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7DIvhH6013021
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 13 Aug 2008 11:57:43 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m7DIvg8S048999
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Wed, 13 Aug 2008 12:57:42 -0600 (MDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5J00E0HZC68F00@brm-avmta-1.central.sun.com> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@sun.com); Wed, 13 Aug 2008 12:57:42 -0600 (MDT)
Received: from brmea-mail-2.sun.com ([192.18.98.43])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5J002H8ZC67TA0@brm-avmta-1.central.sun.com> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Wed,
 13 Aug 2008 12:57:42 -0600 (MDT)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7DIvgR1007006	for
 <lsarc-ext@sun.com>; Wed, 13 Aug 2008 18:57:42 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K5J00701YRDO800@mail-amer.sun.com>
 (original mail from Brian.Cameron@Sun.COM)
 for lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Wed,
 13 Aug 2008 12:57:42 -0600 (MDT)
Received: from [129.153.250.11] by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K5J00E1MZBR7XB0@mail-amer.sun.com>; Wed,
 13 Aug 2008 12:57:28 -0600 (MDT)
Date: Wed, 13 Aug 2008 13:57:27 -0500
From: Brian Cameron <Brian.Cameron@sun.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
	08/19/2008]
In-reply-to: <48A2A74C.80905@sun.com>
Sender: Brian.Cameron@sun.com
To: Henry Zhang <Hua.Zhang@sun.com>
Cc: lsarc-ext@sun.com, Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>
Reply-to: Brian.Cameron@sun.com
Message-id: <48A32E97.3090308@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com>
User-Agent: Thunderbird 2.0.0.14 (X11/20080505)
Status: RO
Content-Length: 1740


Henry:

>> Sections 3.1, 3.4, 4.1, and 4.4 all discuss that Gkrellm supports
>> plugins, but there is no information about plugins in the exported
>> interface table.  How can it support a plugin framework without
>> exporting any related interfaces?
> Sure, it export /usr/include/gkrellm2/gkrellm.h, in which the structure 
> GkrellmMonitor is listed, it's used to record all plugin relative 
> functions. I will add it to export interface of the proposal.

After I've written a plugin, how do I integrate it into the GKrellM
infrastructure.  Do plugins have to be installed in a particular
location, for example, for them to be loaded by the GKrellM daemon?

If so, this plugin directory (or whatever interface is used) should be
highlighted in the ARC materials and the manpage.

>>>   4.11. Security Impact:
>>>
>>>         There is no additional security impact for Solaris.
>> How can something which uses OpenSSL, has a plugin framework, and allows
>> remote observation of a network's health have no security impact?
> I think there is some general security problem when an application 
> connect to network, it may exist all applications using OpenSSL/plugin.
> I will add some words to identify that this application is using 
> OpenSSL, and support plugin to transfer system status information.

Is it possible for a person to write a plugin that does something
malicious?  What protects the system from malicious plugins?  Can
only the sysadmin install new plugins, for example?

What protects the traffic between the remote and local machine from
malicious snooping?  I'd guess OpenSSL is being used for this.  I'm
just saying that the answer should be more fleshed out.  "None" isn't
a good answer in this case.

-- 

Brian

From Hua.Zhang@sun.com Thu Aug 14 01:28:35 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7E8SZqJ006958
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 14 Aug 2008 01:28:35 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m7E8SURp024392
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Thu, 14 Aug 2008 01:28:35 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5L006090VLM500@brm-avmta-1.central.sun.com> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@sun.com); Thu, 14 Aug 2008 02:28:33 -0600 (MDT)
Received: from sineb-mail-2.sun.com ([192.18.19.7])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5L00JJS0VJAMD0@brm-avmta-1.central.sun.com> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Thu,
 14 Aug 2008 02:28:32 -0600 (MDT)
Received: from fe-apac-06.sun.com
 (fe-apac-06.sun.com [192.18.19.177] (may be forged))
	by sineb-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7E8SVg9005256	for
 <lsarc-ext@sun.com>; Thu, 14 Aug 2008 08:28:31 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0K5L005010VA8900@mail-apac.sun.com> (original mail from Hua.Zhang@Sun.COM)
 for lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Thu,
 14 Aug 2008 16:28:30 +0800 (SGT)
Received: from [129.158.217.156] by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0K5L009MS0VH8GHT@mail-apac.sun.com>; Thu,
 14 Aug 2008 16:28:30 +0800 (SGT)
Date: Thu, 14 Aug 2008 16:32:36 +0800
From: Henry Zhang <Hua.Zhang@sun.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
	08/19/2008]
In-reply-to: <48A32E97.3090308@Sun.COM>
Sender: Hua.Zhang@sun.com
To: Brian.Cameron@sun.com
Cc: lsarc-ext@sun.com, Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>
Message-id: <48A3EDA4.8090206@sun.com>
MIME-version: 1.0
Content-type: multipart/mixed; boundary="Boundary_(ID_Y/qbF6JOX9uL5urMM6n6Ag)"
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com> <48A32E97.3090308@Sun.COM>
User-Agent: Thunderbird 2.0.0.6 (X11/20071119)
Status: RO
Content-Length: 12426

This is a multi-part message in MIME format.

--Boundary_(ID_Y/qbF6JOX9uL5urMM6n6Ag)
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 8BIT

Brian, etc. all:

See my answer in-line below.

Please see the updated proposal according to all of the comments.
See the attchemnt.

Thanks,
Henry

Brian Cameron 写道:
> 
> Henry:
> 
>>> Sections 3.1, 3.4, 4.1, and 4.4 all discuss that Gkrellm supports
>>> plugins, but there is no information about plugins in the exported
>>> interface table.  How can it support a plugin framework without
>>> exporting any related interfaces?
>> Sure, it export /usr/include/gkrellm2/gkrellm.h, in which the 
>> structure GkrellmMonitor is listed, it's used to record all plugin 
>> relative functions. I will add it to export interface of the proposal.
> 
> After I've written a plugin, how do I integrate it into the GKrellM
> infrastructure.  Do plugins have to be installed in a particular
> location, for example, for them to be loaded by the GKrellM daemon?
> 
> If so, this plugin directory (or whatever interface is used) should be
> highlighted in the ARC materials and the manpage.
Yes, generally the plugin is stroed under /usr/lib/gkrellm2/plugins, and 
I have added it to the one-pager, and it have been in the manpage.
> 
>>>>   4.11. Security Impact:
>>>>
>>>>         There is no additional security impact for Solaris.
>>> How can something which uses OpenSSL, has a plugin framework, and allows
>>> remote observation of a network's health have no security impact?
>> I think there is some general security problem when an application 
>> connect to network, it may exist all applications using OpenSSL/plugin.
>> I will add some words to identify that this application is using 
>> OpenSSL, and support plugin to transfer system status information.
> 
> Is it possible for a person to write a plugin that does something
> malicious?  What protects the system from malicious plugins?  Can
> only the sysadmin install new plugins, for example?
Yes, only sysadmin can install the plugins.
> 
> What protects the traffic between the remote and local machine from
> malicious snooping?  I'd guess OpenSSL is being used for this.  I'm
> just saying that the answer should be more fleshed out.  "None" isn't
> a good answer in this case.
OK, I have added some words on it into the one-pager.
> 

--Boundary_(ID_Y/qbF6JOX9uL5urMM6n6Ag)
Content-type: text/plain; name=one-pager-gkrellm.txt
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=one-pager-gkrellm.txt

Template Version: @(#)onepager.txt 1.29 04/11/15 SMI

1. Introduction

  1.1. Project/Component Working Name:

       GKrellM

  1.2. Name of Document Author/Supplier:

       Henry Zhang     (hua.zhang@sun.com)

  1.3. Date of This Document:

       30/07/08

  1.4. Name of Major Document Customer(s)/Consumer(s):

    1.4.1. The PAC or CPT you expect to review your project:

           Solaris PAC

    1.4.2. The ARC(s) you expect to review your project:

           LSARC

    1.4.3. The Director/VP who is "Sponsoring" this project:

           Robert.Odea@Sun.Com

    1.4.4. The name of your business unit:

           JDS Desktop Engineering, OPG

  1.5. Email Aliases:
       1.5.1. Responsible Manager:     leo.binchy@Sun.COM
       1.5.2. Responsible Engineer:    hua.zhang@Sun.COM
       1.5.3. Marketing Manager:       jeff.mcmeekin@sun.com
       1.5.4. Interest List:           gkrellm@sun.com

2. Project Summary

  2.1. Project Description:
        
       GKrellM, GNU (or Gtk) Krell Monitors (or Meters), is a single process 
       stack of system monitors which supports applying themes to match its 
       appearance to your window manager, Gtk, or any other theme. The current
       version is 2.3.1.

2.2. Risks and Assumptions:
    
    1. Temperature, fan, and voltage sensor monitors not support since missing
       libsensors.

    2. APM laptop battery meter not support since no APM.
    
    3. This application will depend on libgtop, which isn't engineered to fully
       or best support Solaris interfaces for getting system information because
       it was written from a more Linux perspective on system resources, and some
       system information can't get since not fully support from kernel, e.g. 
       some sensor monitor interfaces.

3. Business Summary

  3.1. Problem Area:

       GKrell is a computer program based on the GTK+ toolkit that creates a 
       single process stack of system monitors. It can be used to monitor the 
       status of CPUs, main memory, hard disks, network interfaces, local and 
       remote mailboxes, and many other things. Plugin is supported.

  3.2. Market/Requester:

       JDS Desktop group

  3.3. Business Justification:

       For many users, it's nice to be able to see, real-time, what is happening
       on their system. There are ways to display memory usage, cpu usage, network
       traffic, available and used disk space, and a whole lot of other similar 
       system statistics. This makes it easier to troubleshoot and notice problems
       as they come up. To be display these monitors, you will need gkrellm.

       It's a very useful monitoring tool, can replace a lots of the dock 
       applets, what's even better is that gkrellm supports a plugin interface,
       allowing vast expandability, it's also infinitely configurable and 
       themeable.

       Additionally Gkrellm is very easy on the CPU and packs a lot of information
       into a little bit of space. 

  3.4. Competitive Analysis:

       Windows XP has SysMetrix, Windows Vista has this type of side bar, 
       and GKrellM can run in Linux and other Unix-like operating systems.

  3.5. Opportunity Window/Exposure:

       It is expected that this project will be integrated into Nevada B100

       Note: this tool has GPL V3 license, it will not integrated into 
       Nevada until the license issue is solved.

  3.6. How will you know when you are done?:

       When it is ported to Nevada and runs correctly.  

       The project will be complete when there are no stoppers, P1 or P2 bugs.

4. Technical Description:

  4.1. Details:
       
       GKrellM is a GTK-based stacked monitor program that charts SMP CPUs, 
       disks, load, active net interfaces, and internet connections. There are
       also builtin monitors for memory and swap, file systems with mount/umount
       feature, mailbox checking including POP3 and IMAP, clock/calendar, laptop
       battery, sensors (temperatures, voltages, and fans), and uptime. It has 
       LEDs for the net monitors and an on/off button and online timer for PPP. 
       Multiple monitors managed by a single process to reduce system load.
       There is a GUI popup for configuration, plugin extensions can be installed, 
       and many themes are available. It also features a client/server monitoring 
       capability.

       If you want to configure GkrellM, you can right-click on the monitor and 
       select Configuration from the drop-down menu, or press the F1 key at  
       anytime while GKrellM has the focus. The configuration menu lets you 
       modify general options, built-in monitors, plug-ins, and themes.
       
       GKrellM consists of the gkrellm client and the gkrellmd server. Gkrellm can 
       run in client mode and collect data from gkrellmd server running on a remote
       machine. In this way, the user can remotely monitor different characteristics  
       of all the machines on their LAN, such as hits and load on the web server,  
       disk usage on the mail server, and port traffic on the NAT. 

       The gkrellm client gets data from gkrellmd through SSH. By default gkrellmd
       will not run by default, so the user need to start gkrellmd manually, 
       and optionally add options to configure gkrellmd.  For example,
       you can configure which port gkrellmd will use and which IP addresses or
       hostnames are allowed to connect to gkrellmd. gkrellm client will also be 
       configured to use some port, this port is used to create the SSH connection
       with the gkrellmd server given port. Then you can start gkrellm on another
       system and get the remote data from gkrellmd.
        
       Both gkrellm and the gkrellmd server are plugin capable so special interest 
       monitors can be coded. And in order to make install plugin, you should be root,
       and ensure the plugin will not add additional security issue.


  4.2. Bug/RFE Number(s):

        RFE 6732524

  4.3. In Scope:

       The system information we can get from Solaris 

  4.4. Out of Scope:

       The system information Solaris can't support, e.g. temperature.
       All plugins that are installed by users themselves.

   4.5. Interfaces:
    
      Imported Interfaces
      Interface               Stability    Comments
      -------------------     -----------  -----------------------------------

       /usr/lib/libkstat.so.1   Committed         standard library
       SUNWgettext              Uncommitted
       libgtop                  Volatile          LSARC/2006/347/
       libOpenSSL               Contract Private  PSARC/2006/019/ 
       GNOME Committed Platform Libraries Committed LSARC/2007/520 GTK+ library
                                                        GNOME 2.20 

      Exported Interfaces        Stability      Comments
      -------------------------  -------------  ---------------------------------

       /usr/bin/gkrellm          Volatile       
       SUNWgkrellm               Uncommitted    Package name
       SUNWgkrellm-devel         Uncommitted    Package name
       /usr/include/gkrellm2/gkrellm.h    Project Private
       /usr/lib/gkrellm2/plugins   Project Private      Used to store plugins

  4.6. Doc Impact:

       Man page will need to be added

  4.7. Admin/Config Impact:

       There are no changes to the system administration and configuration. 

  4.8. HA Impact:

       N/A

  4.9. I18N/L10N Impact:

       The JDS team and the G11N are working together to evaluate and provide
       I18N/L10N support.
       

  4.10. Packaging & Delivery:

        The new packages are:

              -  SUNWgkrellm
              -  SUNWgkrellm-devel 

  4.11. Security Impact:

        This application uses OpenSSL, and support plugins, it may cause some
        security concern, but generally all data transfered through the connection
        is the system usage status information, and not very confidential, 
        addtionally in order to make the network connection more secure,
        this application is using SSH and some configuration on IP/port to use,
        see 4.1 for details. 

  4.12. Dependencies:

        SUNWgettext.spec
        Gtk+ 2.0 >= 2.0 
        gdk 2.0
        glib 2.0 >= 2.0
        libgtop
        libssl

5. Reference Documents:

   GKrellM main project page:   
        http://gkrellm.net

   GKrellM Wiki:
        http://en.wikipedia.org/wiki/GKrellM

   GKrellM themes site:
        http://www.muhri.net/gkrellm/


6. Resources and Schedule:

  6.1. Projected Availability:
       
       Expect to integrated into Nevada in build 100 in Q3 2008

  6.2. Cost of Effort:

       Development     1.0 Engineers - 1 Months
       Testing         0.5 Engineers - 1 Week
       RE              0.5 Engineers - 1 Week

  6.3. Cost of Capital Resources:

       N/A

  6.4. Product Approval Committee requested information:

       6.4.1. Consolidation or Component Name:

              JDS / OpenSolaris
 
       6.4.3. Type of CPT Review and Approval expected:

              Standard

       6.4.4. Project Boundary Conditions:

              None

       6.4.5. Is this a necessary project for OEM agreements:

              No

       6.4.6. Notes:

              N/A

       6.4.7. Target RTI Date/Release:

              Nevada B100 - Sep. 2008

       6.4.8. Target Code Design Review Date:

              Sep. 2008

       6.4.9. Update approval addition:

              New project, no Solaris PAC approval yet

  6.5. ARC review type:

       FastTrack

7. Prototype Availability:

  7.1. Prototype Availability:

       Sep. 2008   

  7.2. Prototype Cost:

       1 engineer
       1 QA
       1 RE

--Boundary_(ID_Y/qbF6JOX9uL5urMM6n6Ag)--

From Hua.Zhang@sun.com Thu Aug 14 01:54:36 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7E8sZYQ008316
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 14 Aug 2008 01:54:35 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m7E8sXOY010541
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Thu, 14 Aug 2008 09:54:34 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5L0080122YF300@brm-avmta-1.central.sun.com> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@sun.com); Thu, 14 Aug 2008 02:54:34 -0600 (MDT)
Received: from sineb-mail-2.sun.com ([192.18.19.7])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5L007X222WHA00@brm-avmta-1.central.sun.com> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Thu,
 14 Aug 2008 02:54:33 -0600 (MDT)
Received: from fe-apac-06.sun.com
 (fe-apac-06.sun.com [192.18.19.177] (may be forged))
	by sineb-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7E8sW5h007153	for
 <lsarc-ext@sun.com>; Thu, 14 Aug 2008 08:54:32 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0K5L0040121ANS00@mail-apac.sun.com> (original mail from Hua.Zhang@Sun.COM)
 for lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Thu,
 14 Aug 2008 16:54:31 +0800 (SGT)
Received: from [129.158.217.156] by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0K5L00BVH22URGO2@mail-apac.sun.com>; Thu,
 14 Aug 2008 16:54:31 +0800 (SGT)
Date: Thu, 14 Aug 2008 16:58:37 +0800
From: Henry Zhang <Hua.Zhang@sun.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
	08/19/2008]
In-reply-to: <48A2D520.1010902@Sun.COM>
Sender: Hua.Zhang@sun.com
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Brian Cameron <Brian.Cameron@sun.com>, lsarc-ext@sun.com,
        Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>
Message-id: <48A3F3BD.6000503@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 8BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com> <48A2D520.1010902@Sun.COM>
User-Agent: Thunderbird 2.0.0.6 (X11/20071119)
Status: RO
Content-Length: 498

Darren,

I looked into the source code, the application is using SSL_CTX_new to 
initial a certificate, and it is saved by a pointer member of a 
structure during the application run, so it can be accessed through this 
pointer...


Thanks,
Henry

Darren J Moffat 写道:
> If it is using OpenSSL for SSL/TLS then there needs to be certificates 
> in use somewhere, so where are they stored for the "server side" and 
> where are the trust anchors for the "client side".
> 
> -- 
> Darren J Moffat

From Darren.Moffat@sun.com Thu Aug 14 03:32:43 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7EAWhpe010342
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 14 Aug 2008 03:32:43 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m7EAWXFb008481
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Thu, 14 Aug 2008 18:32:42 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5L00B056MG7100@nwk-avmta-2.sfbay.sun.com> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@sun.com); Thu, 14 Aug 2008 03:32:40 -0700 (PDT)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5L007XV6MEPN40@nwk-avmta-2.sfbay.sun.com> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Thu,
 14 Aug 2008 03:32:39 -0700 (PDT)
Received: from fe-emea-09.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m7EAWcWm020339	for
 <lsarc-ext@sun.com>; Thu, 14 Aug 2008 10:32:38 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K5L00C016IBLU00@fe-emea-09.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Thu,
 14 Aug 2008 11:32:38 +0100 (BST)
Received: from [129.156.173.21] by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K5L006PM6LRTR10@fe-emea-09.sun.com>; Thu,
 14 Aug 2008 11:32:17 +0100 (BST)
Date: Thu, 14 Aug 2008 11:32:15 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
	08/19/2008]
In-reply-to: <48A3EDA4.8090206@sun.com>
Sender: Darren.Moffat@sun.com
To: Henry Zhang <Hua.Zhang@sun.com>
Cc: Brian.Cameron@sun.com, lsarc-ext@sun.com,
        Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>
Message-id: <48A409AF.7050300@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com> <48A32E97.3090308@Sun.COM>
 <48A3EDA4.8090206@sun.com>
User-Agent: Thunderbird 2.0.0.14 (X11/20080630)
Status: RO
Content-Length: 224

I still don't see how OpenSSL is being used.  The proposal mentions SSH 
for connecting to the remote gkrellmd but SSH and SSL are totally 
different protocols.

The battery issue is still not addressed.

--
Darren J Moffat

From andras.barna@gmail.com Thu Aug 14 04:23:42 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7EBNf5t011304
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 14 Aug 2008 04:23:41 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m7EBNbum010706
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Thu, 14 Aug 2008 12:23:40 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5L00J098ZFMH00@brm-avmta-1.central.sun.com> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@sun.com); Thu, 14 Aug 2008 05:23:39 -0600 (MDT)
Received: from brmea-mail-3.sun.com ([192.18.98.34])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5L007O08ZFHH80@brm-avmta-1.central.sun.com> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Thu,
 14 Aug 2008 05:23:39 -0600 (MDT)
Received: from relay23.sun.com
 (relay23.sun.com [192.12.251.54] (may be forged))	by brmea-mail-3.sun.com
 (8.13.6+Sun/8.12.9) with ESMTP id m7EBM5Hv029642	for <lsarc-ext@sun.com>; Thu,
 14 Aug 2008 11:23:39 +0000 (GMT)
Received: from mms25es.mms.us.syntegra.com ([150.143.232.90] [150.143.232.90])
 by relay23i.sun.com with ESMTP id BT-MMP-1735351 for lsarc-ext@sun.com; Thu,
 14 Aug 2008 11:23:38 +0000 (Z)
Received: from relay22.sun.com (relay22.sun.com [192.12.251.34])
 by mms25es.mms.us.syntegra.com with ESMTP id BT-MMP-14457769 for
 lsarc-ext@sun.com; Thu, 14 Aug 2008 11:23:38 +0000 (Z)
Received: from yx-out-1718.google.com ([74.125.44.157] [74.125.44.157])
 by relay22i.sun.com with ESMTP id BT-MMP-2797739 for lsarc-ext@sun.com; Thu,
 14 Aug 2008 11:23:38 +0000 (Z)
Received: by yx-out-1718.google.com with SMTP id 3so306713yxi.68 for
 <lsarc-ext@sun.com>; Thu, 14 Aug 2008 04:22:47 -0700 (PDT)
Received: by 10.151.48.15 with SMTP id a15mr1611313ybk.209.1218712967001; Thu,
 14 Aug 2008 04:22:47 -0700 (PDT)
Received: by 10.151.11.8 with HTTP; Thu, 14 Aug 2008 04:22:46 -0700 (PDT)
Date: Thu, 14 Aug 2008 14:22:46 +0300
From: Andras Barna <andras.barna@gmail.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
 08/19/2008]
In-reply-to: <48A3EDA4.8090206@sun.com>
To: Henry Zhang <Hua.Zhang@sun.com>
Cc: Brian.Cameron@sun.com, lsarc-ext@sun.com,
        Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>
Message-id: <56dc2e760808140422q6711819clb1fa99b57e777211@mail.gmail.com>
MIME-version: 1.0
Content-type: text/plain; charset=UTF-8
Content-disposition: inline
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;        d=gmail.com;
 s=gamma; h=domainkey-signature:received:received:message-id:date:from:to
 :subject:cc:in-reply-to:mime-version:content-type
 :content-transfer-encoding:content-disposition:references;
 bh=fqhCR8DkkU102m/NQWNEMzQzUFteMkdcB3MFfn3+68s=;
 b=M9YtJusIHnftdu6zURK/arz3mvZaqi3FU9VinIc27d4qqhFQOuCKeY5hJctlNpMFu3
 rOdv2wDTiLSopi0t07PE2stXsm+TC5qJh+q29YLu8o3ByqwrA6ASkpDmiyG1RY08Swo/
 rV2tJ5YssGlW8R1bgHCISqkpxmtRIJA9wZrYg=
DomainKey-Signature: a=rsa-sha1; c=nofws;        d=gmail.com; s=gamma;
 h=message-id:date:from:to:subject:cc:in-reply-to:mime-version
 :content-type:content-transfer-encoding:content-disposition :references;
 b=QbHbHQM0A41uePjb2Td69OgaZuRLD6dlxyWLB80Y5iR17XzGWbpq1N3K6OToW/wU2G
 77g8Y8XgOcw+GvwTS1auU1x5ZbozcUHb62hkeVRhedLXP9H8ArjaJRuwr/i2pZ6i8Fha
 p4AMgI1G0GeGM8qrEB7q8YZ3jccOUpb4KkMpE=
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-Antispam: No, score=1.0/5.0, scanned in 0.153sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com> <48A32E97.3090308@Sun.COM>
 <48A3EDA4.8090206@sun.com>
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from base64 to 8bit by sac.sfbay.sun.com id m7EBNf5t011304
Status: RO
Content-Length: 12662

On Thu, Aug 14, 2008 at 11:32 AM, Henry Zhang <Hua.Zhang@sun.com> wrote:
> Brian, etc. all:
>
> See my answer in-line below.
>
> Please see the updated proposal according to all of the comments.
> See the attchemnt.
>
> Thanks,
> Henry
>
> Brian Cameron 写道:
>>
>> Henry:
>>
>>>> Sections 3.1, 3.4, 4.1, and 4.4 all discuss that Gkrellm supports
>>>> plugins, but there is no information about plugins in the exported
>>>> interface table.  How can it support a plugin framework without
>>>> exporting any related interfaces?
>>>
>>> Sure, it export /usr/include/gkrellm2/gkrellm.h, in which the structure
>>> GkrellmMonitor is listed, it's used to record all plugin relative functions.
>>> I will add it to export interface of the proposal.
>>
>> After I've written a plugin, how do I integrate it into the GKrellM
>> infrastructure.  Do plugins have to be installed in a particular
>> location, for example, for them to be loaded by the GKrellM daemon?
>>
>> If so, this plugin directory (or whatever interface is used) should be
>> highlighted in the ARC materials and the manpage.
>
> Yes, generally the plugin is stroed under /usr/lib/gkrellm2/plugins, and I
> have added it to the one-pager, and it have been in the manpage.
>>
>>>>>  4.11. Security Impact:
>>>>>
>>>>>        There is no additional security impact for Solaris.
>>>>
>>>> How can something which uses OpenSSL, has a plugin framework, and allows
>>>> remote observation of a network's health have no security impact?
>>>
>>> I think there is some general security problem when an application
>>> connect to network, it may exist all applications using OpenSSL/plugin.
>>> I will add some words to identify that this application is using OpenSSL,
>>> and support plugin to transfer system status information.
>>
>> Is it possible for a person to write a plugin that does something
>> malicious?  What protects the system from malicious plugins?  Can
>> only the sysadmin install new plugins, for example?
>
> Yes, only sysadmin can install the plugins.

note: plugins can be installed in ~/.gkrellm2/plugins too

>>
>> What protects the traffic between the remote and local machine from
>> malicious snooping?  I'd guess OpenSSL is being used for this.  I'm
>> just saying that the answer should be more fleshed out.  "None" isn't
>> a good answer in this case.
>
> OK, I have added some words on it into the one-pager.
>>
>
> Template Version: @(#)onepager.txt 1.29 04/11/15 SMI
>
> 1. Introduction
>
>  1.1. Project/Component Working Name:
>
>       GKrellM
>
>  1.2. Name of Document Author/Supplier:
>
>       Henry Zhang     (hua.zhang@sun.com)
>
>  1.3. Date of This Document:
>
>       30/07/08
>
>  1.4. Name of Major Document Customer(s)/Consumer(s):
>
>    1.4.1. The PAC or CPT you expect to review your project:
>
>           Solaris PAC
>
>    1.4.2. The ARC(s) you expect to review your project:
>
>           LSARC
>
>    1.4.3. The Director/VP who is "Sponsoring" this project:
>
>           Robert.Odea@Sun.Com
>
>    1.4.4. The name of your business unit:
>
>           JDS Desktop Engineering, OPG
>
>  1.5. Email Aliases:
>       1.5.1. Responsible Manager:     leo.binchy@Sun.COM
>       1.5.2. Responsible Engineer:    hua.zhang@Sun.COM
>       1.5.3. Marketing Manager:       jeff.mcmeekin@sun.com
>       1.5.4. Interest List:           gkrellm@sun.com
>
> 2. Project Summary
>
>  2.1. Project Description:
>
>       GKrellM, GNU (or Gtk) Krell Monitors (or Meters), is a single process
>       stack of system monitors which supports applying themes to match its
>       appearance to your window manager, Gtk, or any other theme. The
> current
>       version is 2.3.1.
>
> 2.2. Risks and Assumptions:
>
>    1. Temperature, fan, and voltage sensor monitors not support since
> missing
>       libsensors.
>
>    2. APM laptop battery meter not support since no APM.
>
>    3. This application will depend on libgtop, which isn't engineered to
> fully
>       or best support Solaris interfaces for getting system information
> because
>       it was written from a more Linux perspective on system resources, and
> some
>       system information can't get since not fully support from kernel, e.g.
>       some sensor monitor interfaces.
>
> 3. Business Summary
>
>  3.1. Problem Area:
>
>       GKrell is a computer program based on the GTK+ toolkit that creates a
>       single process stack of system monitors. It can be used to monitor the
>       status of CPUs, main memory, hard disks, network interfaces, local and
>       remote mailboxes, and many other things. Plugin is supported.
>
>  3.2. Market/Requester:
>
>       JDS Desktop group
>
>  3.3. Business Justification:
>
>       For many users, it's nice to be able to see, real-time, what is
> happening
>       on their system. There are ways to display memory usage, cpu usage,
> network
>       traffic, available and used disk space, and a whole lot of other
> similar
>       system statistics. This makes it easier to troubleshoot and notice
> problems
>       as they come up. To be display these monitors, you will need gkrellm.
>
>       It's a very useful monitoring tool, can replace a lots of the dock
>       applets, what's even better is that gkrellm supports a plugin
> interface,
>       allowing vast expandability, it's also infinitely configurable and
>       themeable.
>
>       Additionally Gkrellm is very easy on the CPU and packs a lot of
> information
>       into a little bit of space.
>
>  3.4. Competitive Analysis:
>
>       Windows XP has SysMetrix, Windows Vista has this type of side bar,
>       and GKrellM can run in Linux and other Unix-like operating systems.
>
>  3.5. Opportunity Window/Exposure:
>
>       It is expected that this project will be integrated into Nevada B100
>
>       Note: this tool has GPL V3 license, it will not integrated into
>       Nevada until the license issue is solved.
>
>  3.6. How will you know when you are done?:
>
>       When it is ported to Nevada and runs correctly.
>
>       The project will be complete when there are no stoppers, P1 or P2
> bugs.
>
> 4. Technical Description:
>
>  4.1. Details:
>
>       GKrellM is a GTK-based stacked monitor program that charts SMP CPUs,
>       disks, load, active net interfaces, and internet connections. There
> are
>       also builtin monitors for memory and swap, file systems with
> mount/umount
>       feature, mailbox checking including POP3 and IMAP, clock/calendar,
> laptop
>       battery, sensors (temperatures, voltages, and fans), and uptime. It
> has
>       LEDs for the net monitors and an on/off button and online timer for
> PPP.
>       Multiple monitors managed by a single process to reduce system load.
>       There is a GUI popup for configuration, plugin extensions can be
> installed,
>       and many themes are available. It also features a client/server
> monitoring
>       capability.
>
>       If you want to configure GkrellM, you can right-click on the monitor
> and
>       select Configuration from the drop-down menu, or press the F1 key at
>       anytime while GKrellM has the focus. The configuration menu lets you
>       modify general options, built-in monitors, plug-ins, and themes.
>
>       GKrellM consists of the gkrellm client and the gkrellmd server.
> Gkrellm can
>       run in client mode and collect data from gkrellmd server running on a
> remote
>       machine. In this way, the user can remotely monitor different
> characteristics
>       of all the machines on their LAN, such as hits and load on the web
> server,
>       disk usage on the mail server, and port traffic on the NAT.
>
>       The gkrellm client gets data from gkrellmd through SSH. By default
> gkrellmd
>       will not run by default, so the user need to start gkrellmd manually,
>       and optionally add options to configure gkrellmd.  For example,
>       you can configure which port gkrellmd will use and which IP addresses
> or
>       hostnames are allowed to connect to gkrellmd. gkrellm client will also
> be
>       configured to use some port, this port is used to create the SSH
> connection
>       with the gkrellmd server given port. Then you can start gkrellm on
> another
>       system and get the remote data from gkrellmd.
>
>       Both gkrellm and the gkrellmd server are plugin capable so special
> interest
>       monitors can be coded. And in order to make install plugin, you should
> be root,
>       and ensure the plugin will not add additional security issue.
>
>
>  4.2. Bug/RFE Number(s):
>
>        RFE 6732524
>
>  4.3. In Scope:
>
>       The system information we can get from Solaris
>
>  4.4. Out of Scope:
>
>       The system information Solaris can't support, e.g. temperature.
>       All plugins that are installed by users themselves.
>
>   4.5. Interfaces:
>
>      Imported Interfaces
>      Interface               Stability    Comments
>      -------------------     -----------
>  -----------------------------------
>
>       /usr/lib/libkstat.so.1   Committed         standard library
>       SUNWgettext              Uncommitted
>       libgtop                  Volatile          LSARC/2006/347/
>       libOpenSSL               Contract Private  PSARC/2006/019/
>       GNOME Committed Platform Libraries Committed LSARC/2007/520 GTK+
> library
>                                                        GNOME 2.20
>
>      Exported Interfaces        Stability      Comments
>      -------------------------  -------------
>  ---------------------------------
>
>       /usr/bin/gkrellm          Volatile
>       SUNWgkrellm               Uncommitted    Package name
>       SUNWgkrellm-devel         Uncommitted    Package name
>       /usr/include/gkrellm2/gkrellm.h    Project Private
>       /usr/lib/gkrellm2/plugins   Project Private      Used to store plugins
>
>  4.6. Doc Impact:
>
>       Man page will need to be added
>
>  4.7. Admin/Config Impact:
>
>       There are no changes to the system administration and configuration.
>
>  4.8. HA Impact:
>
>       N/A
>
>  4.9. I18N/L10N Impact:
>
>       The JDS team and the G11N are working together to evaluate and provide
>       I18N/L10N support.
>
>
>  4.10. Packaging & Delivery:
>
>        The new packages are:
>
>              -  SUNWgkrellm
>              -  SUNWgkrellm-devel
>
>  4.11. Security Impact:
>
>        This application uses OpenSSL, and support plugins, it may cause some
>        security concern, but generally all data transfered through the
> connection
>        is the system usage status information, and not very confidential,
>        addtionally in order to make the network connection more secure,
>        this application is using SSH and some configuration on IP/port to
> use,
>        see 4.1 for details.
>
>  4.12. Dependencies:
>
>        SUNWgettext.spec
>        Gtk+ 2.0 >= 2.0
>        gdk 2.0
>        glib 2.0 >= 2.0
>        libgtop
>        libssl
>
> 5. Reference Documents:
>
>   GKrellM main project page:
>        http://gkrellm.net
>
>   GKrellM Wiki:
>        http://en.wikipedia.org/wiki/GKrellM
>
>   GKrellM themes site:
>        http://www.muhri.net/gkrellm/
>
>
> 6. Resources and Schedule:
>
>  6.1. Projected Availability:
>
>       Expect to integrated into Nevada in build 100 in Q3 2008
>
>  6.2. Cost of Effort:
>
>       Development     1.0 Engineers - 1 Months
>       Testing         0.5 Engineers - 1 Week
>       RE              0.5 Engineers - 1 Week
>
>  6.3. Cost of Capital Resources:
>
>       N/A
>
>  6.4. Product Approval Committee requested information:
>
>       6.4.1. Consolidation or Component Name:
>
>              JDS / OpenSolaris
>
>       6.4.3. Type of CPT Review and Approval expected:
>
>              Standard
>
>       6.4.4. Project Boundary Conditions:
>
>              None
>
>       6.4.5. Is this a necessary project for OEM agreements:
>
>              No
>
>       6.4.6. Notes:
>
>              N/A
>
>       6.4.7. Target RTI Date/Release:
>
>              Nevada B100 - Sep. 2008
>
>       6.4.8. Target Code Design Review Date:
>
>              Sep. 2008
>
>       6.4.9. Update approval addition:
>
>              New project, no Solaris PAC approval yet
>
>  6.5. ARC review type:
>
>       FastTrack
>
> 7. Prototype Availability:
>
>  7.1. Prototype Availability:
>
>       Sep. 2008
>
>  7.2. Prototype Cost:
>
>       1 engineer
>       1 QA
>       1 RE
>
> _______________________________________________
> opensolaris-arc mailing list
> opensolaris-arc@opensolaris.org
>



-- 
Andy
http://blog.sartek.net


From David.Bustos@Sun.COM Thu Aug 14 09:45:29 2008
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7EGjTFt022309
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 14 Aug 2008 09:45:29 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m7EGjSFF007545
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Thu, 14 Aug 2008 09:45:29 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5L0030VNVST300@nwk-avmta-1.sfbay.Sun.COM> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@sun.com); Thu, 14 Aug 2008 09:45:28 -0700 (PDT)
Received: from dm-sfbay-02.sfbay.sun.com ([129.146.11.31])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5L00G6BNVRR6A0@nwk-avmta-1.sfbay.Sun.COM> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Thu,
 14 Aug 2008 09:45:27 -0700 (PDT)
Received: from ciabatta.sfbay.sun.com
 (ciabatta.SFBay.Sun.COM [129.146.228.101])	by dm-sfbay-02.sfbay.sun.com
 (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m7EGjOdd054208; Thu,
 14 Aug 2008 09:45:24 -0700 (PDT)
Received: from ciabatta.sfbay.sun.com (localhost [127.0.0.1])
	by ciabatta.sfbay.sun.com (8.14.3+Sun/8.14.2) with ESMTP id m7EGdg3q012495;
 Thu, 14 Aug 2008 09:39:42 -0700 (PDT)
Received: (from bustos@localhost)	by ciabatta.sfbay.sun.com
 (8.14.3+Sun/8.14.3/Submit) id m7EGdgFt012494; Thu,
 14 Aug 2008 09:39:42 -0700 (PDT)
Date: Thu, 14 Aug 2008 09:39:42 -0700
From: David Bustos <David.Bustos@Sun.COM>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
 08/19/2008]
In-reply-to: <48A180A0.4030503@sun.com>
To: Henry Zhang <Hua.Zhang@Sun.COM>
Cc: Darren J Moffat <Darren.Moffat@Sun.COM>,
        Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>, lsarc-ext@Sun.COM
Message-id: <20080814163941.GA12488@ciabatta.SFBay.Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A15B89.7040302@Sun.COM> <48A17BC6.7010000@sun.com>
 <48A17E74.5030703@Sun.COM> <48A180A0.4030503@sun.com>
User-Agent: Mutt/1.4.2.1i
Status: RO
Content-Length: 426

Quoth Henry Zhang on Tue, Aug 12, 2008 at 08:22:56PM +0800:
> As I know, we have ACPI in 2008.5, but not APM, need to dig into the 
> codes to see if all is OK to call it to implement the battery support, 
> if so, will add.. Thanks...

If it's any help, I wrote a patch for gkrellm 2.2.7 to retrieve battery
information from acpidrv.  See
http://www.opensolaris.org/jive/click.jspa?searchID=1145207&messageID=15172 .


David

From Brian.Cameron@Sun.COM Thu Aug 14 10:02:22 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7EH2Mie024046
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 14 Aug 2008 10:02:22 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m7EH2M2K007036
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Thu, 14 Aug 2008 10:02:22 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5L0045JONY8U00@nwk-avmta-2.sfbay.sun.com> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@sun.com); Thu, 14 Aug 2008 10:02:22 -0700 (PDT)
Received: from brmea-mail-2.sun.com ([192.18.98.43])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5L00IR3ONWVKB0@nwk-avmta-2.sfbay.sun.com> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Thu,
 14 Aug 2008 10:02:20 -0700 (PDT)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7EH2JvB007161	for
 <lsarc-ext@sun.com>; Thu, 14 Aug 2008 17:02:19 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K5L00801O2SD200@mail-amer.sun.com>
 (original mail from Brian.Cameron@Sun.COM)
 for lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Thu,
 14 Aug 2008 11:02:19 -0600 (MDT)
Received: from [192.168.1.108] ([67.167.213.227])
 by mail-amer.sun.com (Sun Java System Messaging Server 6.2-8.04 (built Feb 28
 2007)) with ESMTPSA id <0K5L0012KONKAT20@mail-amer.sun.com>; Thu,
 14 Aug 2008 11:02:12 -0600 (MDT)
Date: Thu, 14 Aug 2008 12:02:13 -0500
From: Brian Cameron <Brian.Cameron@Sun.COM>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
 08/19/2008]
In-reply-to: <56dc2e760808140422q6711819clb1fa99b57e777211@mail.gmail.com>
Sender: Brian.Cameron@Sun.COM
To: Andras Barna <andras.barna@gmail.com>
Cc: Henry Zhang <Hua.Zhang@Sun.COM>, lsarc-ext@Sun.COM,
        Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>
Message-id: <48A46515.7060202@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com> <48A32E97.3090308@Sun.COM>
 <48A3EDA4.8090206@sun.com>
 <56dc2e760808140422q6711819clb1fa99b57e777211@mail.gmail.com>
User-Agent: Thunderbird 2.0.0.16 (X11/20080731)
Status: RO
Content-Length: 445


Andras/Henry:

> note: plugins can be installed in ~/.gkrellm2/plugins too

I thought Henry said that only sysadmins could install plugins.

If an end-user can install and run plugins, is it possible to exploit
the framework in any way?  If someone tricks a user into installing a
malicious plugin, what bad things can happen, if any.

Does the sysadmin have control over whether plugins in user $HOME
directories get recognized or not?

Brian

From andras.barna@gmail.com Thu Aug 14 10:54:20 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7EHsJFs025647
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 14 Aug 2008 10:54:20 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m7EHsEuT009866
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Fri, 15 Aug 2008 01:54:19 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5L00609R2IAX00@nwk-avmta-2.sfbay.sun.com> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@sun.com); Thu, 14 Aug 2008 10:54:18 -0700 (PDT)
Received: from brmea-mail-3.sun.com ([192.18.98.34])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5L0069KR2H6100@nwk-avmta-2.sfbay.sun.com> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Thu,
 14 Aug 2008 10:54:17 -0700 (PDT)
Received: from relay17i.sun.com
 (ip127.net129179-4.block1.us.syntegra.com [129.179.4.127])
	by brmea-mail-3.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7EHpXgU002473	for
 <lsarc-ext@sun.com>; Thu, 14 Aug 2008 17:54:17 +0000 (GMT)
Received: from mmp13es.mmp.us.syntegra.com ([160.41.208.13] [160.41.208.13])
 by relay17i.sun.com with ESMTP id BT-MMP-1189071 for lsarc-ext@sun.com; Thu,
 14 Aug 2008 17:54:16 +0000 (Z)
Received: from relay16i.sun.com (relay16i.sun.com [129.179.4.126])
 by mmp13es.mmp.us.syntegra.com with ESMTP id BT-MMP-278388 for
 lsarc-ext@sun.com; Thu, 14 Aug 2008 17:54:16 +0000 (Z)
Received: from mail-gx0-f17.google.com ([209.85.217.17] [209.85.217.17])
 by relay1i.sun.com with ESMTP id BT-MMP-11549765 for lsarc-ext@sun.com; Thu,
 14 Aug 2008 17:54:16 +0000 (Z)
Received: by gxk10 with SMTP id 10so2527041gxk.8 for <lsarc-ext@sun.com>; Thu,
 14 Aug 2008 10:54:13 -0700 (PDT)
Received: by 10.150.140.16 with SMTP id n16mr2197636ybd.142.1218736453552; Thu,
 14 Aug 2008 10:54:13 -0700 (PDT)
Received: by 10.151.11.8 with HTTP; Thu, 14 Aug 2008 10:54:13 -0700 (PDT)
Date: Thu, 14 Aug 2008 20:54:13 +0300
From: Andras Barna <andras.barna@gmail.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
 08/19/2008]
In-reply-to: <48A46515.7060202@sun.com>
To: Brian Cameron <Brian.Cameron@sun.com>
Cc: Henry Zhang <Hua.Zhang@sun.com>, lsarc-ext@sun.com,
        Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>
Message-id: <56dc2e760808141054x65c40b6o69b5638615d0ffeb@mail.gmail.com>
MIME-version: 1.0
Content-type: text/plain; charset=UTF-8
Content-transfer-encoding: 7BIT
Content-disposition: inline
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;        d=gmail.com;
 s=gamma; h=domainkey-signature:received:received:message-id:date:from:to
 :subject:cc:in-reply-to:mime-version:content-type
 :content-transfer-encoding:content-disposition:references;
 bh=fRYtUaFBWlJ9MVthqHy75PNepRAItuAxWco/cg9dYhw=;
 b=k1COuEc82+p21E2imgJEOzJPNvFavl+iEIcSRTna17JdY5aOjk2od2AznWwSHHo1JB
 7Lq8VLfk1s4nccvdr/gQt6W9SjY36rhQ2qWsYdjWWmt1BPY6kO76GZUJfzkNxUBBOJ0L
 tEXrpAQlDJd6KyATtJ9L4mUGTQ8KVKpRBaRNI=
DomainKey-Signature: a=rsa-sha1; c=nofws;        d=gmail.com; s=gamma;
 h=message-id:date:from:to:subject:cc:in-reply-to:mime-version
 :content-type:content-transfer-encoding:content-disposition :references;
 b=ZSeDBaT8wHXSePSijuZR0KWuSRPEkUwH41flhXlFK3SAzbKI0Z7N2U33pMlkm+zkdJ
 EP766uan+7VLnuyF2NnxtPozQB4pglOXyujLlprul5SLTUCh+6pfX+qyqe42i4l8nIyp
 Rhu4GIhmG7yH1FHRZHooiymisE5EOSyAxz6pE=
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-Antispam: No, score=0.0/5.0, scanned in 0.122sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com> <48A32E97.3090308@Sun.COM>
 <48A3EDA4.8090206@sun.com>
 <56dc2e760808140422q6711819clb1fa99b57e777211@mail.gmail.com>
 <48A46515.7060202@sun.com>
Status: RO
Content-Length: 799

On Thu, Aug 14, 2008 at 8:02 PM, Brian Cameron <Brian.Cameron@sun.com> wrote:
>
> Andras/Henry:
>
>> note: plugins can be installed in ~/.gkrellm2/plugins too
>
> I thought Henry said that only sysadmins could install plugins.
>
> If an end-user can install and run plugins, is it possible to exploit
> the framework in any way?  If someone tricks a user into installing a
> malicious plugin, what bad things can happen, if any.
>
> Does the sysadmin have control over whether plugins in user $HOME
> directories get recognized or not?

they are recognized and loaded automatically.
check gkrellm.h
#define GKRELLM_PLUGINS_DIR             ".gkrellm2/plugins"
and src/plugins.c
i dont see any restriction

I don't think that the admin can control it.


>
> Brian
>



-- 
Andy
http://blog.sartek.net

From Hua.Zhang@sun.com Thu Aug 14 20:39:54 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7F3drUA020147
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 14 Aug 2008 20:39:54 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m7F3ahBT018669
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Fri, 15 Aug 2008 11:39:51 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5M00901I5YMH00@nwk-avmta-2.sfbay.sun.com> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@Sun.COM); Thu, 14 Aug 2008 20:39:34 -0700 (PDT)
Received: from sineb-mail-2.sun.com ([192.18.19.7])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5M007MNI5XLL90@nwk-avmta-2.sfbay.sun.com> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@Sun.COM); Thu,
 14 Aug 2008 20:39:34 -0700 (PDT)
Received: from fe-apac-05.sun.com
 (fe-apac-05.sun.com [192.18.19.176] (may be forged))
	by sineb-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7F3dW6W008495	for
 <lsarc-ext@Sun.COM>; Fri, 15 Aug 2008 03:39:32 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0K5M00701I1TA100@mail-apac.sun.com> (original mail from Hua.Zhang@Sun.COM)
 for lsarc-ext@Sun.COM (ORCPT lsarc-ext@Sun.COM); Fri,
 15 Aug 2008 11:39:32 +0800 (SGT)
Received: from [129.158.217.156] by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0K5M0070YI5UUHMC@mail-apac.sun.com>; Fri,
 15 Aug 2008 11:39:31 +0800 (SGT)
Date: Fri, 15 Aug 2008 11:43:37 +0800
From: Henry Zhang <Hua.Zhang@sun.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
	08/19/2008]
In-reply-to: <48A409AF.7050300@Sun.COM>
Sender: Hua.Zhang@sun.com
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Brian.Cameron@sun.com, LSARC-ext@sun.com,
        Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>
Message-id: <48A4FB69.3070909@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 8BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com> <48A32E97.3090308@Sun.COM>
 <48A3EDA4.8090206@sun.com> <48A409AF.7050300@Sun.COM>
User-Agent: Thunderbird 2.0.0.6 (X11/20071119)
Status: RO
Content-Length: 627

Darren,


Thanks,
Henry

Darren J Moffat 写道:
> I still don't see how OpenSSL is being used.  The proposal mentions SSH 
> for connecting to the remote gkrellmd but SSH and SSL are totally 
> different protocols.

GKrellM have a feature to get mail status, OpenSSL is only used for 
making connection for
mail data from mail server, e.g. how many unread mails in your mail server.
And SSH is used to make the connection between gkrellmd and gkrellm 
client secure data transfer.

> The battery issue is still not addressed.
Sure, I downloaded the battstat applet source codes, and studying them..
> 
> -- 
> Darren J Moffat

From Hua.Zhang@sun.com Fri Aug 15 01:47:12 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7F8lBcF028063
	for <LSARC-ext@sac.sfbay.sun.com>; Fri, 15 Aug 2008 01:47:11 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m7F8l97I026761
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Fri, 15 Aug 2008 16:47:10 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5M00L03WEK5T00@brm-avmta-1.central.sun.com> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@sun.com); Fri, 15 Aug 2008 02:47:08 -0600 (MDT)
Received: from sineb-mail-2.sun.com ([192.18.19.7])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5M00DG0WEIV630@brm-avmta-1.central.sun.com> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Fri,
 15 Aug 2008 02:47:07 -0600 (MDT)
Received: from fe-apac-05.sun.com
 (fe-apac-05.sun.com [192.18.19.176] (may be forged))
	by sineb-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7F8l6i6024275	for
 <lsarc-ext@sun.com>; Fri, 15 Aug 2008 08:47:06 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0K5M00501WARW700@mail-apac.sun.com> (original mail from Hua.Zhang@Sun.COM)
 for lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Fri,
 15 Aug 2008 16:47:06 +0800 (SGT)
Received: from [129.158.217.156] by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0K5M00MRIWEHLRNS@mail-apac.sun.com>; Fri,
 15 Aug 2008 16:47:05 +0800 (SGT)
Date: Fri, 15 Aug 2008 16:51:14 +0800
From: Henry Zhang <Hua.Zhang@sun.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
 08/19/2008]
In-reply-to: <56dc2e760808141054x65c40b6o69b5638615d0ffeb@mail.gmail.com>
Sender: Hua.Zhang@sun.com
To: Andras Barna <andras.barna@gmail.com>
Cc: Brian Cameron <Brian.Cameron@sun.com>, lsarc-ext@sun.com,
        Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>
Message-id: <48A54382.3040500@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 8BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com> <48A32E97.3090308@Sun.COM>
 <48A3EDA4.8090206@sun.com>
 <56dc2e760808140422q6711819clb1fa99b57e777211@mail.gmail.com>
 <48A46515.7060202@sun.com>
 <56dc2e760808141054x65c40b6o69b5638615d0ffeb@mail.gmail.com>
User-Agent: Thunderbird 2.0.0.6 (X11/20071119)
Status: RO
Content-Length: 1541



Andras Barna 写道:
> On Thu, Aug 14, 2008 at 8:02 PM, Brian Cameron <Brian.Cameron@sun.com> wrote:
>> Andras/Henry:
>>
>>> note: plugins can be installed in ~/.gkrellm2/plugins too
>> I thought Henry said that only sysadmins could install plugins.
Yes, sysadmins can install plugins into /usr/lib/gkrellm2/plugins; 
meanwhile end-user can install his own plugins into his home dir 
~/.gkrellm2/plugins-gkrellmd/.
>>
>> If an end-user can install and run plugins, is it possible to exploit
>> the framework in any way?  If someone tricks a user into installing a
>> malicious plugin, what bad things can happen, if any.
>>
>> Does the sysadmin have control over whether plugins in user $HOME
>> directories get recognized or not?
I think the Gkrellm is designed to allow user to add his own plugins, so 
sysadmin can't control those plugins. If we think those plugins are 
dangerous, we may disable to run those plugins?
> 
> they are recognized and loaded automatically.
> check gkrellm.h
> #define GKRELLM_PLUGINS_DIR             ".gkrellm2/plugins"
> and src/plugins.c
> i dont see any restriction
> 
> I don't think that the admin can control it.
GKrellM is composed of gkrellmd server and gkrellm client.

.gkrellm2/plugins is for gkrellm client, it is used for gkrellm running 
to show the status of the local machine.
The ~/.gkrellm2/plugins-gkrellmd/ is used to store server plugins for 
user, so user can add some his own plugins, and then run gkrellm client 
remotely to get the relative information.
> 
> 
>> Brian
>>
> 
> 
> 

From Darren.Moffat@sun.com Fri Aug 15 02:16:56 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7F9GtWn029811
	for <LSARC-ext@sac.sfbay.sun.com>; Fri, 15 Aug 2008 02:16:56 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m7F9GiEN006439
	for <@sunmail2sca.sfbay.sun.com:LSARC-ext@sun.com>; Fri, 15 Aug 2008 17:16:54 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5M00M09XS3U200@nwk-avmta-1.sfbay.Sun.COM> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@Sun.COM); Fri, 15 Aug 2008 02:16:51 -0700 (PDT)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5M00LNGXS23N20@nwk-avmta-1.sfbay.Sun.COM> for
 LSARC-ext@sun.com (ORCPT LSARC-ext@Sun.COM); Fri,
 15 Aug 2008 02:16:51 -0700 (PDT)
Received: from fe-emea-10.sun.com (gmp-eb-lb-2-fe3.eu.sun.com [192.18.6.12])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m7F9Go8J004235	for
 <LSARC-ext@Sun.COM>; Fri, 15 Aug 2008 09:16:50 +0000 (GMT)
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K5M00D01XGWDY00@fe-emea-10.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for LSARC-ext@Sun.COM (ORCPT LSARC-ext@Sun.COM); Fri,
 15 Aug 2008 10:16:50 +0100 (BST)
Received: from [129.156.173.21] by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K5M006HAXS0OQ40@fe-emea-10.sun.com>; Fri,
 15 Aug 2008 10:16:50 +0100 (BST)
Date: Fri, 15 Aug 2008 10:16:48 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
	08/19/2008]
In-reply-to: <48A4FB69.3070909@sun.com>
Sender: Darren.Moffat@sun.com
To: Henry Zhang <Hua.Zhang@sun.com>
Cc: Brian.Cameron@sun.com, LSARC-ext@sun.com,
        Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>
Message-id: <48A54980.6030208@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 8BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com> <48A32E97.3090308@Sun.COM>
 <48A3EDA4.8090206@sun.com> <48A409AF.7050300@Sun.COM>
 <48A4FB69.3070909@sun.com>
User-Agent: Thunderbird 2.0.0.14 (X11/20080630)
Status: RO
Content-Length: 778

Henry Zhang wrote:
> Darren,
> 
> 
> Thanks,
> Henry
> 
> Darren J Moffat 写道:
>> I still don't see how OpenSSL is being used.  The proposal mentions 
>> SSH for connecting to the remote gkrellmd but SSH and SSL are totally 
>> different protocols.
> 
> GKrellM have a feature to get mail status, OpenSSL is only used for 
> making connection for
> mail data from mail server, e.g. how many unread mails in your mail server.

So this is for imap over SSL/TLS (imaps).  Now I understand.  Where are 
the X.509 certificate Trust Anchors for these SSL/TLS connections held ? 
  How does the user get prompted to verify the certificate if there are 
no trust anchors ?  Where is the users answer about trust of the 
presented certificate for imaps stored ?


-- 
Darren J Moffat

From Brian.Cameron@Sun.COM Sat Aug 16 10:23:30 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7GHNUTK002295
	for <LSARC-ext@sac.sfbay.sun.com>; Sat, 16 Aug 2008 10:23:30 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m7GHNSpx000862
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Sat, 16 Aug 2008 18:23:28 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5P00301EZ43400@nwk-avmta-2.sfbay.sun.com> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@Sun.COM); Sat, 16 Aug 2008 10:23:28 -0700 (PDT)
Received: from brmea-mail-1.sun.com ([192.18.98.31])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5P002D2EZ302E0@nwk-avmta-2.sfbay.sun.com> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@Sun.COM); Sat,
 16 Aug 2008 10:23:27 -0700 (PDT)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7GHNRxS014762	for
 <lsarc-ext@Sun.COM>; Sat, 16 Aug 2008 17:23:27 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K5P00701EWXV800@mail-amer.sun.com>
 (original mail from Brian.Cameron@Sun.COM)
 for lsarc-ext@Sun.COM (ORCPT lsarc-ext@Sun.COM); Sat,
 16 Aug 2008 11:23:27 -0600 (MDT)
Received: from [10.0.0.27] ([74.41.197.134])
 by mail-amer.sun.com (Sun Java System Messaging Server 6.2-8.04 (built Feb 28
 2007)) with ESMTPSA id <0K5P00B5MEYXXO80@mail-amer.sun.com>; Sat,
 16 Aug 2008 11:23:27 -0600 (MDT)
Date: Sat, 16 Aug 2008 12:23:27 -0500
From: Brian Cameron <Brian.Cameron@Sun.COM>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
 08/19/2008]
In-reply-to: <48A54382.3040500@sun.com>
Sender: Brian.Cameron@Sun.COM
To: Henry Zhang <Hua.Zhang@Sun.COM>
Cc: Andras Barna <andras.barna@gmail.com>, lsarc-ext@Sun.COM,
        Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>
Message-id: <48A70D0F.5050107@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com> <48A32E97.3090308@Sun.COM>
 <48A3EDA4.8090206@sun.com>
 <56dc2e760808140422q6711819clb1fa99b57e777211@mail.gmail.com>
 <48A46515.7060202@sun.com>
 <56dc2e760808141054x65c40b6o69b5638615d0ffeb@mail.gmail.com>
 <48A54382.3040500@sun.com>
User-Agent: Thunderbird 2.0.0.16 (X11/20080731)
Status: RO
Content-Length: 703


Henry:

> .gkrellm2/plugins is for gkrellm client, it is used for gkrellm running 
> to show the status of the local machine.
> The ~/.gkrellm2/plugins-gkrellmd/ is used to store server plugins for 
> user, so user can add some his own plugins, and then run gkrellm client 
> remotely to get the relative information.

If I trick a user into installing a plugin which allows them to monitor
my keyboard strokes, could such information be sent to the remote
client?

What, if anything, can a system administrator do to prevent such attacks
from being possible.  Can the system administrator turn off the feature
which allows users plugins to be functional?  Is this feature off or on
by default?

Brian

From Hua.Zhang@sun.com Sun Aug 17 22:05:45 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7I55id8012101
	for <LSARC-ext@sac.sfbay.sun.com>; Sun, 17 Aug 2008 22:05:45 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m7I55e4g000417
	for <@sunmail2sca.sfbay.sun.com:LSARC-ext@sun.com>; Mon, 18 Aug 2008 13:05:44 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5S0010565IF700@nwk-avmta-2.sfbay.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@Sun.COM); Sun, 17 Aug 2008 22:05:42 -0700 (PDT)
Received: from sineb-mail-2.sun.com ([192.18.19.7])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5S00LBO65GDL20@nwk-avmta-2.sfbay.sun.com> for
 LSARC-ext@sun.com (ORCPT LSARC-ext@Sun.COM); Sun,
 17 Aug 2008 22:05:41 -0700 (PDT)
Received: from fe-apac-05.sun.com
 (fe-apac-05.sun.com [192.18.19.176] (may be forged))
	by sineb-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7I55euf000566	for
 <LSARC-ext@Sun.COM>; Mon, 18 Aug 2008 05:05:40 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0K5S00C0160RJ700@mail-apac.sun.com> (original mail from Hua.Zhang@Sun.COM)
 for LSARC-ext@Sun.COM (ORCPT LSARC-ext@Sun.COM); Mon,
 18 Aug 2008 13:05:40 +0800 (SGT)
Received: from [129.158.217.156] by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0K5S00MD4655LR9Y@mail-apac.sun.com>; Mon,
 18 Aug 2008 13:05:30 +0800 (SGT)
Date: Mon, 18 Aug 2008 13:09:40 +0800
From: Henry Zhang <Hua.Zhang@sun.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
	08/19/2008]
In-reply-to: <48A54980.6030208@Sun.COM>
Sender: Hua.Zhang@sun.com
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Brian.Cameron@sun.com, LSARC-ext@sun.com,
        Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>
Message-id: <48A90414.6060707@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 8BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com> <48A32E97.3090308@Sun.COM>
 <48A3EDA4.8090206@sun.com> <48A409AF.7050300@Sun.COM>
 <48A4FB69.3070909@sun.com> <48A54980.6030208@Sun.COM>
User-Agent: Thunderbird 2.0.0.6 (X11/20071119)
Status: RO
Content-Length: 922

Hi Darren,

I double-checked the source codes, seems that gkrellm doesn't use 
certificate.


Thanks,
Henry

Darren J Moffat 写道:
> Henry Zhang wrote:
>> Darren,
>>
>>
>> Thanks,
>> Henry
>>
>> Darren J Moffat 写道:
>>> I still don't see how OpenSSL is being used.  The proposal mentions 
>>> SSH for connecting to the remote gkrellmd but SSH and SSL are totally 
>>> different protocols.
>>
>> GKrellM have a feature to get mail status, OpenSSL is only used for 
>> making connection for
>> mail data from mail server, e.g. how many unread mails in your mail 
>> server.
> 
> So this is for imap over SSL/TLS (imaps).  Now I understand.  Where are 
> the X.509 certificate Trust Anchors for these SSL/TLS connections held ? 
>  How does the user get prompted to verify the certificate if there are 
> no trust anchors ?  Where is the users answer about trust of the 
> presented certificate for imaps stored ?
> 
> 

From Hua.Zhang@sun.com Sun Aug 17 22:45:39 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7I5jcLp012394
	for <LSARC-ext@sac.sfbay.sun.com>; Sun, 17 Aug 2008 22:45:39 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m7I5jbt4012930
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Mon, 18 Aug 2008 13:45:37 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5S0010R7ZZB600@brm-avmta-1.central.sun.com> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@Sun.COM); Sun, 17 Aug 2008 23:45:35 -0600 (MDT)
Received: from sineb-mail-2.sun.com ([192.18.19.7])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5S002K27ZYUX90@brm-avmta-1.central.sun.com> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@Sun.COM); Sun,
 17 Aug 2008 23:45:35 -0600 (MDT)
Received: from fe-apac-06.sun.com
 (fe-apac-06.sun.com [192.18.19.177] (may be forged))
	by sineb-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7I5jXDp003738	for
 <lsarc-ext@Sun.COM>; Mon, 18 Aug 2008 05:45:33 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0K5S00K017Z8LU00@mail-apac.sun.com> (original mail from Hua.Zhang@Sun.COM)
 for lsarc-ext@Sun.COM (ORCPT lsarc-ext@Sun.COM); Mon,
 18 Aug 2008 13:45:33 +0800 (SGT)
Received: from [129.158.217.156] by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0K5S00BPL7ZXRE6T@mail-apac.sun.com>; Mon,
 18 Aug 2008 13:45:33 +0800 (SGT)
Date: Mon, 18 Aug 2008 13:49:44 +0800
From: Henry Zhang <Hua.Zhang@sun.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
 08/19/2008]
In-reply-to: <48A70D0F.5050107@sun.com>
Sender: Hua.Zhang@sun.com
To: Brian Cameron <Brian.Cameron@sun.com>
Cc: Andras Barna <andras.barna@gmail.com>, lsarc-ext@sun.com,
        Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>
Message-id: <48A90D78.702@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 8BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com> <48A32E97.3090308@Sun.COM>
 <48A3EDA4.8090206@sun.com>
 <56dc2e760808140422q6711819clb1fa99b57e777211@mail.gmail.com>
 <48A46515.7060202@sun.com>
 <56dc2e760808141054x65c40b6o69b5638615d0ffeb@mail.gmail.com>
 <48A54382.3040500@sun.com> <48A70D0F.5050107@sun.com>
User-Agent: Thunderbird 2.0.0.6 (X11/20071119)
Status: RO
Content-Length: 994

Brian,

Brian Cameron 写道:
> 
> Henry:
> 
>> .gkrellm2/plugins is for gkrellm client, it is used for gkrellm 
>> running to show the status of the local machine.
>> The ~/.gkrellm2/plugins-gkrellmd/ is used to store server plugins for 
>> user, so user can add some his own plugins, and then run gkrellm 
>> client remotely to get the relative information.
> 
> If I trick a user into installing a plugin which allows them to monitor
> my keyboard strokes, could such information be sent to the remote
> client?
Yes, it's possible.

> 
> What, if anything, can a system administrator do to prevent such attacks
> from being possible.  Can the system administrator turn off the feature
> which allows users plugins to be functional?  Is this feature off or on
> by default?
By default, gkrellmd server will load and run all plugins, but we can 
change some codes to make it not load all plugins under 
~/.gkrellm2/plugins-gkrellmd/, only load the plugins installed by 
sysadmins..
> 
> Brian

From Darren.Moffat@Sun.COM Mon Aug 18 02:09:48 2008
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7I99m16018564
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 18 Aug 2008 02:09:48 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m7I99knj015915
	for <@sunmail2sca.sfbay.sun.com:LSARC-ext@sun.com>; Mon, 18 Aug 2008 02:09:47 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5S00D11HGB0800@nwk-avmta-2.sfbay.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@Sun.COM); Mon, 18 Aug 2008 02:09:47 -0700 (PDT)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5S00L6BHG8DWD0@nwk-avmta-2.sfbay.sun.com> for
 LSARC-ext@sun.com (ORCPT LSARC-ext@Sun.COM); Mon,
 18 Aug 2008 02:09:45 -0700 (PDT)
Received: from fe-emea-09.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m7I99i8F024932	for
 <LSARC-ext@Sun.COM>; Mon, 18 Aug 2008 09:09:44 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K5S00J01H6FSE00@fe-emea-09.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for LSARC-ext@Sun.COM (ORCPT LSARC-ext@Sun.COM); Mon,
 18 Aug 2008 10:09:44 +0100 (BST)
Received: from [129.156.173.21] by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K5S00CM0HG3R180@fe-emea-09.sun.com>; Mon,
 18 Aug 2008 10:09:41 +0100 (BST)
Date: Mon, 18 Aug 2008 10:09:39 +0100
From: Darren J Moffat <Darren.Moffat@Sun.COM>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
	08/19/2008]
In-reply-to: <48A90414.6060707@sun.com>
Sender: Darren.Moffat@Sun.COM
To: Henry Zhang <Hua.Zhang@Sun.COM>
Cc: Brian.Cameron@Sun.COM, LSARC-ext@Sun.COM,
        Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>
Message-id: <48A93C53.6020006@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com> <48A32E97.3090308@Sun.COM>
 <48A3EDA4.8090206@sun.com> <48A409AF.7050300@Sun.COM>
 <48A4FB69.3070909@sun.com> <48A54980.6030208@Sun.COM>
 <48A90414.6060707@sun.com>
User-Agent: Thunderbird 2.0.0.14 (X11/20080630)
Status: RO
Content-Length: 603

Henry Zhang wrote:
> Hi Darren,
> 
> I double-checked the source codes, seems that gkrellm doesn't use 
> certificate.

That doesn't seem correct.  You said that it uses SSL (via OpenSSL) to 
protect connections to a mailserver.  The mailserver if it is doing SSL 
will send certificates so gkrellm must be doing something with them - so 
what is it ?  Does it it choose not to validate the certs ?  If so that 
is really bad because it means that it is basically equivalent to not 
doing SSL at all (since the connection is now subject to an undetected 
Man in the Middle Attack).

-- 
Darren J Moffat

From Darren.Moffat@Sun.COM Mon Aug 18 03:17:17 2008
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7IAHGxS019832
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 18 Aug 2008 03:17:16 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m7IAHGtH002824
	for <@sunmail2sca.sfbay.sun.com:LSARC-EXT@sun.com>; Mon, 18 Aug 2008 03:17:16 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5S00G01KKS3J00@nwk-avmta-2.sfbay.sun.com> for LSARC-EXT@sun.com
 (ORCPT LSARC-EXT@Sun.COM); Mon, 18 Aug 2008 03:17:16 -0700 (PDT)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5S00ELDKKRDVE0@nwk-avmta-2.sfbay.sun.com> for
 LSARC-EXT@sun.com (ORCPT LSARC-EXT@Sun.COM); Mon,
 18 Aug 2008 03:17:16 -0700 (PDT)
Received: from fe-emea-10.sun.com (gmp-eb-lb-2-fe3.eu.sun.com [192.18.6.12])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m7IAHFf8006032	for
 <LSARC-EXT@Sun.COM>; Mon, 18 Aug 2008 10:17:15 +0000 (GMT)
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K5S00G01JOAIP00@fe-emea-10.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for LSARC-EXT@Sun.COM (ORCPT LSARC-EXT@Sun.COM); Mon,
 18 Aug 2008 11:17:15 +0100 (BST)
Received: from [129.156.173.21] by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K5S00HOFKKLGZC0@fe-emea-10.sun.com> for LSARC-EXT@Sun.COM
 (ORCPT LSARC-EXT@Sun.COM); Mon, 18 Aug 2008 11:17:09 +0100 (BST)
Date: Mon, 18 Aug 2008 11:17:09 +0100
From: Darren J Moffat <Darren.Moffat@Sun.COM>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
	08/19/2008]
In-reply-to: <48A94753.9000104@sun.com>
Sender: Darren.Moffat@Sun.COM
To: Henry Zhang <Hua.Zhang@Sun.COM>, LSARC-EXT@Sun.COM
Message-id: <48A94C25.9040504@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com> <48A32E97.3090308@Sun.COM>
 <48A3EDA4.8090206@sun.com> <48A409AF.7050300@Sun.COM>
 <48A4FB69.3070909@sun.com> <48A54980.6030208@Sun.COM>
 <48A90414.6060707@sun.com> <48A93C53.6020006@Sun.COM>
 <48A94753.9000104@sun.com>
User-Agent: Thunderbird 2.0.0.14 (X11/20080630)
Status: RO
Content-Length: 1004

I see from the code that it is passing SSL_VERIFY_NONE to 
SSL_CTX_set_verify()

 From the man page:


      SSL_VERIFY_NONE
          Server mode: the server will not send a client
          certificate request to the client, so the client will
          not send a certificate.

          Client mode: if not using an anonymous cipher (by
          default disabled), the server will send a certificate
          which will be checked. The result of the certificate
          verification process can be checked after the TLS/SSL
          handshake using the SSL_get_verify_result(3) function.
          The handshake will be continued regardless of the
          verification result.


This is the answer for the case.  Personally I'm not happy with this 
however it is what gkrellm does and it answers my question.  I would 
like the project team to file a bug upstream (if there isn't one 
already) to provide functionality to actually verify the server's 
SSL/TLS certificate.

--
Darren J Moffat

From Hua.Zhang@sun.com Mon Aug 18 04:10:04 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7IBA4Wq020726
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 18 Aug 2008 04:10:04 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m7IB9vNn009129
	for <@sunmail2sca.sfbay.sun.com:LSARC-EXT@sun.com>; Mon, 18 Aug 2008 04:10:04 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5S00201N0RN900@brm-avmta-1.central.sun.com> for LSARC-EXT@sun.com
 (ORCPT LSARC-EXT@Sun.COM); Mon, 18 Aug 2008 05:10:03 -0600 (MDT)
Received: from sineb-mail-1.sun.com ([192.18.19.6])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5S00B41N0P4RB0@brm-avmta-1.central.sun.com> for
 LSARC-EXT@sun.com (ORCPT LSARC-EXT@Sun.COM); Mon,
 18 Aug 2008 05:10:02 -0600 (MDT)
Received: from fe-apac-06.sun.com
 (fe-apac-06.sun.com [192.18.19.177] (may be forged))
	by sineb-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7IBA19C008750	for
 <LSARC-EXT@Sun.COM>; Mon, 18 Aug 2008 11:10:01 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0K5S00701MZ78X00@mail-apac.sun.com> (original mail from Hua.Zhang@Sun.COM)
 for LSARC-EXT@Sun.COM (ORCPT LSARC-EXT@Sun.COM); Mon,
 18 Aug 2008 19:10:00 +0800 (SGT)
Received: from [129.158.217.156] by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0K5S00FCUN0OQYMK@mail-apac.sun.com> for LSARC-EXT@Sun.COM
 (ORCPT LSARC-EXT@Sun.COM); Mon, 18 Aug 2008 19:10:00 +0800 (SGT)
Date: Mon, 18 Aug 2008 19:14:12 +0800
From: Henry Zhang <Hua.Zhang@sun.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
	08/19/2008]
In-reply-to: <48A94C25.9040504@Sun.COM>
Sender: Hua.Zhang@sun.com
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: LSARC-EXT@sun.com
Message-id: <48A95984.8060107@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 8BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com> <48A32E97.3090308@Sun.COM>
 <48A3EDA4.8090206@sun.com> <48A409AF.7050300@Sun.COM>
 <48A4FB69.3070909@sun.com> <48A54980.6030208@Sun.COM>
 <48A90414.6060707@sun.com> <48A93C53.6020006@Sun.COM>
 <48A94753.9000104@sun.com> <48A94C25.9040504@Sun.COM>
User-Agent: Thunderbird 2.0.0.6 (X11/20071119)
Status: RO
Content-Length: 1146

Hi Darren,

Thanks, I will file a bug on this issue...

Regards,
Henry

Darren J Moffat 写道:
> I see from the code that it is passing SSL_VERIFY_NONE to 
> SSL_CTX_set_verify()
> 
>  From the man page:
> 
> 
>      SSL_VERIFY_NONE
>          Server mode: the server will not send a client
>          certificate request to the client, so the client will
>          not send a certificate.
> 
>          Client mode: if not using an anonymous cipher (by
>          default disabled), the server will send a certificate
>          which will be checked. The result of the certificate
>          verification process can be checked after the TLS/SSL
>          handshake using the SSL_get_verify_result(3) function.
>          The handshake will be continued regardless of the
>          verification result.
> 
> 
> This is the answer for the case.  Personally I'm not happy with this 
> however it is what gkrellm does and it answers my question.  I would 
> like the project team to file a bug upstream (if there isn't one 
> already) to provide functionality to actually verify the server's 
> SSL/TLS certificate.
> 
> -- 
> Darren J Moffat

From John.Fischer@sun.com Mon Aug 18 08:39:30 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7IFdUpv027745
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 18 Aug 2008 08:39:30 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m7IFdQtP007246
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Mon, 18 Aug 2008 08:39:30 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5S00E0NZHSD700@nwk-avmta-1.sfbay.Sun.COM> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@sun.com); Mon, 18 Aug 2008 08:39:28 -0700 (PDT)
Received: from brmea-mail-1.sun.com ([192.18.98.31])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5S00KJIZHRE5E0@nwk-avmta-1.sfbay.Sun.COM> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Mon,
 18 Aug 2008 08:39:27 -0700 (PDT)
Received: from fe-amer-09.sun.com ([192.18.109.79])
	by brmea-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7IFdQpl024104	for
 <lsarc-ext@sun.com>; Mon, 18 Aug 2008 15:39:26 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K5S00K01XWN8I00@mail-amer.sun.com>
 (original mail from John.Fischer@Sun.COM)
 for lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Mon,
 18 Aug 2008 09:39:26 -0600 (MDT)
Received: from 129.145.154.66 ([129.145.154.66])
 by mail-amer.sun.com (Sun Java System Messaging Server 6.2-8.04 (built Feb 28
 2007)) with ESMTPSA id <0K5S00902ZH2J500@mail-amer.sun.com>; Mon,
 18 Aug 2008 09:39:04 -0600 (MDT)
Date: Mon, 18 Aug 2008 08:38:52 -0700
From: John Fischer <John.Fischer@sun.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
	08/19/2008]
In-reply-to: <48A70D0F.5050107@sun.com>
Sender: John.Fischer@sun.com
To: Brian Cameron <Brian.Cameron@sun.com>
Cc: Henry Zhang <Hua.Zhang@sun.com>, Andras Barna <andras.barna@gmail.com>,
        lsarc-ext@sun.com, Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>
Reply-to: John.Fischer@sun.com
Message-id: <1219073931.9503.11.camel@sr1-umpk-16>
MIME-version: 1.0
X-Mailer: Ximian Evolution 1.4.6.301
Content-type: text/plain
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com> <48A32E97.3090308@Sun.COM>
 <48A3EDA4.8090206@sun.com>
 <56dc2e760808140422q6711819clb1fa99b57e777211@mail.gmail.com>
 <48A46515.7060202@sun.com>
 <56dc2e760808141054x65c40b6o69b5638615d0ffeb@mail.gmail.com>
 <48A54382.3040500@sun.com> <48A70D0F.5050107@sun.com>
Status: RO
Content-Length: 921

Brian,

How is this any different from other tools like Firefox?
An end user can add plugins and Add-ons to Firefox.
Thanks,

John

On Sat, 2008-08-16 at 10:23, Brian Cameron wrote:
> Henry:
> 
> > .gkrellm2/plugins is for gkrellm client, it is used for gkrellm running 
> > to show the status of the local machine.
> > The ~/.gkrellm2/plugins-gkrellmd/ is used to store server plugins for 
> > user, so user can add some his own plugins, and then run gkrellm client 
> > remotely to get the relative information.
> 
> If I trick a user into installing a plugin which allows them to monitor
> my keyboard strokes, could such information be sent to the remote
> client?
> 
> What, if anything, can a system administrator do to prevent such attacks
> from being possible.  Can the system administrator turn off the feature
> which allows users plugins to be functional?  Is this feature off or on
> by default?
> 
> Brian


From Brian.Cameron@sun.com Mon Aug 18 09:24:35 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7IGOY5C029378
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 18 Aug 2008 09:24:35 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m7IGOVRu023582
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Mon, 18 Aug 2008 17:24:33 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5T0010J1KWGJ00@brm-avmta-1.central.sun.com> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@sun.com); Mon, 18 Aug 2008 10:24:32 -0600 (MDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5T00JZD1KVYC60@brm-avmta-1.central.sun.com> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Mon,
 18 Aug 2008 10:24:32 -0600 (MDT)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7IGOVYo026886	for
 <lsarc-ext@sun.com>; Mon, 18 Aug 2008 16:24:31 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K5T007011FGKH00@mail-amer.sun.com>
 (original mail from Brian.Cameron@Sun.COM)
 for lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Mon,
 18 Aug 2008 10:24:31 -0600 (MDT)
Received: from [10.0.0.41] ([74.41.197.134])
 by mail-amer.sun.com (Sun Java System Messaging Server 6.2-8.04 (built Feb 28
 2007)) with ESMTPSA id <0K5T003PE1KSMUB0@mail-amer.sun.com>; Mon,
 18 Aug 2008 10:24:28 -0600 (MDT)
Date: Mon, 18 Aug 2008 11:24:36 -0500
From: Brian Cameron <Brian.Cameron@sun.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
	08/19/2008]
In-reply-to: <1219073931.9503.11.camel@sr1-umpk-16>
Sender: Brian.Cameron@sun.com
To: John.Fischer@sun.com
Cc: Henry Zhang <Hua.Zhang@sun.com>, Andras Barna <andras.barna@gmail.com>,
        lsarc-ext@sun.com, Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>
Message-id: <48A9A244.2070107@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com> <48A32E97.3090308@Sun.COM>
 <48A3EDA4.8090206@sun.com>
 <56dc2e760808140422q6711819clb1fa99b57e777211@mail.gmail.com>
 <48A46515.7060202@sun.com>
 <56dc2e760808141054x65c40b6o69b5638615d0ffeb@mail.gmail.com>
 <48A54382.3040500@sun.com> <48A70D0F.5050107@sun.com>
 <1219073931.9503.11.camel@sr1-umpk-16>
User-Agent: Thunderbird 2.0.0.16 (X11/20080731)
Status: RO
Content-Length: 1713


John:

> How is this any different from other tools like Firefox?
> An end user can add plugins and Add-ons to Firefox.
> Thanks,

I wasn't trying to suggest that it is a problem to be able to add
plugins (even malicious ones).

It just seemed to me that Henry was a little confused about how to
approach answering the "Security" question on the ARC form, so I was
trying to highlight some issues that probably should be mentioned.
At any rate "None" seems an insufficient answer, based on this
discussion.

The original paperwork for this case was not very clear about the
plugin interfaces, or that end-users could add plug-ins themselves.
So I have just been trying to tease out what seems to be missing
information.  For all I know, you can install plugins over the
network from the client machine, so I am hoping that in asking these
questions Henry will provide us with more complete information.

Brian


> On Sat, 2008-08-16 at 10:23, Brian Cameron wrote:
>> Henry:
>>
>>> .gkrellm2/plugins is for gkrellm client, it is used for gkrellm running 
>>> to show the status of the local machine.
>>> The ~/.gkrellm2/plugins-gkrellmd/ is used to store server plugins for 
>>> user, so user can add some his own plugins, and then run gkrellm client 
>>> remotely to get the relative information.
>> If I trick a user into installing a plugin which allows them to monitor
>> my keyboard strokes, could such information be sent to the remote
>> client?
>>
>> What, if anything, can a system administrator do to prevent such attacks
>> from being possible.  Can the system administrator turn off the feature
>> which allows users plugins to be functional?  Is this feature off or on
>> by default?
>>
>> Brian
> 


From Brian.Cameron@Sun.COM Mon Aug 18 09:26:22 2008
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7IGQMFU029417
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 18 Aug 2008 09:26:22 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m7IGQMbH010263
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Mon, 18 Aug 2008 09:26:22 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5T001071NXLQ00@brm-avmta-1.central.sun.com> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@Sun.COM); Mon, 18 Aug 2008 10:26:21 -0600 (MDT)
Received: from brmea-mail-3.sun.com ([192.18.98.34])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5T00JKO1NWY460@brm-avmta-1.central.sun.com> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@Sun.COM); Mon,
 18 Aug 2008 10:26:20 -0600 (MDT)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-3.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7IGQKRm028794	for
 <lsarc-ext@Sun.COM>; Mon, 18 Aug 2008 16:26:20 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K5T007011FGKH00@mail-amer.sun.com>
 (original mail from Brian.Cameron@Sun.COM)
 for lsarc-ext@Sun.COM (ORCPT lsarc-ext@Sun.COM); Mon,
 18 Aug 2008 10:26:20 -0600 (MDT)
Received: from [10.0.0.41] ([74.41.197.134])
 by mail-amer.sun.com (Sun Java System Messaging Server 6.2-8.04 (built Feb 28
 2007)) with ESMTPSA id <0K5T003DY1NNMUC0@mail-amer.sun.com>; Mon,
 18 Aug 2008 10:26:12 -0600 (MDT)
Date: Mon, 18 Aug 2008 11:26:19 -0500
From: Brian Cameron <Brian.Cameron@Sun.COM>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
 08/19/2008]
In-reply-to: <48A90D78.702@sun.com>
Sender: Brian.Cameron@Sun.COM
To: Henry Zhang <Hua.Zhang@Sun.COM>
Cc: Andras Barna <andras.barna@gmail.com>, lsarc-ext@Sun.COM,
        Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>
Message-id: <48A9A2AB.7030603@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com> <48A32E97.3090308@Sun.COM>
 <48A3EDA4.8090206@sun.com>
 <56dc2e760808140422q6711819clb1fa99b57e777211@mail.gmail.com>
 <48A46515.7060202@sun.com>
 <56dc2e760808141054x65c40b6o69b5638615d0ffeb@mail.gmail.com>
 <48A54382.3040500@sun.com> <48A70D0F.5050107@sun.com> <48A90D78.702@sun.com>
User-Agent: Thunderbird 2.0.0.16 (X11/20080731)
Status: RO
Content-Length: 793


Henry:

I'm just trying to get a clearer picture about how this works, and
the security ramifications.

>> What, if anything, can a system administrator do to prevent such attacks
>> from being possible.  Can the system administrator turn off the feature
>> which allows users plugins to be functional?  Is this feature off or on
>> by default?
> By default, gkrellmd server will load and run all plugins, but we can 
> change some codes to make it not load all plugins under 
> ~/.gkrellm2/plugins-gkrellmd/, only load the plugins installed by 
> sysadmins..

I'm not sure that this is necessary.  Might be good to update the one
pager with the security-related information that has been discussed.
Then ARC can better make any decision about any additional work
which may be needed.

Brian

From Hua.Zhang@Sun.COM Mon Aug 18 20:08:12 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7J38BQX024964
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 18 Aug 2008 20:08:12 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m7J385ix010453
	for <@sunmail2sca.sfbay.sun.com:lsarc-ext@sun.com>; Tue, 19 Aug 2008 04:08:10 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K5T00M05VDKOR00@nwk-avmta-1.sfbay.Sun.COM> for lsarc-ext@sun.com
 (ORCPT lsarc-ext@sun.com); Mon, 18 Aug 2008 20:08:08 -0700 (PDT)
Received: from sineb-mail-1.sun.com ([192.18.19.6])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K5T003DSVDIGBE0@nwk-avmta-1.sfbay.Sun.COM> for
 lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Mon,
 18 Aug 2008 20:08:08 -0700 (PDT)
Received: from fe-apac-06.sun.com
 (fe-apac-06.sun.com [192.18.19.177] (may be forged))
	by sineb-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7J386E0006251	for
 <lsarc-ext@sun.com>; Tue, 19 Aug 2008 03:08:06 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0K5T00001V7BMU00@mail-apac.sun.com> (original mail from Hua.Zhang@Sun.COM)
 for lsarc-ext@sun.com (ORCPT lsarc-ext@sun.com); Tue,
 19 Aug 2008 11:08:06 +0800 (SGT)
Received: from [129.158.217.156] by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0K5T009XMVDH8FNQ@mail-apac.sun.com>; Tue,
 19 Aug 2008 11:08:06 +0800 (SGT)
Date: Tue, 19 Aug 2008 11:12:17 +0800
From: Henry Zhang <Hua.Zhang@Sun.COM>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
 08/19/2008]
In-reply-to: <48A9A2AB.7030603@sun.com>
Sender: Hua.Zhang@Sun.COM
To: Brian Cameron <Brian.Cameron@Sun.COM>
Cc: Andras Barna <andras.barna@gmail.com>, lsarc-ext@Sun.COM,
        Shi-Ying Irene Huang <sh162551@sac.sfbay.sun.com>
Message-id: <48AA3A11.5060503@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 8BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com> <48A32E97.3090308@Sun.COM>
 <48A3EDA4.8090206@sun.com>
 <56dc2e760808140422q6711819clb1fa99b57e777211@mail.gmail.com>
 <48A46515.7060202@sun.com>
 <56dc2e760808141054x65c40b6o69b5638615d0ffeb@mail.gmail.com>
 <48A54382.3040500@sun.com> <48A70D0F.5050107@sun.com> <48A90D78.702@sun.com>
 <48A9A2AB.7030603@sun.com>
User-Agent: Thunderbird 2.0.0.6 (X11/20071119)
Status: RO
Content-Length: 888



Brian Cameron 写道:
> 
> Henry:
> 
> I'm just trying to get a clearer picture about how this works, and
> the security ramifications.
> 
>>> What, if anything, can a system administrator do to prevent such attacks
>>> from being possible.  Can the system administrator turn off the feature
>>> which allows users plugins to be functional?  Is this feature off or on
>>> by default?
>> By default, gkrellmd server will load and run all plugins, but we can 
>> change some codes to make it not load all plugins under 
>> ~/.gkrellm2/plugins-gkrellmd/, only load the plugins installed by 
>> sysadmins..
> 
> I'm not sure that this is necessary.  Might be good to update the one
> pager with the security-related information that has been discussed.
> Then ARC can better make any decision about any additional work
> which may be needed.
OK, finish updating the one-pager...
> 
> Brian

From Hua.Zhang@Sun.COM Mon Aug 25 04:25:43 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7PBPgRF002027
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 25 Aug 2008 04:25:42 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m7PBPbK2002999
	for <@sunmail2sca.sfbay.sun.com:LSARC-EXT@sun.com>; Mon, 25 Aug 2008 19:25:41 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K6500G05MESQ100@nwk-avmta-1.sfbay.Sun.COM> for LSARC-EXT@sun.com
 (ORCPT LSARC-EXT@sun.com); Mon, 25 Aug 2008 04:25:40 -0700 (PDT)
Received: from sineb-mail-1.sun.com ([192.18.19.6])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K6500MEVMERYL90@nwk-avmta-1.sfbay.Sun.COM> for
 LSARC-EXT@sun.com (ORCPT LSARC-EXT@sun.com); Mon,
 25 Aug 2008 04:25:40 -0700 (PDT)
Received: from fe-apac-05.sun.com
 (fe-apac-05.sun.com [192.18.19.176] (may be forged))
	by sineb-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7PBPcRn026978	for
 <LSARC-EXT@sun.com>; Mon, 25 Aug 2008 11:25:38 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0K6500E01M7H7S00@mail-apac.sun.com> (original mail from Hua.Zhang@Sun.COM)
 for LSARC-EXT@sun.com (ORCPT LSARC-EXT@sun.com); Mon,
 25 Aug 2008 19:25:38 +0800 (SGT)
Received: from [129.158.217.156] by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0K65007L9MEPXJZ9@mail-apac.sun.com> for LSARC-EXT@sun.com
 (ORCPT LSARC-EXT@sun.com); Mon, 25 Aug 2008 19:25:38 +0800 (SGT)
Date: Mon, 25 Aug 2008 19:30:00 +0800
From: Henry Zhang <Hua.Zhang@Sun.COM>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
	08/19/2008]
In-reply-to: <48A95984.8060107@sun.com>
Sender: Hua.Zhang@Sun.COM
To: Henry Zhang <Hua.Zhang@Sun.COM>
Cc: Darren J Moffat <Darren.Moffat@Sun.COM>, LSARC-EXT@Sun.COM
Message-id: <48B297B8.4090102@sun.com>
MIME-version: 1.0
Content-type: multipart/mixed; boundary="Boundary_(ID_G5I/Nhbjkou11cM/kfOYfQ)"
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com> <48A32E97.3090308@Sun.COM>
 <48A3EDA4.8090206@sun.com> <48A409AF.7050300@Sun.COM>
 <48A4FB69.3070909@sun.com> <48A54980.6030208@Sun.COM>
 <48A90414.6060707@sun.com> <48A93C53.6020006@Sun.COM>
 <48A94753.9000104@sun.com> <48A94C25.9040504@Sun.COM>
 <48A95984.8060107@sun.com>
User-Agent: Thunderbird 2.0.0.6 (X11/20071119)
Status: RO
Content-Length: 12176

This is a multi-part message in MIME format.

--Boundary_(ID_G5I/Nhbjkou11cM/kfOYfQ)
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 8BIT

Hi all,

I would summary the discussion below.

1, The battery support on Solaris:
I investigated 2 solution, one is the  patch wrote by David, but this 
patch is using acpidrv.h and /dev/acpidrv which are not on Solaris now, 
the other solution is using HAL, I think this is a solution we can use.
So I am implementing to use HAL/Dbus for the battery information.

2, SSL certification authentication:
I checked the bugzilla, and no category for GKrellM, I sent a mail to 
the maintainer on this issue. I am discussing with him on how to fix 
this problem..

3, Security impact:
Add some content to describe the possible impaction.

Attachment is the updated one-pager..

Thanks,
Henry

Henry Zhang 写道:
> Hi Darren,
> 
> Thanks, I will file a bug on this issue...
> 
> Regards,
> Henry
> 
> Darren J Moffat 写道:
>> I see from the code that it is passing SSL_VERIFY_NONE to 
>> SSL_CTX_set_verify()
>>
>>  From the man page:
>>
>>
>>      SSL_VERIFY_NONE
>>          Server mode: the server will not send a client
>>          certificate request to the client, so the client will
>>          not send a certificate.
>>
>>          Client mode: if not using an anonymous cipher (by
>>          default disabled), the server will send a certificate
>>          which will be checked. The result of the certificate
>>          verification process can be checked after the TLS/SSL
>>          handshake using the SSL_get_verify_result(3) function.
>>          The handshake will be continued regardless of the
>>          verification result.
>>
>>
>> This is the answer for the case.  Personally I'm not happy with this 
>> however it is what gkrellm does and it answers my question.  I would 
>> like the project team to file a bug upstream (if there isn't one 
>> already) to provide functionality to actually verify the server's 
>> SSL/TLS certificate.
>>
>> -- 
>> Darren J Moffat

--Boundary_(ID_G5I/Nhbjkou11cM/kfOYfQ)
Content-type: text/plain; name=one-pager-gkrellm.txt
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=one-pager-gkrellm.txt

Template Version: @(#)onepager.txt 1.29 04/11/15 SMI

1. Introduction

  1.1. Project/Component Working Name:

       GKrellM

  1.2. Name of Document Author/Supplier:

       Henry Zhang     (hua.zhang@sun.com)

  1.3. Date of This Document:

       30/07/08

  1.4. Name of Major Document Customer(s)/Consumer(s):

    1.4.1. The PAC or CPT you expect to review your project:

           Solaris PAC

    1.4.2. The ARC(s) you expect to review your project:

           LSARC

    1.4.3. The Director/VP who is "Sponsoring" this project:

           Robert.Odea@Sun.Com

    1.4.4. The name of your business unit:

           JDS Desktop Engineering, OPG

  1.5. Email Aliases:
       1.5.1. Responsible Manager:     leo.binchy@Sun.COM
       1.5.2. Responsible Engineer:    hua.zhang@Sun.COM
       1.5.3. Marketing Manager:       jeff.mcmeekin@sun.com
       1.5.4. Interest List:           gkrellm@sun.com

2. Project Summary

  2.1. Project Description:
        
       GKrellM, GNU (or Gtk) Krell Monitors (or Meters), is a single process 
       stack of system monitors which supports applying themes to match its 
       appearance to your window manager, Gtk, or any other theme. The current
       version is 2.3.1.

2.2. Risks and Assumptions:
    
    1. Temperature, fan, and voltage sensor monitors not support since missing
       libsensors.

    2. APM laptop battery meter not support since no APM, we will use HAL/DBus
       to implement this function.
    
    3. This application will depend on libgtop, which isn't engineered to fully
       or best support Solaris interfaces for getting system information because
       it was written from a more Linux perspective on system resources, and some
       system information can't get since not fully support from kernel, e.g. 
       some sensor monitor interfaces.

3. Business Summary

  3.1. Problem Area:

       GKrell is a computer program based on the GTK+ toolkit that creates a 
       single process stack of system monitors. It can be used to monitor the 
       status of CPUs, main memory, hard disks, network interfaces, local and 
       remote mailboxes, and many other things. Plugin is supported.

  3.2. Market/Requester:

       JDS Desktop group

  3.3. Business Justification:

       For many users, it's nice to be able to see, real-time, what is happening
       on their system. There are ways to display memory usage, cpu usage, network
       traffic, available and used disk space, and a whole lot of other similar 
       system statistics. This makes it easier to troubleshoot and notice problems
       as they come up. To be display these monitors, you will need gkrellm.

       It's a very useful monitoring tool, can replace a lots of the dock 
       applets, what's even better is that gkrellm supports a plugin interface,
       allowing vast expandability, it's also infinitely configurable and 
       themeable.

       Additionally Gkrellm is very easy on the CPU and packs a lot of information
       into a little bit of space. 

  3.4. Competitive Analysis:

       Windows XP has SysMetrix, Windows Vista has this type of side bar, 
       and GKrellM can run in Linux and other Unix-like operating systems.

  3.5. Opportunity Window/Exposure:

       It is expected that this project will be integrated into Nevada B100

       Note: this tool has GPL V3 license, it will not integrated into 
       Nevada until the license issue is solved.

  3.6. How will you know when you are done?:

       When it is ported to Nevada and runs correctly.  

       The project will be complete when there are no stoppers, P1 or P2 bugs.

4. Technical Description:

  4.1. Details:
       
       GKrellM is a GTK-based stacked monitor program that charts SMP CPUs, 
       disks, load, active net interfaces, and internet connections. There are
       also builtin monitors for memory and swap, file systems with mount/umount
       feature, mailbox checking including POP3 and IMAP, clock/calendar, laptop
       battery, sensors (temperatures, voltages, and fans), and uptime. It has 
       LEDs for the net monitors and an on/off button and online timer for PPP. 
       Multiple monitors managed by a single process to reduce system load.
       There is a GUI popup for configuration, plugin extensions can be installed, 
       and many themes are available. It also features a client/server monitoring 
       capability.

       If you want to configure GkrellM, you can right-click on the monitor and 
       select Configuration from the drop-down menu, or press the F1 key at  
       anytime while GKrellM has the focus. The configuration menu lets you 
       modify general options, built-in monitors, plug-ins, and themes.
       
       GKrellM consists of the gkrellm client and the gkrellmd server. Gkrellm can 
       run in client mode and collect data from gkrellmd server running on a remote
       machine. In this way, the user can remotely monitor different characteristics  
       of all the machines on their LAN, such as hits and load on the web server,  
       disk usage on the mail server, and port traffic on the NAT. 

       The gkrellm client gets data from gkrellmd through SSH. By default gkrellmd
       will not run by default, so the user need to start gkrellmd manually, 
       and optionally add options to configure gkrellmd.  For example,
       you can configure which port gkrellmd will use and which IP addresses or
       hostnames are allowed to connect to gkrellmd. gkrellm client will also be 
       configured to use some port, this port is used to create the SSH connection
       with the gkrellmd server given port. Then you can start gkrellm on another
       system and get the remote data from gkrellmd.
        
       Both gkrellm and the gkrellmd server are plugin capable so special interest 
       monitors can be coded. And in order to make install plugin, you should be root,
       and ensure the plugin will not add additional security issue.


  4.2. Bug/RFE Number(s):

        RFE 6732524

  4.3. In Scope:

       The system information we can get from Solaris 

  4.4. Out of Scope:

       The system information Solaris can't support, e.g. temperature.
       All plugins that are installed by users themselves.

   4.5. Interfaces:
    
      Imported Interfaces
      Interface               Stability    Comments
      -------------------     -----------  -----------------------------------

       /usr/lib/libkstat.so.1   Committed         standard library
       SUNWgettext              Uncommitted
       libgtop                  Volatile          LSARC/2006/347/
       libOpenSSL               Contract Private  PSARC/2006/019/ 
       GNOME Committed Platform Libraries Committed LSARC/2007/520 GTK+ library
                                                        GNOME 2.20 

      Exported Interfaces        Stability      Comments
      -------------------------  -------------  ---------------------------------

       /usr/bin/gkrellm          Volatile       
       SUNWgkrellm               Uncommitted    Package name
       SUNWgkrellm-devel         Uncommitted    Package name
       /usr/include/gkrellm2/gkrellm.h    Project Private
       /usr/lib/gkrellm2/plugins   Project Private      Used to store plugins

  4.6. Doc Impact:

       Man page will need to be added

  4.7. Admin/Config Impact:

       There are no changes to the system administration and configuration. 

  4.8. HA Impact:

       N/A

  4.9. I18N/L10N Impact:

       The JDS team and the G11N are working together to evaluate and provide
       I18N/L10N support.
       

  4.10. Packaging & Delivery:

        The new packages are:

              -  SUNWgkrellm
              -  SUNWgkrellm-devel 

  4.11. Security Impact:

        This application uses OpenSSL, and support plugins, it may cause some
        security concern, but generally all data transfered through the connection
        is the system usage status information, and not very confidential, 
        addtionally in order to make the network connection more secure,
        this application is using SSH and some configuration on IP/port to use,
        see 4.1 for details. 

  4.12. Dependencies:

        SUNWgettext.spec
        Gtk+ 2.0 >= 2.0 
        gdk 2.0
        glib 2.0 >= 2.0
        libgtop
        libssl

5. Reference Documents:

   GKrellM main project page:   
        http://gkrellm.net

   GKrellM Wiki:
        http://en.wikipedia.org/wiki/GKrellM

   GKrellM themes site:
        http://www.muhri.net/gkrellm/


6. Resources and Schedule:

  6.1. Projected Availability:
       
       Expect to integrated into Nevada in build 100 in Q3 2008

  6.2. Cost of Effort:

       Development     1.0 Engineers - 1 Months
       Testing         0.5 Engineers - 1 Week
       RE              0.5 Engineers - 1 Week

  6.3. Cost of Capital Resources:

       N/A

  6.4. Product Approval Committee requested information:

       6.4.1. Consolidation or Component Name:

              JDS / OpenSolaris
 
       6.4.3. Type of CPT Review and Approval expected:

              Standard

       6.4.4. Project Boundary Conditions:

              None

       6.4.5. Is this a necessary project for OEM agreements:

              No

       6.4.6. Notes:

              N/A

       6.4.7. Target RTI Date/Release:

              Nevada B100 - Sep. 2008

       6.4.8. Target Code Design Review Date:

              Sep. 2008

       6.4.9. Update approval addition:

              New project, no Solaris PAC approval yet

  6.5. ARC review type:

       FastTrack

7. Prototype Availability:

  7.1. Prototype Availability:

       Sep. 2008   

  7.2. Prototype Cost:

       1 engineer
       1 QA
       1 RE

--Boundary_(ID_G5I/Nhbjkou11cM/kfOYfQ)--

From andras.barna@gmail.com Mon Aug 25 04:43:37 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7PBhZXF002157
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 25 Aug 2008 04:43:36 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m7PBhT0Y008408
	for <@sunmail2sca.sfbay.sun.com:LSARC-EXT@sun.com>; Mon, 25 Aug 2008 19:43:35 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K650050DN8JJF00@brm-avmta-1.central.sun.com> for LSARC-EXT@sun.com
 (ORCPT LSARC-EXT@sun.com); Mon, 25 Aug 2008 05:43:31 -0600 (MDT)
Received: from brmea-mail-2.sun.com ([192.18.98.43])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K6500H2WN8JGE50@brm-avmta-1.central.sun.com> for
 LSARC-EXT@sun.com (ORCPT LSARC-EXT@sun.com); Mon,
 25 Aug 2008 05:43:31 -0600 (MDT)
Received: from relay44i.sun.com ([192.5.209.118])
	by brmea-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7PBhUd6002524	for
 <LSARC-EXT@sun.com>; Mon, 25 Aug 2008 11:43:30 +0000 (GMT)
Received: from mms48es.mms.us.syntegra.com ([160.41.221.230] [160.41.221.230])
 by relay44i.sun.com with ESMTP id BT-MMP-170709 for LSARC-EXT@sun.com; Mon,
 25 Aug 2008 11:43:30 +0000 (Z)
Received: from relay42i.sun.com (relay42i.sun.com [192.5.209.72])
 by mms48es.mms.us.syntegra.com with ESMTP id BT-MMP-11774803 for
 LSARC-EXT@sun.com; Mon, 25 Aug 2008 11:43:29 +0000 (Z)
Received: from yx-out-1718.google.com ([74.125.44.153] [74.125.44.153])
 by relay4i.sun.com with ESMTP id BT-MMP-7816994 for LSARC-EXT@sun.com; Mon,
 25 Aug 2008 11:43:29 +0000 (Z)
Received: by yx-out-1718.google.com with SMTP id 3so857432yxi.68 for
 <LSARC-EXT@sun.com>; Mon, 25 Aug 2008 04:42:39 -0700 (PDT)
Received: by 10.151.113.5 with SMTP id q5mr7013874ybm.37.1219664558946; Mon,
 25 Aug 2008 04:42:38 -0700 (PDT)
Received: by 10.151.11.8 with HTTP; Mon, 25 Aug 2008 04:42:38 -0700 (PDT)
Date: Mon, 25 Aug 2008 14:42:38 +0300
From: Andras Barna <andras.barna@gmail.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
 08/19/2008]
In-reply-to: <48B297B8.4090102@sun.com>
To: Henry Zhang <Hua.Zhang@sun.com>
Cc: LSARC-EXT@sun.com, Darren J Moffat <Darren.Moffat@sun.com>
Message-id: <56dc2e760808250442v28c2a31cgf8be32f9b549444b@mail.gmail.com>
MIME-version: 1.0
Content-type: text/plain; charset=UTF-8
Content-disposition: inline
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;        d=gmail.com;
 s=gamma; h=domainkey-signature:received:received:message-id:date:from:to
 :subject:cc:in-reply-to:mime-version:content-type
 :content-transfer-encoding:content-disposition:references;
 bh=WYiz4dsOBhiA9QiNXHgzo6KVAmsjmz7lvsCghS/w05k=;
 b=GTor9yYe8I/lhYCVe9ttkOe7VX9cTBQuqNBBI534/do/JBMW6y50VNNcjeLoFOAjOt
 SXOoaCViOJPMx27BhttP6Tres2mM+EJ6j+H/NP5dzqFyiu1GElWdo08SHu56Tixp4xyS
 svpJFKdkuNaS87QdqfZHOaZe1KE0ummlmWrp8=
DomainKey-Signature: a=rsa-sha1; c=nofws;        d=gmail.com; s=gamma;
 h=message-id:date:from:to:subject:cc:in-reply-to:mime-version
 :content-type:content-transfer-encoding:content-disposition :references;
 b=cC7j93PY0pjYcwuu+JMVUqy6iSoQ2eaTwQvVVV/PkyBIWIw53If4X3K8voh9iVOsrd
 O2qwa7lf/RlRltNyTdX9JfMlAxjigCb2KLOgEdmxhZ42vVTEGzhiY4yrevZF4kcbXcQj
 m7MglR33ia2DyHzbYJQUBJdlvOMkCdpmflaCE=
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-Antispam: No, score=1.0/5.0, scanned in 0.153sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A409AF.7050300@Sun.COM> <48A4FB69.3070909@sun.com>
 <48A54980.6030208@Sun.COM> <48A90414.6060707@sun.com>
 <48A93C53.6020006@Sun.COM> <48A94753.9000104@sun.com>
 <48A94C25.9040504@Sun.COM> <48A95984.8060107@sun.com>
 <48B297B8.4090102@sun.com>
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from base64 to 8bit by sac.sfbay.sun.com id m7PBhZXF002157
Status: RO
Content-Length: 12389

FYI: gkrellm on solaris not requires libgtop

On Mon, Aug 25, 2008 at 2:30 PM, Henry Zhang <Hua.Zhang@sun.com> wrote:
> Hi all,
>
> I would summary the discussion below.
>
> 1, The battery support on Solaris:
> I investigated 2 solution, one is the  patch wrote by David, but this patch
> is using acpidrv.h and /dev/acpidrv which are not on Solaris now, the other
> solution is using HAL, I think this is a solution we can use.
> So I am implementing to use HAL/Dbus for the battery information.
>
> 2, SSL certification authentication:
> I checked the bugzilla, and no category for GKrellM, I sent a mail to the
> maintainer on this issue. I am discussing with him on how to fix this
> problem..
>
> 3, Security impact:
> Add some content to describe the possible impaction.
>
> Attachment is the updated one-pager..
>
> Thanks,
> Henry
>
> Henry Zhang 写道:
>>
>> Hi Darren,
>>
>> Thanks, I will file a bug on this issue...
>>
>> Regards,
>> Henry
>>
>> Darren J Moffat 写道:
>>>
>>> I see from the code that it is passing SSL_VERIFY_NONE to
>>> SSL_CTX_set_verify()
>>>
>>>  From the man page:
>>>
>>>
>>>     SSL_VERIFY_NONE
>>>         Server mode: the server will not send a client
>>>         certificate request to the client, so the client will
>>>         not send a certificate.
>>>
>>>         Client mode: if not using an anonymous cipher (by
>>>         default disabled), the server will send a certificate
>>>         which will be checked. The result of the certificate
>>>         verification process can be checked after the TLS/SSL
>>>         handshake using the SSL_get_verify_result(3) function.
>>>         The handshake will be continued regardless of the
>>>         verification result.
>>>
>>>
>>> This is the answer for the case.  Personally I'm not happy with this
>>> however it is what gkrellm does and it answers my question.  I would like
>>> the project team to file a bug upstream (if there isn't one already) to
>>> provide functionality to actually verify the server's SSL/TLS certificate.
>>>
>>> --
>>> Darren J Moffat
>
> Template Version: @(#)onepager.txt 1.29 04/11/15 SMI
>
> 1. Introduction
>
>  1.1. Project/Component Working Name:
>
>       GKrellM
>
>  1.2. Name of Document Author/Supplier:
>
>       Henry Zhang     (hua.zhang@sun.com)
>
>  1.3. Date of This Document:
>
>       30/07/08
>
>  1.4. Name of Major Document Customer(s)/Consumer(s):
>
>    1.4.1. The PAC or CPT you expect to review your project:
>
>           Solaris PAC
>
>    1.4.2. The ARC(s) you expect to review your project:
>
>           LSARC
>
>    1.4.3. The Director/VP who is "Sponsoring" this project:
>
>           Robert.Odea@Sun.Com
>
>    1.4.4. The name of your business unit:
>
>           JDS Desktop Engineering, OPG
>
>  1.5. Email Aliases:
>       1.5.1. Responsible Manager:     leo.binchy@Sun.COM
>       1.5.2. Responsible Engineer:    hua.zhang@Sun.COM
>       1.5.3. Marketing Manager:       jeff.mcmeekin@sun.com
>       1.5.4. Interest List:           gkrellm@sun.com
>
> 2. Project Summary
>
>  2.1. Project Description:
>
>       GKrellM, GNU (or Gtk) Krell Monitors (or Meters), is a single process
>       stack of system monitors which supports applying themes to match its
>       appearance to your window manager, Gtk, or any other theme. The
> current
>       version is 2.3.1.
>
> 2.2. Risks and Assumptions:
>
>    1. Temperature, fan, and voltage sensor monitors not support since
> missing
>       libsensors.
>
>    2. APM laptop battery meter not support since no APM, we will use
> HAL/DBus
>       to implement this function.
>
>    3. This application will depend on libgtop, which isn't engineered to
> fully
>       or best support Solaris interfaces for getting system information
> because
>       it was written from a more Linux perspective on system resources, and
> some
>       system information can't get since not fully support from kernel, e.g.
>       some sensor monitor interfaces.
>
> 3. Business Summary
>
>  3.1. Problem Area:
>
>       GKrell is a computer program based on the GTK+ toolkit that creates a
>       single process stack of system monitors. It can be used to monitor the
>       status of CPUs, main memory, hard disks, network interfaces, local and
>       remote mailboxes, and many other things. Plugin is supported.
>
>  3.2. Market/Requester:
>
>       JDS Desktop group
>
>  3.3. Business Justification:
>
>       For many users, it's nice to be able to see, real-time, what is
> happening
>       on their system. There are ways to display memory usage, cpu usage,
> network
>       traffic, available and used disk space, and a whole lot of other
> similar
>       system statistics. This makes it easier to troubleshoot and notice
> problems
>       as they come up. To be display these monitors, you will need gkrellm.
>
>       It's a very useful monitoring tool, can replace a lots of the dock
>       applets, what's even better is that gkrellm supports a plugin
> interface,
>       allowing vast expandability, it's also infinitely configurable and
>       themeable.
>
>       Additionally Gkrellm is very easy on the CPU and packs a lot of
> information
>       into a little bit of space.
>
>  3.4. Competitive Analysis:
>
>       Windows XP has SysMetrix, Windows Vista has this type of side bar,
>       and GKrellM can run in Linux and other Unix-like operating systems.
>
>  3.5. Opportunity Window/Exposure:
>
>       It is expected that this project will be integrated into Nevada B100
>
>       Note: this tool has GPL V3 license, it will not integrated into
>       Nevada until the license issue is solved.
>
>  3.6. How will you know when you are done?:
>
>       When it is ported to Nevada and runs correctly.
>
>       The project will be complete when there are no stoppers, P1 or P2
> bugs.
>
> 4. Technical Description:
>
>  4.1. Details:
>
>       GKrellM is a GTK-based stacked monitor program that charts SMP CPUs,
>       disks, load, active net interfaces, and internet connections. There
> are
>       also builtin monitors for memory and swap, file systems with
> mount/umount
>       feature, mailbox checking including POP3 and IMAP, clock/calendar,
> laptop
>       battery, sensors (temperatures, voltages, and fans), and uptime. It
> has
>       LEDs for the net monitors and an on/off button and online timer for
> PPP.
>       Multiple monitors managed by a single process to reduce system load.
>       There is a GUI popup for configuration, plugin extensions can be
> installed,
>       and many themes are available. It also features a client/server
> monitoring
>       capability.
>
>       If you want to configure GkrellM, you can right-click on the monitor
> and
>       select Configuration from the drop-down menu, or press the F1 key at
>       anytime while GKrellM has the focus. The configuration menu lets you
>       modify general options, built-in monitors, plug-ins, and themes.
>
>       GKrellM consists of the gkrellm client and the gkrellmd server.
> Gkrellm can
>       run in client mode and collect data from gkrellmd server running on a
> remote
>       machine. In this way, the user can remotely monitor different
> characteristics
>       of all the machines on their LAN, such as hits and load on the web
> server,
>       disk usage on the mail server, and port traffic on the NAT.
>
>       The gkrellm client gets data from gkrellmd through SSH. By default
> gkrellmd
>       will not run by default, so the user need to start gkrellmd manually,
>       and optionally add options to configure gkrellmd.  For example,
>       you can configure which port gkrellmd will use and which IP addresses
> or
>       hostnames are allowed to connect to gkrellmd. gkrellm client will also
> be
>       configured to use some port, this port is used to create the SSH
> connection
>       with the gkrellmd server given port. Then you can start gkrellm on
> another
>       system and get the remote data from gkrellmd.
>
>       Both gkrellm and the gkrellmd server are plugin capable so special
> interest
>       monitors can be coded. And in order to make install plugin, you should
> be root,
>       and ensure the plugin will not add additional security issue.
>
>
>  4.2. Bug/RFE Number(s):
>
>        RFE 6732524
>
>  4.3. In Scope:
>
>       The system information we can get from Solaris
>
>  4.4. Out of Scope:
>
>       The system information Solaris can't support, e.g. temperature.
>       All plugins that are installed by users themselves.
>
>   4.5. Interfaces:
>
>      Imported Interfaces
>      Interface               Stability    Comments
>      -------------------     -----------
>  -----------------------------------
>
>       /usr/lib/libkstat.so.1   Committed         standard library
>       SUNWgettext              Uncommitted
>       libgtop                  Volatile          LSARC/2006/347/
>       libOpenSSL               Contract Private  PSARC/2006/019/
>       GNOME Committed Platform Libraries Committed LSARC/2007/520 GTK+
> library
>                                                        GNOME 2.20
>
>      Exported Interfaces        Stability      Comments
>      -------------------------  -------------
>  ---------------------------------
>
>       /usr/bin/gkrellm          Volatile
>       SUNWgkrellm               Uncommitted    Package name
>       SUNWgkrellm-devel         Uncommitted    Package name
>       /usr/include/gkrellm2/gkrellm.h    Project Private
>       /usr/lib/gkrellm2/plugins   Project Private      Used to store plugins
>
>  4.6. Doc Impact:
>
>       Man page will need to be added
>
>  4.7. Admin/Config Impact:
>
>       There are no changes to the system administration and configuration.
>
>  4.8. HA Impact:
>
>       N/A
>
>  4.9. I18N/L10N Impact:
>
>       The JDS team and the G11N are working together to evaluate and provide
>       I18N/L10N support.
>
>
>  4.10. Packaging & Delivery:
>
>        The new packages are:
>
>              -  SUNWgkrellm
>              -  SUNWgkrellm-devel
>
>  4.11. Security Impact:
>
>        This application uses OpenSSL, and support plugins, it may cause some
>        security concern, but generally all data transfered through the
> connection
>        is the system usage status information, and not very confidential,
>        addtionally in order to make the network connection more secure,
>        this application is using SSH and some configuration on IP/port to
> use,
>        see 4.1 for details.
>
>  4.12. Dependencies:
>
>        SUNWgettext.spec
>        Gtk+ 2.0 >= 2.0
>        gdk 2.0
>        glib 2.0 >= 2.0
>        libgtop
>        libssl
>
> 5. Reference Documents:
>
>   GKrellM main project page:
>        http://gkrellm.net
>
>   GKrellM Wiki:
>        http://en.wikipedia.org/wiki/GKrellM
>
>   GKrellM themes site:
>        http://www.muhri.net/gkrellm/
>
>
> 6. Resources and Schedule:
>
>  6.1. Projected Availability:
>
>       Expect to integrated into Nevada in build 100 in Q3 2008
>
>  6.2. Cost of Effort:
>
>       Development     1.0 Engineers - 1 Months
>       Testing         0.5 Engineers - 1 Week
>       RE              0.5 Engineers - 1 Week
>
>  6.3. Cost of Capital Resources:
>
>       N/A
>
>  6.4. Product Approval Committee requested information:
>
>       6.4.1. Consolidation or Component Name:
>
>              JDS / OpenSolaris
>
>       6.4.3. Type of CPT Review and Approval expected:
>
>              Standard
>
>       6.4.4. Project Boundary Conditions:
>
>              None
>
>       6.4.5. Is this a necessary project for OEM agreements:
>
>              No
>
>       6.4.6. Notes:
>
>              N/A
>
>       6.4.7. Target RTI Date/Release:
>
>              Nevada B100 - Sep. 2008
>
>       6.4.8. Target Code Design Review Date:
>
>              Sep. 2008
>
>       6.4.9. Update approval addition:
>
>              New project, no Solaris PAC approval yet
>
>  6.5. ARC review type:
>
>       FastTrack
>
> 7. Prototype Availability:
>
>  7.1. Prototype Availability:
>
>       Sep. 2008
>
>  7.2. Prototype Cost:
>
>       1 engineer
>       1 QA
>       1 RE
>
> _______________________________________________
> opensolaris-arc mailing list
> opensolaris-arc@opensolaris.org
>



-- 
Andy
http://blog.sartek.net


From Hua.Zhang@sun.com Mon Aug 25 05:10:10 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7PCAAEd003253
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 25 Aug 2008 05:10:10 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m7PCA5HU006614
	for <@sunmail2sca.sfbay.sun.com:LSARC-EXT@sun.com>; Mon, 25 Aug 2008 05:10:10 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K650072FOGWK400@brm-avmta-1.central.sun.com> for LSARC-EXT@sun.com
 (ORCPT LSARC-EXT@sun.com); Mon, 25 Aug 2008 06:10:08 -0600 (MDT)
Received: from sineb-mail-2.sun.com ([192.18.19.7])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K6500HXMOGVGD60@brm-avmta-1.central.sun.com> for
 LSARC-EXT@sun.com (ORCPT LSARC-EXT@sun.com); Mon,
 25 Aug 2008 06:10:08 -0600 (MDT)
Received: from fe-apac-06.sun.com
 (fe-apac-06.sun.com [192.18.19.177] (may be forged))
	by sineb-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7PCA27D022692	for
 <LSARC-EXT@sun.com>; Mon, 25 Aug 2008 12:10:06 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0K6500K01OCL5K00@mail-apac.sun.com> (original mail from Hua.Zhang@Sun.COM)
 for LSARC-EXT@sun.com (ORCPT LSARC-EXT@sun.com); Mon,
 25 Aug 2008 20:10:04 +0800 (SGT)
Received: from [129.158.217.156] by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0K65009EEOGD8FQ3@mail-apac.sun.com> for LSARC-EXT@sun.com
 (ORCPT LSARC-EXT@sun.com); Mon, 25 Aug 2008 20:09:50 +0800 (SGT)
Date: Mon, 25 Aug 2008 20:14:12 +0800
From: Henry Zhang <Hua.Zhang@sun.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
 08/19/2008]
In-reply-to: <56dc2e760808250442v28c2a31cgf8be32f9b549444b@mail.gmail.com>
Sender: Hua.Zhang@sun.com
To: Andras Barna <andras.barna@gmail.com>
Cc: LSARC-EXT@sun.com, Darren J Moffat <Darren.Moffat@sun.com>
Message-id: <48B2A214.2050005@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 8BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A409AF.7050300@Sun.COM> <48A4FB69.3070909@sun.com>
 <48A54980.6030208@Sun.COM> <48A90414.6060707@sun.com>
 <48A93C53.6020006@Sun.COM> <48A94753.9000104@sun.com>
 <48A94C25.9040504@Sun.COM> <48A95984.8060107@sun.com>
 <48B297B8.4090102@sun.com>
 <56dc2e760808250442v28c2a31cgf8be32f9b549444b@mail.gmail.com>
User-Agent: Thunderbird 2.0.0.6 (X11/20071119)
Status: RO
Content-Length: 12952

Yes, and I noticed some functions are missing, and some functions are 
not correct in current Nevada, I am writing new codes based on libgtop 
for them...

Henry

Andras Barna 写道:
> FYI: gkrellm on solaris not requires libgtop
> 
> On Mon, Aug 25, 2008 at 2:30 PM, Henry Zhang <Hua.Zhang@sun.com> wrote:
>> Hi all,
>>
>> I would summary the discussion below.
>>
>> 1, The battery support on Solaris:
>> I investigated 2 solution, one is the  patch wrote by David, but this patch
>> is using acpidrv.h and /dev/acpidrv which are not on Solaris now, the other
>> solution is using HAL, I think this is a solution we can use.
>> So I am implementing to use HAL/Dbus for the battery information.
>>
>> 2, SSL certification authentication:
>> I checked the bugzilla, and no category for GKrellM, I sent a mail to the
>> maintainer on this issue. I am discussing with him on how to fix this
>> problem..
>>
>> 3, Security impact:
>> Add some content to describe the possible impaction.
>>
>> Attachment is the updated one-pager..
>>
>> Thanks,
>> Henry
>>
>> Henry Zhang 写道:
>>> Hi Darren,
>>>
>>> Thanks, I will file a bug on this issue...
>>>
>>> Regards,
>>> Henry
>>>
>>> Darren J Moffat 写道:
>>>> I see from the code that it is passing SSL_VERIFY_NONE to
>>>> SSL_CTX_set_verify()
>>>>
>>>>  From the man page:
>>>>
>>>>
>>>>     SSL_VERIFY_NONE
>>>>         Server mode: the server will not send a client
>>>>         certificate request to the client, so the client will
>>>>         not send a certificate.
>>>>
>>>>         Client mode: if not using an anonymous cipher (by
>>>>         default disabled), the server will send a certificate
>>>>         which will be checked. The result of the certificate
>>>>         verification process can be checked after the TLS/SSL
>>>>         handshake using the SSL_get_verify_result(3) function.
>>>>         The handshake will be continued regardless of the
>>>>         verification result.
>>>>
>>>>
>>>> This is the answer for the case.  Personally I'm not happy with this
>>>> however it is what gkrellm does and it answers my question.  I would like
>>>> the project team to file a bug upstream (if there isn't one already) to
>>>> provide functionality to actually verify the server's SSL/TLS certificate.
>>>>
>>>> --
>>>> Darren J Moffat
>> Template Version: @(#)onepager.txt 1.29 04/11/15 SMI
>>
>> 1. Introduction
>>
>>  1.1. Project/Component Working Name:
>>
>>       GKrellM
>>
>>  1.2. Name of Document Author/Supplier:
>>
>>       Henry Zhang     (hua.zhang@sun.com)
>>
>>  1.3. Date of This Document:
>>
>>       30/07/08
>>
>>  1.4. Name of Major Document Customer(s)/Consumer(s):
>>
>>    1.4.1. The PAC or CPT you expect to review your project:
>>
>>           Solaris PAC
>>
>>    1.4.2. The ARC(s) you expect to review your project:
>>
>>           LSARC
>>
>>    1.4.3. The Director/VP who is "Sponsoring" this project:
>>
>>           Robert.Odea@Sun.Com
>>
>>    1.4.4. The name of your business unit:
>>
>>           JDS Desktop Engineering, OPG
>>
>>  1.5. Email Aliases:
>>       1.5.1. Responsible Manager:     leo.binchy@Sun.COM
>>       1.5.2. Responsible Engineer:    hua.zhang@Sun.COM
>>       1.5.3. Marketing Manager:       jeff.mcmeekin@sun.com
>>       1.5.4. Interest List:           gkrellm@sun.com
>>
>> 2. Project Summary
>>
>>  2.1. Project Description:
>>
>>       GKrellM, GNU (or Gtk) Krell Monitors (or Meters), is a single process
>>       stack of system monitors which supports applying themes to match its
>>       appearance to your window manager, Gtk, or any other theme. The
>> current
>>       version is 2.3.1.
>>
>> 2.2. Risks and Assumptions:
>>
>>    1. Temperature, fan, and voltage sensor monitors not support since
>> missing
>>       libsensors.
>>
>>    2. APM laptop battery meter not support since no APM, we will use
>> HAL/DBus
>>       to implement this function.
>>
>>    3. This application will depend on libgtop, which isn't engineered to
>> fully
>>       or best support Solaris interfaces for getting system information
>> because
>>       it was written from a more Linux perspective on system resources, and
>> some
>>       system information can't get since not fully support from kernel, e.g.
>>       some sensor monitor interfaces.
>>
>> 3. Business Summary
>>
>>  3.1. Problem Area:
>>
>>       GKrell is a computer program based on the GTK+ toolkit that creates a
>>       single process stack of system monitors. It can be used to monitor the
>>       status of CPUs, main memory, hard disks, network interfaces, local and
>>       remote mailboxes, and many other things. Plugin is supported.
>>
>>  3.2. Market/Requester:
>>
>>       JDS Desktop group
>>
>>  3.3. Business Justification:
>>
>>       For many users, it's nice to be able to see, real-time, what is
>> happening
>>       on their system. There are ways to display memory usage, cpu usage,
>> network
>>       traffic, available and used disk space, and a whole lot of other
>> similar
>>       system statistics. This makes it easier to troubleshoot and notice
>> problems
>>       as they come up. To be display these monitors, you will need gkrellm.
>>
>>       It's a very useful monitoring tool, can replace a lots of the dock
>>       applets, what's even better is that gkrellm supports a plugin
>> interface,
>>       allowing vast expandability, it's also infinitely configurable and
>>       themeable.
>>
>>       Additionally Gkrellm is very easy on the CPU and packs a lot of
>> information
>>       into a little bit of space.
>>
>>  3.4. Competitive Analysis:
>>
>>       Windows XP has SysMetrix, Windows Vista has this type of side bar,
>>       and GKrellM can run in Linux and other Unix-like operating systems.
>>
>>  3.5. Opportunity Window/Exposure:
>>
>>       It is expected that this project will be integrated into Nevada B100
>>
>>       Note: this tool has GPL V3 license, it will not integrated into
>>       Nevada until the license issue is solved.
>>
>>  3.6. How will you know when you are done?:
>>
>>       When it is ported to Nevada and runs correctly.
>>
>>       The project will be complete when there are no stoppers, P1 or P2
>> bugs.
>>
>> 4. Technical Description:
>>
>>  4.1. Details:
>>
>>       GKrellM is a GTK-based stacked monitor program that charts SMP CPUs,
>>       disks, load, active net interfaces, and internet connections. There
>> are
>>       also builtin monitors for memory and swap, file systems with
>> mount/umount
>>       feature, mailbox checking including POP3 and IMAP, clock/calendar,
>> laptop
>>       battery, sensors (temperatures, voltages, and fans), and uptime. It
>> has
>>       LEDs for the net monitors and an on/off button and online timer for
>> PPP.
>>       Multiple monitors managed by a single process to reduce system load.
>>       There is a GUI popup for configuration, plugin extensions can be
>> installed,
>>       and many themes are available. It also features a client/server
>> monitoring
>>       capability.
>>
>>       If you want to configure GkrellM, you can right-click on the monitor
>> and
>>       select Configuration from the drop-down menu, or press the F1 key at
>>       anytime while GKrellM has the focus. The configuration menu lets you
>>       modify general options, built-in monitors, plug-ins, and themes.
>>
>>       GKrellM consists of the gkrellm client and the gkrellmd server.
>> Gkrellm can
>>       run in client mode and collect data from gkrellmd server running on a
>> remote
>>       machine. In this way, the user can remotely monitor different
>> characteristics
>>       of all the machines on their LAN, such as hits and load on the web
>> server,
>>       disk usage on the mail server, and port traffic on the NAT.
>>
>>       The gkrellm client gets data from gkrellmd through SSH. By default
>> gkrellmd
>>       will not run by default, so the user need to start gkrellmd manually,
>>       and optionally add options to configure gkrellmd.  For example,
>>       you can configure which port gkrellmd will use and which IP addresses
>> or
>>       hostnames are allowed to connect to gkrellmd. gkrellm client will also
>> be
>>       configured to use some port, this port is used to create the SSH
>> connection
>>       with the gkrellmd server given port. Then you can start gkrellm on
>> another
>>       system and get the remote data from gkrellmd.
>>
>>       Both gkrellm and the gkrellmd server are plugin capable so special
>> interest
>>       monitors can be coded. And in order to make install plugin, you should
>> be root,
>>       and ensure the plugin will not add additional security issue.
>>
>>
>>  4.2. Bug/RFE Number(s):
>>
>>        RFE 6732524
>>
>>  4.3. In Scope:
>>
>>       The system information we can get from Solaris
>>
>>  4.4. Out of Scope:
>>
>>       The system information Solaris can't support, e.g. temperature.
>>       All plugins that are installed by users themselves.
>>
>>   4.5. Interfaces:
>>
>>      Imported Interfaces
>>      Interface               Stability    Comments
>>      -------------------     -----------
>>  -----------------------------------
>>
>>       /usr/lib/libkstat.so.1   Committed         standard library
>>       SUNWgettext              Uncommitted
>>       libgtop                  Volatile          LSARC/2006/347/
>>       libOpenSSL               Contract Private  PSARC/2006/019/
>>       GNOME Committed Platform Libraries Committed LSARC/2007/520 GTK+
>> library
>>                                                        GNOME 2.20
>>
>>      Exported Interfaces        Stability      Comments
>>      -------------------------  -------------
>>  ---------------------------------
>>
>>       /usr/bin/gkrellm          Volatile
>>       SUNWgkrellm               Uncommitted    Package name
>>       SUNWgkrellm-devel         Uncommitted    Package name
>>       /usr/include/gkrellm2/gkrellm.h    Project Private
>>       /usr/lib/gkrellm2/plugins   Project Private      Used to store plugins
>>
>>  4.6. Doc Impact:
>>
>>       Man page will need to be added
>>
>>  4.7. Admin/Config Impact:
>>
>>       There are no changes to the system administration and configuration.
>>
>>  4.8. HA Impact:
>>
>>       N/A
>>
>>  4.9. I18N/L10N Impact:
>>
>>       The JDS team and the G11N are working together to evaluate and provide
>>       I18N/L10N support.
>>
>>
>>  4.10. Packaging & Delivery:
>>
>>        The new packages are:
>>
>>              -  SUNWgkrellm
>>              -  SUNWgkrellm-devel
>>
>>  4.11. Security Impact:
>>
>>        This application uses OpenSSL, and support plugins, it may cause some
>>        security concern, but generally all data transfered through the
>> connection
>>        is the system usage status information, and not very confidential,
>>        addtionally in order to make the network connection more secure,
>>        this application is using SSH and some configuration on IP/port to
>> use,
>>        see 4.1 for details.
>>
>>  4.12. Dependencies:
>>
>>        SUNWgettext.spec
>>        Gtk+ 2.0 >= 2.0
>>        gdk 2.0
>>        glib 2.0 >= 2.0
>>        libgtop
>>        libssl
>>
>> 5. Reference Documents:
>>
>>   GKrellM main project page:
>>        http://gkrellm.net
>>
>>   GKrellM Wiki:
>>        http://en.wikipedia.org/wiki/GKrellM
>>
>>   GKrellM themes site:
>>        http://www.muhri.net/gkrellm/
>>
>>
>> 6. Resources and Schedule:
>>
>>  6.1. Projected Availability:
>>
>>       Expect to integrated into Nevada in build 100 in Q3 2008
>>
>>  6.2. Cost of Effort:
>>
>>       Development     1.0 Engineers - 1 Months
>>       Testing         0.5 Engineers - 1 Week
>>       RE              0.5 Engineers - 1 Week
>>
>>  6.3. Cost of Capital Resources:
>>
>>       N/A
>>
>>  6.4. Product Approval Committee requested information:
>>
>>       6.4.1. Consolidation or Component Name:
>>
>>              JDS / OpenSolaris
>>
>>       6.4.3. Type of CPT Review and Approval expected:
>>
>>              Standard
>>
>>       6.4.4. Project Boundary Conditions:
>>
>>              None
>>
>>       6.4.5. Is this a necessary project for OEM agreements:
>>
>>              No
>>
>>       6.4.6. Notes:
>>
>>              N/A
>>
>>       6.4.7. Target RTI Date/Release:
>>
>>              Nevada B100 - Sep. 2008
>>
>>       6.4.8. Target Code Design Review Date:
>>
>>              Sep. 2008
>>
>>       6.4.9. Update approval addition:
>>
>>              New project, no Solaris PAC approval yet
>>
>>  6.5. ARC review type:
>>
>>       FastTrack
>>
>> 7. Prototype Availability:
>>
>>  7.1. Prototype Availability:
>>
>>       Sep. 2008
>>
>>  7.2. Prototype Cost:
>>
>>       1 engineer
>>       1 QA
>>       1 RE
>>
>> _______________________________________________
>> opensolaris-arc mailing list
>> opensolaris-arc@opensolaris.org
>>
> 
> 
> 

From Brian.Cameron@SUN.COM Mon Aug 25 06:07:05 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7PD75ck005339
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 25 Aug 2008 06:07:05 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m7PD73NZ022067
	for <@sunmail2sca.sfbay.sun.com:LSARC-EXT@sun.com>; Mon, 25 Aug 2008 06:07:05 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K650050NR3S2E00@nwk-avmta-1.sfbay.Sun.COM> for LSARC-EXT@sun.com
 (ORCPT LSARC-EXT@sun.com); Mon, 25 Aug 2008 06:07:04 -0700 (PDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K65001ONR3PSMB0@nwk-avmta-1.sfbay.Sun.COM> for
 LSARC-EXT@sun.com (ORCPT LSARC-EXT@sun.com); Mon,
 25 Aug 2008 06:07:01 -0700 (PDT)
Received: from fe-amer-09.sun.com ([192.18.109.79])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7PD71Ho017604	for
 <LSARC-EXT@sun.com>; Mon, 25 Aug 2008 13:07:01 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K6500901QPEET00@mail-amer.sun.com>
 (original mail from Brian.Cameron@Sun.COM)
 for LSARC-EXT@sun.com (ORCPT LSARC-EXT@sun.com); Mon,
 25 Aug 2008 07:07:01 -0600 (MDT)
Received: from [129.153.250.143] by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K65005JVR3F0550@mail-amer.sun.com> for LSARC-EXT@sun.com
 (ORCPT LSARC-EXT@sun.com); Mon, 25 Aug 2008 07:06:51 -0600 (MDT)
Date: Mon, 25 Aug 2008 08:07:01 -0500
From: Brian Cameron <Brian.Cameron@SUN.COM>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
	08/19/2008]
In-reply-to: <48B297B8.4090102@sun.com>
Sender: Brian.Cameron@SUN.COM
To: Henry Zhang <Hua.Zhang@SUN.COM>
Cc: Darren J Moffat <Darren.Moffat@SUN.COM>, LSARC-EXT@SUN.COM
Message-id: <48B2AE75.1030201@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com> <48A32E97.3090308@Sun.COM>
 <48A3EDA4.8090206@sun.com> <48A409AF.7050300@Sun.COM>
 <48A4FB69.3070909@sun.com> <48A54980.6030208@Sun.COM>
 <48A90414.6060707@sun.com> <48A93C53.6020006@Sun.COM>
 <48A94753.9000104@sun.com> <48A94C25.9040504@Sun.COM>
 <48A95984.8060107@sun.com> <48B297B8.4090102@sun.com>
User-Agent: Thunderbird 2.0.0.16 (X11/20080811)
Status: RO
Content-Length: 3473


Henry:

The one pager does not mention the ~/.gkrellm2/plugins-gkrellmd/
interface, nor does it mention that end users can install their own
plugins.

In section 4.1 you say:

        And in order to make install plugin, you should be root,
        and ensure the plugin will not add additional security issue.

The above seems a bit misleading since you can also install plugins
as users.  You don't need to be root.

In section 4.11, you say

         This application uses OpenSSL, and support plugins, it may cause
         some security concern,

It isn't clear if you are saying that there is some security concern
with OpenSSL or plugins, or both.  Is the security concern the same
or different for these two things?

         but generally all data transfered through the connection
         is the system usage status information, and not very
         confidential,

It is probably reasonable to say this for the default plugins, but
I'd think that an end user could install plugins that do not follow
this general rule.

         addtionally in order to make the network connection more secure,
         this application is using SSH and some configuration on IP/port
         to use,

Do you mean to say "this application uses SSH and allows the sysadmin
to specify which IP/port to use via configuration."   Are you suggesting
that being able to configure the IP/port adds security?  You misspell
"Additionally".

In general I find section 4.11 a little hard to read since it is one
long sentence.

Brian


> I would summary the discussion below.
> 
> 1, The battery support on Solaris:
> I investigated 2 solution, one is the  patch wrote by David, but this 
> patch is using acpidrv.h and /dev/acpidrv which are not on Solaris now, 
> the other solution is using HAL, I think this is a solution we can use.
> So I am implementing to use HAL/Dbus for the battery information.
> 
> 2, SSL certification authentication:
> I checked the bugzilla, and no category for GKrellM, I sent a mail to 
> the maintainer on this issue. I am discussing with him on how to fix 
> this problem..
> 
> 3, Security impact:
> Add some content to describe the possible impaction.
> 
> Attachment is the updated one-pager..
> 
> Thanks,
> Henry
> 
> Henry Zhang ??:
>> Hi Darren,
>>
>> Thanks, I will file a bug on this issue...
>>
>> Regards,
>> Henry
>>
>> Darren J Moffat ??:
>>> I see from the code that it is passing SSL_VERIFY_NONE to 
>>> SSL_CTX_set_verify()
>>>
>>>  From the man page:
>>>
>>>
>>>      SSL_VERIFY_NONE
>>>          Server mode: the server will not send a client
>>>          certificate request to the client, so the client will
>>>          not send a certificate.
>>>
>>>          Client mode: if not using an anonymous cipher (by
>>>          default disabled), the server will send a certificate
>>>          which will be checked. The result of the certificate
>>>          verification process can be checked after the TLS/SSL
>>>          handshake using the SSL_get_verify_result(3) function.
>>>          The handshake will be continued regardless of the
>>>          verification result.
>>>
>>>
>>> This is the answer for the case.  Personally I'm not happy with this 
>>> however it is what gkrellm does and it answers my question.  I would 
>>> like the project team to file a bug upstream (if there isn't one 
>>> already) to provide functionality to actually verify the server's 
>>> SSL/TLS certificate.
>>>
>>> -- 
>>> Darren J Moffat


From Hua.Zhang@sun.com Mon Aug 25 06:46:35 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7PDkYNu006444
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 25 Aug 2008 06:46:35 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m7PDkU0e017364
	for <@sunmail2sca.sfbay.sun.com:LSARC-EXT@sun.com>; Mon, 25 Aug 2008 21:46:34 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K6500E05SXLF800@nwk-avmta-2.sfbay.sun.com> for LSARC-EXT@sun.com
 (ORCPT LSARC-EXT@sun.com); Mon, 25 Aug 2008 06:46:33 -0700 (PDT)
Received: from sineb-mail-1.sun.com ([192.18.19.6])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K6500934SXJBW50@nwk-avmta-2.sfbay.sun.com> for
 LSARC-EXT@sun.com (ORCPT LSARC-EXT@sun.com); Mon,
 25 Aug 2008 06:46:32 -0700 (PDT)
Received: from fe-apac-05.sun.com
 (fe-apac-05.sun.com [192.18.19.176] (may be forged))
	by sineb-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7PDkVNJ001522	for
 <LSARC-EXT@sun.com>; Mon, 25 Aug 2008 13:46:31 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0K6500801SXB2Q00@mail-apac.sun.com> (original mail from Hua.Zhang@Sun.COM)
 for LSARC-EXT@sun.com (ORCPT LSARC-EXT@sun.com); Mon,
 25 Aug 2008 21:46:31 +0800 (SGT)
Received: from [129.158.217.156] by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0K65003B5SXIJPMK@mail-apac.sun.com> for LSARC-EXT@sun.com
 (ORCPT LSARC-EXT@sun.com); Mon, 25 Aug 2008 21:46:31 +0800 (SGT)
Date: Mon, 25 Aug 2008 21:50:51 +0800
From: Henry Zhang <Hua.Zhang@sun.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
	08/19/2008]
In-reply-to: <48B2AE75.1030201@sun.com>
Sender: Hua.Zhang@sun.com
To: Brian Cameron <Brian.Cameron@sun.com>
Cc: Darren J Moffat <Darren.Moffat@sun.com>, LSARC-EXT@sun.com
Message-id: <48B2B8BB.9010908@sun.com>
MIME-version: 1.0
Content-type: multipart/mixed; boundary="Boundary_(ID_4HV0uj9OPNVcaMICitG/jw)"
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com> <48A32E97.3090308@Sun.COM>
 <48A3EDA4.8090206@sun.com> <48A409AF.7050300@Sun.COM>
 <48A4FB69.3070909@sun.com> <48A54980.6030208@Sun.COM>
 <48A90414.6060707@sun.com> <48A93C53.6020006@Sun.COM>
 <48A94753.9000104@sun.com> <48A94C25.9040504@Sun.COM>
 <48A95984.8060107@sun.com> <48B297B8.4090102@sun.com>
 <48B2AE75.1030201@sun.com>
User-Agent: Thunderbird 2.0.0.6 (X11/20071119)
Status: RO
Content-Length: 14395

This is a multi-part message in MIME format.

--Boundary_(ID_4HV0uj9OPNVcaMICitG/jw)
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 8BIT

Brian,

Brian Cameron 写道:
> 
> Henry:
> 
> The one pager does not mention the ~/.gkrellm2/plugins-gkrellmd/
> interface, nor does it mention that end users can install their own
> plugins.
> 
> In section 4.1 you say:
> 
>        And in order to make install plugin, you should be root,
>        and ensure the plugin will not add additional security issue.
> 
> The above seems a bit misleading since you can also install plugins
> as users.  You don't need to be root.

That make sense, I added the content on the end-user plugin supports.
> 
> In section 4.11, you say
> 
>         This application uses OpenSSL, and support plugins, it may cause
>         some security concern,
> 
> It isn't clear if you are saying that there is some security concern
> with OpenSSL or plugins, or both.  Is the security concern the same
> or different for these two things?
> 
>         but generally all data transfered through the connection
>         is the system usage status information, and not very
>         confidential,
> 
> It is probably reasonable to say this for the default plugins, but
> I'd think that an end user could install plugins that do not follow
> this general rule.
> 
>         addtionally in order to make the network connection more secure,
>         this application is using SSH and some configuration on IP/port
>         to use,
> 
> Do you mean to say "this application uses SSH and allows the sysadmin
> to specify which IP/port to use via configuration."   Are you suggesting
> that being able to configure the IP/port adds security?  You misspell
> "Additionally".
> 
> In general I find section 4.11 a little hard to read since it is one
> long sentence.
I updated the one-pager, hope this make things more clear.

> 
> Brian
> 
> 
>> I would summary the discussion below.
>>
>> 1, The battery support on Solaris:
>> I investigated 2 solution, one is the  patch wrote by David, but this 
>> patch is using acpidrv.h and /dev/acpidrv which are not on Solaris 
>> now, the other solution is using HAL, I think this is a solution we 
>> can use.
>> So I am implementing to use HAL/Dbus for the battery information.
>>
>> 2, SSL certification authentication:
>> I checked the bugzilla, and no category for GKrellM, I sent a mail to 
>> the maintainer on this issue. I am discussing with him on how to fix 
>> this problem..
>>
>> 3, Security impact:
>> Add some content to describe the possible impaction.
>>
>> Attachment is the updated one-pager..
>>
>> Thanks,
>> Henry
>>
>> Henry Zhang ??:
>>> Hi Darren,
>>>
>>> Thanks, I will file a bug on this issue...
>>>
>>> Regards,
>>> Henry
>>>
>>> Darren J Moffat ??:
>>>> I see from the code that it is passing SSL_VERIFY_NONE to 
>>>> SSL_CTX_set_verify()
>>>>
>>>>  From the man page:
>>>>
>>>>
>>>>      SSL_VERIFY_NONE
>>>>          Server mode: the server will not send a client
>>>>          certificate request to the client, so the client will
>>>>          not send a certificate.
>>>>
>>>>          Client mode: if not using an anonymous cipher (by
>>>>          default disabled), the server will send a certificate
>>>>          which will be checked. The result of the certificate
>>>>          verification process can be checked after the TLS/SSL
>>>>          handshake using the SSL_get_verify_result(3) function.
>>>>          The handshake will be continued regardless of the
>>>>          verification result.
>>>>
>>>>
>>>> This is the answer for the case.  Personally I'm not happy with this 
>>>> however it is what gkrellm does and it answers my question.  I would 
>>>> like the project team to file a bug upstream (if there isn't one 
>>>> already) to provide functionality to actually verify the server's 
>>>> SSL/TLS certificate.
>>>>
>>>> -- 
>>>> Darren J Moffat
> 

--Boundary_(ID_4HV0uj9OPNVcaMICitG/jw)
Content-type: text/plain; name=one-pager-gkrellm.txt
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=one-pager-gkrellm.txt

Template Version: @(#)onepager.txt 1.29 04/11/15 SMI

1. Introduction

  1.1. Project/Component Working Name:

       GKrellM

  1.2. Name of Document Author/Supplier:

       Henry Zhang     (hua.zhang@sun.com)

  1.3. Date of This Document:

       30/07/08

  1.4. Name of Major Document Customer(s)/Consumer(s):

    1.4.1. The PAC or CPT you expect to review your project:

           Solaris PAC

    1.4.2. The ARC(s) you expect to review your project:

           LSARC

    1.4.3. The Director/VP who is "Sponsoring" this project:

           Robert.Odea@Sun.Com

    1.4.4. The name of your business unit:

           JDS Desktop Engineering, OPG

  1.5. Email Aliases:
       1.5.1. Responsible Manager:     leo.binchy@Sun.COM
       1.5.2. Responsible Engineer:    hua.zhang@Sun.COM
       1.5.3. Marketing Manager:       jeff.mcmeekin@sun.com
       1.5.4. Interest List:           gkrellm@sun.com

2. Project Summary

  2.1. Project Description:
        
       GKrellM, GNU (or Gtk) Krell Monitors (or Meters), is a single process 
       stack of system monitors which supports applying themes to match its 
       appearance to your window manager, Gtk, or any other theme. The current
       version is 2.3.1.

2.2. Risks and Assumptions:
    
    1. Temperature, fan, and voltage sensor monitors not support since missing
       libsensors.

    2. APM laptop battery meter not support since no APM, we will use HAL/DBus
       to implement this function.
    
    3. This application will depend on libgtop, which isn't engineered to fully
       or best support Solaris interfaces for getting system information because
       it was written from a more Linux perspective on system resources, and some
       system information can't get since not fully support from kernel, e.g. 
       some sensor monitor interfaces.

3. Business Summary

  3.1. Problem Area:

       GKrell is a computer program based on the GTK+ toolkit that creates a 
       single process stack of system monitors. It can be used to monitor the 
       status of CPUs, main memory, hard disks, network interfaces, local and 
       remote mailboxes, and many other things. Plugin is supported.

  3.2. Market/Requester:

       JDS Desktop group

  3.3. Business Justification:

       For many users, it's nice to be able to see, real-time, what is happening
       on their system. There are ways to display memory usage, cpu usage, network
       traffic, available and used disk space, and a whole lot of other similar 
       system statistics. This makes it easier to troubleshoot and notice problems
       as they come up. To be display these monitors, you will need gkrellm.

       It's a very useful monitoring tool, can replace a lots of the dock 
       applets, what's even better is that gkrellm supports a plugin interface,
       allowing vast expandability, it's also infinitely configurable and 
       themeable.

       Additionally Gkrellm is very easy on the CPU and packs a lot of information
       into a little bit of space. 

  3.4. Competitive Analysis:

       Windows XP has SysMetrix, Windows Vista has this type of side bar, 
       and GKrellM can run in Linux and other Unix-like operating systems.

  3.5. Opportunity Window/Exposure:

       It is expected that this project will be integrated into Nevada B100

       Note: this tool has GPL V3 license, it will not integrated into 
       Nevada until the license issue is solved.

  3.6. How will you know when you are done?:

       When it is ported to Nevada and runs correctly.  

       The project will be complete when there are no stoppers, P1 or P2 bugs.

4. Technical Description:

  4.1. Details:
       
       GKrellM is a GTK-based stacked monitor program that charts SMP CPUs, 
       disks, load, active net interfaces, and internet connections. There are
       also builtin monitors for memory and swap, file systems with mount/umount
       feature, mailbox checking including POP3 and IMAP, clock/calendar, laptop
       battery, sensors (temperatures, voltages, and fans), and uptime. It has 
       LEDs for the net monitors and an on/off button and online timer for PPP. 
       Multiple monitors managed by a single process to reduce system load.
       There is a GUI popup for configuration, plugin extensions can be installed, 
       and many themes are available. It also features a client/server monitoring 
       capability.

       If you want to configure GkrellM, you can right-click on the monitor and 
       select Configuration from the drop-down menu, or press the F1 key at  
       anytime while GKrellM has the focus. The configuration menu lets you 
       modify general options, built-in monitors, plug-ins, and themes.
       
       GKrellM consists of the gkrellm client and the gkrellmd server. Gkrellm can 
       run in client mode and collect data from gkrellmd server running on a remote
       machine. In this way, the user can remotely monitor different characteristics  
       of all the machines on their LAN, such as hits and load on the web server,  
       disk usage on the mail server, and port traffic on the NAT. 

       The gkrellm client gets data from gkrellmd through SSH. By default gkrellmd
       will not run by default, so the user need to start gkrellmd manually, 
       and optionally add options to configure gkrellmd.  For example,
       you can configure which port gkrellmd will use and which IP addresses or
       hostnames are allowed to connect to gkrellmd. gkrellm client will also be 
       configured to use some port, this port is used to create the SSH connection
       with the gkrellmd server given port. Then you can start gkrellm on another
       system and get the remote data from gkrellmd.
        
       Both gkrellm and the gkrellmd server are plugin capable so special interest
       monitors can be coded. In order to make install system plugin, 
       you should be root, also end-user can add their plugins, and ensure the 
       plugin will not add additional security issue.


  4.2. Bug/RFE Number(s):

        RFE 6732524

  4.3. In Scope:

       The system information we can get from Solaris 

  4.4. Out of Scope:

       The system information Solaris can't support, e.g. temperature.
       All plugins that are installed by users themselves.

   4.5. Interfaces:
    
      Imported Interfaces
      Interface               Stability    Comments
      -------------------     -----------  -----------------------------------

       /usr/lib/libkstat.so.1   Committed         standard library
       SUNWgettext              Uncommitted
       libgtop                  Volatile          LSARC/2006/347/
       libOpenSSL               Contract Private  PSARC/2006/019/ 
       GNOME Committed Platform Libraries Committed LSARC/2007/520 GTK+ library
                                                        GNOME 2.20 

      Exported Interfaces        Stability      Comments
      -------------------------  -------------  ---------------------------------

       /usr/bin/gkrellm          Volatile       
       SUNWgkrellm               Uncommitted    Package name
       SUNWgkrellm-devel         Uncommitted    Package name
       /usr/include/gkrellm2/gkrellm.h    Project Private
       /usr/lib/gkrellm2/plugins         Project Private  Store system plugins
       $HOME/.gkrellm2/plugins-gkrellmd/ Project Private  Store server plugin
       $HOME/.gkrellm2/plugins/          Project Private  Store end-user plugin

  4.6. Doc Impact:

       Man page will need to be added

  4.7. Admin/Config Impact:

       There are no changes to the system administration and configuration. 

  4.8. HA Impact:

       N/A

  4.9. I18N/L10N Impact:

       The JDS team and the G11N are working together to evaluate and provide
       I18N/L10N support.
       

  4.10. Packaging & Delivery:

        The new packages are:

              -  SUNWgkrellm
              -  SUNWgkrellm-devel 

  4.11. Security Impact:

        This application uses OpenSSL, and support plugins, both of them may cause 
        some security concern. By default all data transfered through the 
        connection is the system usage status information, not very confidential.
        but if end-user add some plugins, it may send out some critical data.
        In order to make the network connection more secure, user can use SSH to 
        setup the connection between gdrellmd server and gkrellm client, and 
        identify which IP/port they will use, see 4.1 for details. 

  4.12. Dependencies:

        SUNWgettext.spec
        Gtk+ 2.0 >= 2.0 
        gdk 2.0
        glib 2.0 >= 2.0
        libgtop
        libssl

5. Reference Documents:

   GKrellM main project page:   
        http://gkrellm.net

   GKrellM Wiki:
        http://en.wikipedia.org/wiki/GKrellM

   GKrellM themes site:
        http://www.muhri.net/gkrellm/


6. Resources and Schedule:

  6.1. Projected Availability:
       
       Expect to integrated into Nevada in build 100 in Q3 2008

  6.2. Cost of Effort:

       Development     1.0 Engineers - 1 Months
       Testing         0.5 Engineers - 1 Week
       RE              0.5 Engineers - 1 Week

  6.3. Cost of Capital Resources:

       N/A

  6.4. Product Approval Committee requested information:

       6.4.1. Consolidation or Component Name:

              JDS / OpenSolaris
 
       6.4.3. Type of CPT Review and Approval expected:

              Standard

       6.4.4. Project Boundary Conditions:

              None

       6.4.5. Is this a necessary project for OEM agreements:

              No

       6.4.6. Notes:

              N/A

       6.4.7. Target RTI Date/Release:

              Nevada B100 - Sep. 2008

       6.4.8. Target Code Design Review Date:

              Sep. 2008

       6.4.9. Update approval addition:

              New project, no Solaris PAC approval yet

  6.5. ARC review type:

       FastTrack

7. Prototype Availability:

  7.1. Prototype Availability:

       Sep. 2008   

  7.2. Prototype Cost:

       1 engineer
       1 QA
       1 RE

--Boundary_(ID_4HV0uj9OPNVcaMICitG/jw)--

From Brian.Cameron@Sun.COM Mon Aug 25 06:52:10 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7PDqArP006608
	for <LSARC-ext@sac.sfbay.sun.com>; Mon, 25 Aug 2008 06:52:10 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m7PDq7xO034145
	for <@sunmail2sca.sfbay.sun.com:LSARC-EXT@sun.com>; Mon, 25 Aug 2008 07:52:10 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K6500903T6XNY00@nwk-avmta-1.sfbay.Sun.COM> for LSARC-EXT@sun.com
 (ORCPT LSARC-EXT@sun.com); Mon, 25 Aug 2008 06:52:09 -0700 (PDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K65005RST6WVX20@nwk-avmta-1.sfbay.Sun.COM> for
 LSARC-EXT@sun.com (ORCPT LSARC-EXT@sun.com); Mon,
 25 Aug 2008 06:52:08 -0700 (PDT)
Received: from fe-amer-09.sun.com ([192.18.109.79])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7PDq8GH006918	for
 <LSARC-EXT@sun.com>; Mon, 25 Aug 2008 13:52:08 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K6500701STEAU00@mail-amer.sun.com>
 (original mail from Brian.Cameron@Sun.COM)
 for LSARC-EXT@sun.com (ORCPT LSARC-EXT@sun.com); Mon,
 25 Aug 2008 07:52:08 -0600 (MDT)
Received: from [129.153.250.143] by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K6500503T6M05G0@mail-amer.sun.com> for LSARC-EXT@sun.com
 (ORCPT LSARC-EXT@sun.com); Mon, 25 Aug 2008 07:51:59 -0600 (MDT)
Date: Mon, 25 Aug 2008 08:52:08 -0500
From: Brian Cameron <Brian.Cameron@Sun.COM>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
	08/19/2008]
In-reply-to: <48B2B8BB.9010908@sun.com>
Sender: Brian.Cameron@Sun.COM
To: Henry Zhang <Hua.Zhang@Sun.COM>
Cc: Darren J Moffat <Darren.Moffat@Sun.COM>, LSARC-EXT@Sun.COM
Message-id: <48B2B908.7010608@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 8BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com> <48A32E97.3090308@Sun.COM>
 <48A3EDA4.8090206@sun.com> <48A409AF.7050300@Sun.COM>
 <48A4FB69.3070909@sun.com> <48A54980.6030208@Sun.COM>
 <48A90414.6060707@sun.com> <48A93C53.6020006@Sun.COM>
 <48A94753.9000104@sun.com> <48A94C25.9040504@Sun.COM>
 <48A95984.8060107@sun.com> <48B297B8.4090102@sun.com>
 <48B2AE75.1030201@sun.com> <48B2B8BB.9010908@sun.com>
User-Agent: Thunderbird 2.0.0.16 (X11/20080811)
Status: RO
Content-Length: 3913


Henry:

Much more clear.  Thanks.

Brian


> Brian Cameron 写道:
>>
>> Henry:
>>
>> The one pager does not mention the ~/.gkrellm2/plugins-gkrellmd/
>> interface, nor does it mention that end users can install their own
>> plugins.
>>
>> In section 4.1 you say:
>>
>>        And in order to make install plugin, you should be root,
>>        and ensure the plugin will not add additional security issue.
>>
>> The above seems a bit misleading since you can also install plugins
>> as users.  You don't need to be root.
> 
> That make sense, I added the content on the end-user plugin supports.
>>
>> In section 4.11, you say
>>
>>         This application uses OpenSSL, and support plugins, it may cause
>>         some security concern,
>>
>> It isn't clear if you are saying that there is some security concern
>> with OpenSSL or plugins, or both.  Is the security concern the same
>> or different for these two things?
>>
>>         but generally all data transfered through the connection
>>         is the system usage status information, and not very
>>         confidential,
>>
>> It is probably reasonable to say this for the default plugins, but
>> I'd think that an end user could install plugins that do not follow
>> this general rule.
>>
>>         addtionally in order to make the network connection more secure,
>>         this application is using SSH and some configuration on IP/port
>>         to use,
>>
>> Do you mean to say "this application uses SSH and allows the sysadmin
>> to specify which IP/port to use via configuration."   Are you suggesting
>> that being able to configure the IP/port adds security?  You misspell
>> "Additionally".
>>
>> In general I find section 4.11 a little hard to read since it is one
>> long sentence.
> I updated the one-pager, hope this make things more clear.
> 
>>
>> Brian
>>
>>
>>> I would summary the discussion below.
>>>
>>> 1, The battery support on Solaris:
>>> I investigated 2 solution, one is the  patch wrote by David, but this 
>>> patch is using acpidrv.h and /dev/acpidrv which are not on Solaris 
>>> now, the other solution is using HAL, I think this is a solution we 
>>> can use.
>>> So I am implementing to use HAL/Dbus for the battery information.
>>>
>>> 2, SSL certification authentication:
>>> I checked the bugzilla, and no category for GKrellM, I sent a mail to 
>>> the maintainer on this issue. I am discussing with him on how to fix 
>>> this problem..
>>>
>>> 3, Security impact:
>>> Add some content to describe the possible impaction.
>>>
>>> Attachment is the updated one-pager..
>>>
>>> Thanks,
>>> Henry
>>>
>>> Henry Zhang ??:
>>>> Hi Darren,
>>>>
>>>> Thanks, I will file a bug on this issue...
>>>>
>>>> Regards,
>>>> Henry
>>>>
>>>> Darren J Moffat ??:
>>>>> I see from the code that it is passing SSL_VERIFY_NONE to 
>>>>> SSL_CTX_set_verify()
>>>>>
>>>>>  From the man page:
>>>>>
>>>>>
>>>>>      SSL_VERIFY_NONE
>>>>>          Server mode: the server will not send a client
>>>>>          certificate request to the client, so the client will
>>>>>          not send a certificate.
>>>>>
>>>>>          Client mode: if not using an anonymous cipher (by
>>>>>          default disabled), the server will send a certificate
>>>>>          which will be checked. The result of the certificate
>>>>>          verification process can be checked after the TLS/SSL
>>>>>          handshake using the SSL_get_verify_result(3) function.
>>>>>          The handshake will be continued regardless of the
>>>>>          verification result.
>>>>>
>>>>>
>>>>> This is the answer for the case.  Personally I'm not happy with 
>>>>> this however it is what gkrellm does and it answers my question.  I 
>>>>> would like the project team to file a bug upstream (if there isn't 
>>>>> one already) to provide functionality to actually verify the 
>>>>> server's SSL/TLS certificate.
>>>>>
>>>>> -- 
>>>>> Darren J Moffat
>>


From Irene.Huang@sun.com Tue Aug 26 19:10:00 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m7R29xW6020294
	for <LSARC-ext@sac.sfbay.sun.com>; Tue, 26 Aug 2008 19:10:00 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m7R29je1000162
	for <@sunmail2sca.sfbay.sun.com:LSARC-EXT@sun.com>; Wed, 27 Aug 2008 10:09:58 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K6800K01M0MC300@nwk-avmta-1.sfbay.Sun.COM> for LSARC-EXT@sun.com
 (ORCPT LSARC-EXT@sun.com); Tue, 26 Aug 2008 19:09:58 -0700 (PDT)
Received: from sineb-mail-2.sun.com ([192.18.19.7])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K680065XM0L5WC0@nwk-avmta-1.sfbay.Sun.COM> for
 LSARC-EXT@sun.com (ORCPT LSARC-EXT@sun.com); Tue,
 26 Aug 2008 19:09:58 -0700 (PDT)
Received: from fe-apac-05.sun.com
 (fe-apac-05.sun.com [192.18.19.176] (may be forged))
	by sineb-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m7R29uHQ013022	for
 <LSARC-EXT@sun.com>; Wed, 27 Aug 2008 02:09:56 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0K6800F01LV8QO00@mail-apac.sun.com>
 (original mail from Irene.Huang@Sun.COM)
 for LSARC-EXT@sun.com (ORCPT LSARC-EXT@sun.com); Wed,
 27 Aug 2008 10:09:56 +0800 (SGT)
Received: from [129.158.217.63] by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0K680036GM0JJPJO@mail-apac.sun.com> for LSARC-EXT@sun.com
 (ORCPT LSARC-EXT@sun.com); Wed, 27 Aug 2008 10:09:56 +0800 (SGT)
Date: Wed, 27 Aug 2008 10:09:55 +0800
From: Irene Huang <Irene.Huang@sun.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
	08/19/2008]
In-reply-to: <48B2B908.7010608@sun.com>
Sender: Irene.Huang@sun.com
To: Brian Cameron <Brian.Cameron@sun.com>
Cc: Henry Zhang <Hua.Zhang@sun.com>, Darren J Moffat <Darren.Moffat@sun.com>,
        LSARC-EXT@sun.com
Message-id: <48B4B773.6060307@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 8BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com> <48A32E97.3090308@Sun.COM>
 <48A3EDA4.8090206@sun.com> <48A409AF.7050300@Sun.COM>
 <48A4FB69.3070909@sun.com> <48A54980.6030208@Sun.COM>
 <48A90414.6060707@sun.com> <48A93C53.6020006@Sun.COM>
 <48A94753.9000104@sun.com> <48A94C25.9040504@Sun.COM>
 <48A95984.8060107@sun.com> <48B297B8.4090102@sun.com>
 <48B2AE75.1030201@sun.com> <48B2B8BB.9010908@sun.com>
 <48B2B908.7010608@sun.com>
User-Agent: Thunderbird 2.0.0.16 (Windows/20080708)
Status: RO
Content-Length: 4205

Hi, all

I am resetting the time out for this case to be August 29th.
Any issues please send an email before then.

Thanks

--Irene

Brian Cameron wrote:
>
> Henry:
>
> Much more clear.  Thanks.
>
> Brian
>
>
>> Brian Cameron 写道:
>>>
>>> Henry:
>>>
>>> The one pager does not mention the ~/.gkrellm2/plugins-gkrellmd/
>>> interface, nor does it mention that end users can install their own
>>> plugins.
>>>
>>> In section 4.1 you say:
>>>
>>>        And in order to make install plugin, you should be root,
>>>        and ensure the plugin will not add additional security issue.
>>>
>>> The above seems a bit misleading since you can also install plugins
>>> as users.  You don't need to be root.
>>
>> That make sense, I added the content on the end-user plugin supports.
>>>
>>> In section 4.11, you say
>>>
>>>         This application uses OpenSSL, and support plugins, it may 
>>> cause
>>>         some security concern,
>>>
>>> It isn't clear if you are saying that there is some security concern
>>> with OpenSSL or plugins, or both.  Is the security concern the same
>>> or different for these two things?
>>>
>>>         but generally all data transfered through the connection
>>>         is the system usage status information, and not very
>>>         confidential,
>>>
>>> It is probably reasonable to say this for the default plugins, but
>>> I'd think that an end user could install plugins that do not follow
>>> this general rule.
>>>
>>>         addtionally in order to make the network connection more 
>>> secure,
>>>         this application is using SSH and some configuration on IP/port
>>>         to use,
>>>
>>> Do you mean to say "this application uses SSH and allows the sysadmin
>>> to specify which IP/port to use via configuration."   Are you 
>>> suggesting
>>> that being able to configure the IP/port adds security?  You misspell
>>> "Additionally".
>>>
>>> In general I find section 4.11 a little hard to read since it is one
>>> long sentence.
>> I updated the one-pager, hope this make things more clear.
>>
>>>
>>> Brian
>>>
>>>
>>>> I would summary the discussion below.
>>>>
>>>> 1, The battery support on Solaris:
>>>> I investigated 2 solution, one is the  patch wrote by David, but 
>>>> this patch is using acpidrv.h and /dev/acpidrv which are not on 
>>>> Solaris now, the other solution is using HAL, I think this is a 
>>>> solution we can use.
>>>> So I am implementing to use HAL/Dbus for the battery information.
>>>>
>>>> 2, SSL certification authentication:
>>>> I checked the bugzilla, and no category for GKrellM, I sent a mail 
>>>> to the maintainer on this issue. I am discussing with him on how to 
>>>> fix this problem..
>>>>
>>>> 3, Security impact:
>>>> Add some content to describe the possible impaction.
>>>>
>>>> Attachment is the updated one-pager..
>>>>
>>>> Thanks,
>>>> Henry
>>>>
>>>> Henry Zhang ??:
>>>>> Hi Darren,
>>>>>
>>>>> Thanks, I will file a bug on this issue...
>>>>>
>>>>> Regards,
>>>>> Henry
>>>>>
>>>>> Darren J Moffat ??:
>>>>>> I see from the code that it is passing SSL_VERIFY_NONE to 
>>>>>> SSL_CTX_set_verify()
>>>>>>
>>>>>>  From the man page:
>>>>>>
>>>>>>
>>>>>>      SSL_VERIFY_NONE
>>>>>>          Server mode: the server will not send a client
>>>>>>          certificate request to the client, so the client will
>>>>>>          not send a certificate.
>>>>>>
>>>>>>          Client mode: if not using an anonymous cipher (by
>>>>>>          default disabled), the server will send a certificate
>>>>>>          which will be checked. The result of the certificate
>>>>>>          verification process can be checked after the TLS/SSL
>>>>>>          handshake using the SSL_get_verify_result(3) function.
>>>>>>          The handshake will be continued regardless of the
>>>>>>          verification result.
>>>>>>
>>>>>>
>>>>>> This is the answer for the case.  Personally I'm not happy with 
>>>>>> this however it is what gkrellm does and it answers my question.  
>>>>>> I would like the project team to file a bug upstream (if there 
>>>>>> isn't one already) to provide functionality to actually verify 
>>>>>> the server's SSL/TLS certificate.
>>>>>>
>>>>>> -- 
>>>>>> Darren J Moffat
>>>
>


From Irene.Huang@sun.com Sun Aug 31 19:33:13 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m812XCc4018175
	for <LSARC-ext@sac.sfbay.sun.com>; Sun, 31 Aug 2008 19:33:12 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m812X8f1025725
	for <@sunmail2sca.sfbay.sun.com:LSARC-EXT@sun.com>; Mon, 1 Sep 2008 03:33:11 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K6H00B01WFABW00@brm-avmta-1.central.sun.com> for LSARC-EXT@sun.com
 (ORCPT LSARC-EXT@sun.com); Sun, 31 Aug 2008 20:33:10 -0600 (MDT)
Received: from sineb-mail-1.sun.com ([192.18.19.6])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K6H001RIWF8WJ60@brm-avmta-1.central.sun.com> for
 LSARC-EXT@sun.com (ORCPT LSARC-EXT@sun.com); Sun,
 31 Aug 2008 20:33:09 -0600 (MDT)
Received: from fe-apac-06.sun.com
 (fe-apac-06.sun.com [192.18.19.177] (may be forged))
	by sineb-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m812X7hd015594	for
 <LSARC-EXT@sun.com>; Mon, 01 Sep 2008 02:33:07 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0K6H00M01WBM2K00@mail-apac.sun.com>
 (original mail from Irene.Huang@Sun.COM)
 for LSARC-EXT@sun.com (ORCPT LSARC-EXT@sun.com); Mon,
 01 Sep 2008 10:33:07 +0800 (SGT)
Received: from [129.158.217.63] by mail-apac.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0K6H00B4ZWF6REO9@mail-apac.sun.com> for LSARC-EXT@sun.com
 (ORCPT LSARC-EXT@sun.com); Mon, 01 Sep 2008 10:33:07 +0800 (SGT)
Date: Mon, 01 Sep 2008 10:33:04 +0800
From: Irene Huang <Irene.Huang@sun.com>
Subject: Re: Gkrellm for OpenSolaris [LSARC/2008/513 FastTrack timeout
	08/19/2008]
In-reply-to: <48B4B773.6060307@sun.com>
Sender: Irene.Huang@sun.com
To: Irene Huang <Irene.Huang@sun.com>
Cc: Brian Cameron <Brian.Cameron@sun.com>, Henry Zhang <Hua.Zhang@sun.com>,
        Darren J Moffat <Darren.Moffat@sun.com>, lsarc-ext@sun.com
Message-id: <48BB5460.4070505@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=UTF-8
Content-transfer-encoding: 8BIT
X-PMX-Version: 5.4.1.325704
References: <200808120649.m7C6nmwB004728@sac.sfbay.sun.com>
 <48A21533.7020806@sun.com> <48A2A74C.80905@sun.com> <48A32E97.3090308@Sun.COM>
 <48A3EDA4.8090206@sun.com> <48A409AF.7050300@Sun.COM>
 <48A4FB69.3070909@sun.com> <48A54980.6030208@Sun.COM>
 <48A90414.6060707@sun.com> <48A93C53.6020006@Sun.COM>
 <48A94753.9000104@sun.com> <48A94C25.9040504@Sun.COM>
 <48A95984.8060107@sun.com> <48B297B8.4090102@sun.com>
 <48B2AE75.1030201@sun.com> <48B2B8BB.9010908@sun.com>
 <48B2B908.7010608@sun.com> <48B4B773.6060307@sun.com>
User-Agent: Thunderbird 2.0.0.16 (Windows/20080708)
Status: RO
Content-Length: 4447

Hi, all

This case has pass timeout. I am closing it as approved.

--Irene
Irene Huang wrote:
> Hi, all
>
> I am resetting the time out for this case to be August 29th.
> Any issues please send an email before then.
>
> Thanks
>
> --Irene
>
> Brian Cameron wrote:
>>
>> Henry:
>>
>> Much more clear.  Thanks.
>>
>> Brian
>>
>>
>>> Brian Cameron 写道:
>>>>
>>>> Henry:
>>>>
>>>> The one pager does not mention the ~/.gkrellm2/plugins-gkrellmd/
>>>> interface, nor does it mention that end users can install their own
>>>> plugins.
>>>>
>>>> In section 4.1 you say:
>>>>
>>>>        And in order to make install plugin, you should be root,
>>>>        and ensure the plugin will not add additional security issue.
>>>>
>>>> The above seems a bit misleading since you can also install plugins
>>>> as users.  You don't need to be root.
>>>
>>> That make sense, I added the content on the end-user plugin supports.
>>>>
>>>> In section 4.11, you say
>>>>
>>>>         This application uses OpenSSL, and support plugins, it may 
>>>> cause
>>>>         some security concern,
>>>>
>>>> It isn't clear if you are saying that there is some security concern
>>>> with OpenSSL or plugins, or both.  Is the security concern the same
>>>> or different for these two things?
>>>>
>>>>         but generally all data transfered through the connection
>>>>         is the system usage status information, and not very
>>>>         confidential,
>>>>
>>>> It is probably reasonable to say this for the default plugins, but
>>>> I'd think that an end user could install plugins that do not follow
>>>> this general rule.
>>>>
>>>>         addtionally in order to make the network connection more 
>>>> secure,
>>>>         this application is using SSH and some configuration on 
>>>> IP/port
>>>>         to use,
>>>>
>>>> Do you mean to say "this application uses SSH and allows the sysadmin
>>>> to specify which IP/port to use via configuration."   Are you 
>>>> suggesting
>>>> that being able to configure the IP/port adds security?  You misspell
>>>> "Additionally".
>>>>
>>>> In general I find section 4.11 a little hard to read since it is one
>>>> long sentence.
>>> I updated the one-pager, hope this make things more clear.
>>>
>>>>
>>>> Brian
>>>>
>>>>
>>>>> I would summary the discussion below.
>>>>>
>>>>> 1, The battery support on Solaris:
>>>>> I investigated 2 solution, one is the  patch wrote by David, but 
>>>>> this patch is using acpidrv.h and /dev/acpidrv which are not on 
>>>>> Solaris now, the other solution is using HAL, I think this is a 
>>>>> solution we can use.
>>>>> So I am implementing to use HAL/Dbus for the battery information.
>>>>>
>>>>> 2, SSL certification authentication:
>>>>> I checked the bugzilla, and no category for GKrellM, I sent a mail 
>>>>> to the maintainer on this issue. I am discussing with him on how 
>>>>> to fix this problem..
>>>>>
>>>>> 3, Security impact:
>>>>> Add some content to describe the possible impaction.
>>>>>
>>>>> Attachment is the updated one-pager..
>>>>>
>>>>> Thanks,
>>>>> Henry
>>>>>
>>>>> Henry Zhang ??:
>>>>>> Hi Darren,
>>>>>>
>>>>>> Thanks, I will file a bug on this issue...
>>>>>>
>>>>>> Regards,
>>>>>> Henry
>>>>>>
>>>>>> Darren J Moffat ??:
>>>>>>> I see from the code that it is passing SSL_VERIFY_NONE to 
>>>>>>> SSL_CTX_set_verify()
>>>>>>>
>>>>>>>  From the man page:
>>>>>>>
>>>>>>>
>>>>>>>      SSL_VERIFY_NONE
>>>>>>>          Server mode: the server will not send a client
>>>>>>>          certificate request to the client, so the client will
>>>>>>>          not send a certificate.
>>>>>>>
>>>>>>>          Client mode: if not using an anonymous cipher (by
>>>>>>>          default disabled), the server will send a certificate
>>>>>>>          which will be checked. The result of the certificate
>>>>>>>          verification process can be checked after the TLS/SSL
>>>>>>>          handshake using the SSL_get_verify_result(3) function.
>>>>>>>          The handshake will be continued regardless of the
>>>>>>>          verification result.
>>>>>>>
>>>>>>>
>>>>>>> This is the answer for the case.  Personally I'm not happy with 
>>>>>>> this however it is what gkrellm does and it answers my 
>>>>>>> question.  I would like the project team to file a bug upstream 
>>>>>>> (if there isn't one already) to provide functionality to 
>>>>>>> actually verify the server's SSL/TLS certificate.
>>>>>>>
>>>>>>> -- 
>>>>>>> Darren J Moffat
>>>>
>>
>


