From bc99092@sac.sfbay.sun.com Wed May 20 13:58:38 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n4KKwcAk011115
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 20 May 2009 13:58:38 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n4KKwZX2008792;
	Wed, 20 May 2009 13:58:38 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJY00C0RNLOFG00@brm-avmta-1.central.sun.com>; Wed,
 20 May 2009 14:58:36 -0600 (MDT)
Received: from dm-sfbay-02.sfbay.sun.com ([129.146.11.31])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJY00FTBNLNH0D0@brm-avmta-1.central.sun.com>; Wed,
 20 May 2009 14:58:35 -0600 (MDT)
Received: from sac.sfbay.sun.com (sac.SFBay.Sun.COM [129.146.226.132])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n4KKwZTK041053; Wed, 20 May 2009 13:58:35 -0700 (PDT)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n4KKwY0Z011110; Wed,
 20 May 2009 13:58:34 -0700 (PDT)
Received: (from bc99092@localhost)
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit) id n4KKwYjd011106; Wed,
 20 May 2009 13:58:34 -0700 (PDT)
Date: Wed, 20 May 2009 13:58:34 -0700 (PDT)
From: Brian Cameron <bc99092@sac.sfbay.sun.com>
Subject: Jokosher [LSARC/2009/314 FastTrack timeout 06/02/2009]
To: LSARC-ext@sun.com
Cc: desktop-discuss@opensolaris.org
Message-id: <200905202058.n4KKwYjd011106@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 10791


Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
This information is Copyright 2009 Sun Microsystems
1. Introduction
    1.1. Project/Component Working Name:
	 Jokosher
    1.2. Name of Document Author/Supplier:
	 Author:  Brian Cameron
    1.3  Date of This Document:
	20 May, 2009
4. Technical Description
Template Version: @(#)sac_nextcase %I% %G% SMI
This information is Copyright 2008 Sun Microsystems

1. Introduction
   1.1. Project/Component Working Name:

        jokosher

   1.2. Name of Document Author/Supplier:

        Author:  Brian Cameron

   1.3  Date of This Document:

        12 May 2009

   1.4. Name of Major Document Customer(s)/Consumer(s):
        1.4.1. The PAC or CPT you expect to review your project:

               Solaris PAC

        1.4.2. The ARC(s) you expect to review your project:

               LSARC

        1.4.3. The Director/VP who is "Sponsoring" this project:

               Robert O'Dea

        1.4.4. The name of your business unit:

               Software - OPG

   1.5. Email Aliases:
        1.5.1. Responsible Manager: 

               leo.binchy@sun.com

        1.5.2. Responsible Engineer:

               brian.cameron@sun.com

        1.5.3  Marketing Manager:

               glynn.foster@sun.com

        1.5.4. Interest List: 

               desktop-discuss@opensolaris.org 

2. Project Summary
   2.1. Project Description:

        jokosher is a simple, yet powerful multi-track studio written in Python
        that uses GStreamer and gnonlin.  With jokosher you can create and
        record music, podcasts and more, all from an integrated simple
        environment.  It supports recording, editing (e.g. splitting, trimming,
        moving), mixing, and exporting audio.  It supports all audio formats
        that are supported by GStreamer.  Users can, for example, purchase
        plugins from Fluendo to enable MP3 or WindowsMedia Audio support.

        jokosher uses the GPL license and contains a license exception which
        allows distribution with non-free GStreamer-plugins.

4. Technical Description:
   4.1. Details:

        Jokosher provides a multi-track interface for recording and mixing
        audio.  Jokosher supports two workspace modes: the Recording Workspace
        and the Mixing Workspace.  The user simply toggles between the two
        modes by clicking on the "Audio Mixers" button in the toolbar.

        When in the Recording Workspace mode, the user may create multiple
        audio tracks.  The tracks may either be an existing audio file which
        the user can specify, or be an instrument.  The instrument setting is
        intended to be used when the user intends to record the track into
        jokosher.  

        Jokosher provides a set of Instrument files, which simply specify a
        label and an icon for the instrument.  When a track is associated with
        an instrument then the track is shown with this label and icon so that
        the user can easily determine what instrument is associated with each
        track.

        When in the Mixing Workspace mode the user can specify the volume level
        and balance setting for each track.  Once the mix is specified, then
        the user can use jokosher's "Mixdown" feature to save the final audio
        mix to a file in the desired audio format.  The Mixdown dialog also
        allows the user to run user-specified scripts to do any desired actions
        once the mix is completed, such as to upload the file to a server or to
        create a playlist.

        Jokosher projects can be saved in a file format with the extension
        ".jokosher".  When reloaded, the track and mixing settings and all
        preferences are restored so a user can continue working on a project.
        These files are associated with the MIME type "application/x-jokosher".

        Jokosher provides extensions which allow third party developers to add
        features to Jokosher to make it support file types or support 
        additional functionality.  Jokosher includes an extensions manager
        which allows users to add, remove, or configure extensions. [1]

        By default jokosher includes the following extensions:

        - A "Set Tempo" extension which allows the user to set the tempo for
          a project by clicking on a button on each beat during playback.
        - A "Minimal Mode" extension which changes the UI to a minimal
          appearance
        - An "Instrument Type Manager" extension which allows the user to 
          specify the label and icon for new instruments, and to delete any
          previously added instruments.
        - A "Search FreeSound" extension which will search the FreeSound
          library of freely licensable and usable sound clips.  The FreeSound
          library can be found at http://www.freesound.org/.
        - An "Extension Console" which provides a fully functional python
          console with access to the jokosher extension API and jokosher
          internals.  Useful for writing or debugging extension code.
        - A "Jokosher D-Bus API" extension which allows other processes to 
          call Jokosher extension API functions via D-Bus.

        Note that, by default, the jokosher FreeSound extension saves the
        user's FreeSound username and password in plaintext in the user's
        jokosher $HOME configuration.  When the plugin is used after initial
        login, the username and password values are filled in for the user.

        However, on Solaris, we will patch the code so that this feature is
        disabled, and the FreeSound extension will not save the username and
        password information to the user's $HOME directory.  This will mean
        the user will need to re-enter this information each time they restart
        jokosher and wish to use this plugin.
          
   4.2. Interfaces:
        
      Exported Interfaces                          Stability   Comments
      -------------------------------------------  ----------  ----------------

      /usr/bin/jokosher                            Volatile     Jokosher
                                                                application.
      /usr/lib/python2.6/vendor-packages/Jokosher  Volatile     Jokosher python
                                                                implementation.
      /usr/share/applications/jokosher.desktop     Volatile     Jokosher desktop
                                                                file.
      /usr/share/gnome/help/jokosher               Volatile     Jokosher help
                                                                files.
      /usr/share/jokosher                          Volatile     Jokosher
                                                                internal data.
      /usr/share/jokosher/Instruments              Volatile     Jokosher
                                                                instrument
                                                                files.
      /usr/share/jokosher/extensions               Volatile     Jokosher
                                                                extension files.
      /usr/share/jokosher/pixmaps                  Project      Jokosher image
                                                   Private      files.
      /usr/share/icons/hicolor/48x48/apps/jokosher.png         
                                                   Project      Jokosher
                                                   Private      application
                                                                image.
      /usr/share/pixmaps/jokosher.png              Project      Jokosher
                                                   Private      application
                                                                image.
      /usr/share/mime/packages/jokosher.xml        Volatile     Specifies the
                                                                MIME type for
                                                                jokosher files.
      /usr/share/omf/jokosher                      Project      Jokosher OMF 
                                                   Private      files.
      $HOME/.local/share/jokosher                  Volatile     Jokosher user
                                                                configuration

      SUNWgnonlin                                  Uncommitted  Package.
      SUNWjokosher                                 Uncommitted  Package.

 
      Imported Interfaces    Stability          Comments
      ---------------        ---------------    -----------------------
      GNOME Base Libraries   Committed          LSARC 2006/202
      GStreamer              Volatile           LSARC/2006/202
      GNonLin                Volatile           Not yet filed
      Python                 External           PSARC/2005/532  Python
                             Evolving           Migration from /usr/sfw 
                                                to /usr and upgrade to v2.4.x
      gst-python             Volatile           LSARC 2008/105
      Pygtk, gnome-python    Unstable           LSARC 2005/506
      D-Bus                  Volatile           LSARC 2006/368
      Python Setuptools      Uncommitted        PSARC 2008/084

   4.3. Doc Impact:

        jokosher includes Help documentation.  Jokosher does not ship with any
        developer documentation, but the help files do point to the Jokosher
        developer webiste for more information about doing things like writing
        extensions.

   4.4. Packaging & Delivery:
        
        SUNWjokosher - jokosher application.

   4.5. Dependencies:

        The ARC case for GNonLin, which is being submitted at the same time
        as this case.  I will update this section and the Comments value for
        GNonLin in the Imported Interface table to include the ARC number
        when available.

   4.6. L10N Impact:

        The Desktop team and the G11N are working together to evaluate and
        provide I18N/L10N support.

   4.7 Security Impact:

       None.
       
5. Reference Documents:

       [1] Jokosher Extensions Documentation
       http://userdocs.jokosher.org/Extensions/

       Jokosher Website and User Documentation:
       http://www.jokosher.org/
       http://userdocs.jokosher.org/

6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		Desktop
    6.5. ARC review type: FastTrack
    6.6. ARC Exposure: open


6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		Desktop
    6.5. ARC review type: FastTrack
    6.6. ARC Exposure: open


From Halton.Huo@sun.com Wed May 20 20:56:38 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n4L3ubi9013031
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 20 May 2009 20:56:38 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n4L3uLuq018035
	for <@sunmail2sca.sfbay.sun.com:LSARC-ext@sun.com>; Thu, 21 May 2009 11:56:36 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJZ00M036YBA100@nwk-avmta-2.sfbay.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Wed, 20 May 2009 20:56:35 -0700 (PDT)
Received: from sineb-mail-2.sun.com ([192.18.19.7])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJZ00ECW6Y9UO50@nwk-avmta-2.sfbay.sun.com> for
 LSARC-ext@sun.com (ORCPT LSARC-ext@sun.com); Wed,
 20 May 2009 20:56:35 -0700 (PDT)
Received: from fe-apac-05.sun.com
 (fe-apac-05.sun.com [192.18.19.176] (may be forged))
	by sineb-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n4L3uXjK021388	for
 <LSARC-ext@sun.com>; Thu, 21 May 2009 03:56:33 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KJZ00I006PR3H00@mail-apac.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Thu, 21 May 2009 11:56:33 +0800 (SGT)
Received: from [129.158.217.237] ([unknown] [129.158.217.237])
 by mail-apac.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 with ESMTPSA id <0KJZ00GIN6Y34ED0@mail-apac.sun.com>; Thu,
 21 May 2009 11:56:33 +0800 (SGT)
Date: Thu, 21 May 2009 12:06:09 +0800
From: Halton Huo <Halton.Huo@sun.com>
Subject: Re: [desktop-discuss] Jokosher [LSARC/2009/314 FastTrack timeout
 06/02/2009]
In-reply-to: <200905202058.n4KKwYjd011106@sac.sfbay.sun.com>
Sender: Halton.Huo@sun.com
To: Brian Cameron <bc99092@sac.sfbay.sun.com>
Cc: desktop-discuss@opensolaris.org, LSARC-ext@sun.com
Message-id: <1242878769.897.28.camel@opensolaris>
MIME-version: 1.0
X-Mailer: Evolution 2.24.2
Content-type: text/plain; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905202058.n4KKwYjd011106@sac.sfbay.sun.com>
Status: RO
Content-Length: 1476


Brian,

You're using Jokosher/jokosher at the beginning of a sentence, should be
"Jokosher"?

> 
>         Note that, by default, the jokosher FreeSound extension saves the
>         user's FreeSound username and password in plaintext in the user's
>         jokosher $HOME configuration.  When the plugin is used after initial
                                                  ~~~~~~
You use "extension" all the time expect this, so I think should be
"extension" instead of "plugin" here.
>         login, the username and password values are filled in for the user.
> 
>         However, on Solaris, we will patch the code so that this feature is
>         disabled, and the FreeSound extension will not save the username and
>         password information to the user's $HOME directory.  This will mean
>         the user will need to re-enter this information each time they restart
>         jokosher and wish to use this plugin.
Any possible use gnome-keyring to store/load the password? 

>           
>    4.2. Interfaces:
>         
>       Exported Interfaces                          Stability   Comments
[...]
> 
>       SUNWgnonlin                                  Uncommitted  Package.
I do not think SUNWgnonlin package should be in the Exported table.

>    4.7 Security Impact:
> 
>        None.
Since Jokosher offer functionality to allow access
http://www.freesound.org/ with username/password, I'm afraid there is
some network security concern.

-Halton


From Brian.Cameron@sun.com Thu May 21 09:43:20 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n4LGhIsN018683
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 21 May 2009 09:43:18 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n4LGh7vn027397
	for <@sunmail2sca.sfbay.sun.com:LSARC-ext@sun.com>; Thu, 21 May 2009 17:43:17 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KK00000D6G2QO00@nwk-avmta-2.sfbay.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@Sun.Com); Thu, 21 May 2009 09:43:14 -0700 (PDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KK000I336G2IV70@nwk-avmta-2.sfbay.sun.com> for
 LSARC-ext@sun.com (ORCPT LSARC-ext@Sun.Com); Thu,
 21 May 2009 09:43:14 -0700 (PDT)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n4LGhDI6022736	for
 <LSARC-ext@Sun.Com>; Thu, 21 May 2009 16:43:14 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KK000H0068J2X00@mail-amer.sun.com> for LSARC-ext@Sun.Com
 (ORCPT LSARC-ext@Sun.Com); Thu, 21 May 2009 10:43:13 -0600 (MDT)
Received: from [192.168.1.70] ([unknown] [189.136.184.94])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7u2-7.02 64bit
 (built Apr 16 2009)) with ESMTPSA id <0KK0000XU6FXX460@mail-amer.sun.com>; Thu,
 21 May 2009 10:43:13 -0600 (MDT)
Date: Thu, 21 May 2009 11:43:11 -0500
From: Brian Cameron <Brian.Cameron@sun.com>
Subject: Re: Jokosher [LSARC/2009/314 FastTrack timeout 06/02/2009]
In-reply-to: <200905202058.n4KKwYjd011106@sac.sfbay.sun.com>
Sender: Brian.Cameron@sun.com
To: Brian Cameron <bc99092@sac.sfbay.sun.com>
Cc: LSARC-ext@sun.com, desktop-discuss@opensolaris.org
Message-id: <4A15849F.3050505@sun.com>
MIME-version: 1.0
Content-type: multipart/mixed; boundary="Boundary_(ID_FJkzu5mQLvDWl34CTsQTQg)"
X-PMX-Version: 5.4.1.325704
References: <200905202058.n4KKwYjd011106@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.21 (X11/20090505)
Status: RO
Content-Length: 1144

This is a multi-part message in MIME format.

--Boundary_(ID_FJkzu5mQLvDWl34CTsQTQg)
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT


I made some minor corrections to the jokosher one_pager.  Refer to
attached diff file.  Differences include:

- Refer to the jokosher extensions consistently as "extensions" and
   not as plugins.
- Remove SUNWgnonlin from the exported interface table.  This is
   obviously defined in the separate "LSARC 2009/313 GNonLin" case
   and was a typo that it was included here.

Brian

--Boundary_(ID_FJkzu5mQLvDWl34CTsQTQg)
Content-type: text/plain; name=jokosher.diff
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=jokosher.diff

123c123
<         jokosher $HOME configuration.  When the plugin is used after initial
---
>         jokosher $HOME configuration.  When the extension is used after initial
130c130
<         jokosher and wish to use this plugin.
---
>         jokosher and wish to use this extension.
168,169d167
< 
<       SUNWgnonlin                                  Uncommitted  Package.

--Boundary_(ID_FJkzu5mQLvDWl34CTsQTQg)--

From Brian.Cameron@Sun.COM Thu May 21 09:59:49 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n4LGxngo019501
	for <LSARC-ext@sac.sfbay.sun.com>; Thu, 21 May 2009 09:59:49 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n4LGxmvn009869
	for <@sunmail2sca.sfbay.sun.com:LSARC-ext@sun.com>; Thu, 21 May 2009 17:59:48 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KK00010577NMF00@nwk-avmta-2.sfbay.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@Sun.Com); Thu, 21 May 2009 09:59:47 -0700 (PDT)
Received: from brmea-mail-1.sun.com ([192.18.98.31])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KK000IT577MIT90@nwk-avmta-2.sfbay.sun.com> for
 LSARC-ext@sun.com (ORCPT LSARC-ext@Sun.Com); Thu,
 21 May 2009 09:59:46 -0700 (PDT)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n4LGxjxf026747	for
 <LSARC-ext@Sun.Com>; Thu, 21 May 2009 16:59:45 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KK000H0068J2X00@mail-amer.sun.com> for LSARC-ext@Sun.Com
 (ORCPT LSARC-ext@Sun.Com); Thu, 21 May 2009 10:59:45 -0600 (MDT)
Received: from [192.168.1.70] ([unknown] [189.136.184.94])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7u2-7.02 64bit
 (built Apr 16 2009)) with ESMTPSA id <0KK000DFS779RT00@mail-amer.sun.com>; Thu,
 21 May 2009 10:59:35 -0600 (MDT)
Date: Thu, 21 May 2009 11:59:35 -0500
From: Brian Cameron <Brian.Cameron@Sun.COM>
Subject: Re: Jokosher [LSARC/2009/314 FastTrack timeout 06/02/2009]
In-reply-to: <200905202058.n4KKwYjd011106@sac.sfbay.sun.com>
Sender: Brian.Cameron@Sun.COM
To: Brian Cameron <bc99092@sac.sfbay.sun.com>
Cc: LSARC-ext@Sun.COM, desktop-discuss@opensolaris.org
Message-id: <4A158877.2070803@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905202058.n4KKwYjd011106@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.21 (X11/20090505)
Status: RO
Content-Length: 12476


To make the security issues with the FreeSound extension more clear, I 
updated section 4.7 of the Jokosher ARC materials as follows:

    4.7 Security Impact:

        The Jokosher FreeSound extension allows users to login to
        http://www.freesound.org with a username and password.  On
        Solaris, the extension is modified to not save the username or
        password information in the user's configuration for better
        security.

        Note that a FreeSound account allows users to gain access to free
        sound samples and to post messages on their forum.

        Also note that the FreeSound website does not use HTTPS, so
        accessing the account via the Jokosher extension should have the
        same security as accessing it via a normal web browser
        application.

If anyone feels that it would be best to simply remove the FreeSound
extension from Jokosher to avoid any sort of security concerns, that
is also possible.  It is a nice-to-have feature, not a critical piece
of Jokosher functionality.

Brian


Brian Cameron wrote:
> Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
> This information is Copyright 2009 Sun Microsystems
> 1. Introduction
>     1.1. Project/Component Working Name:
> 	 Jokosher
>     1.2. Name of Document Author/Supplier:
> 	 Author:  Brian Cameron
>     1.3  Date of This Document:
> 	20 May, 2009
> 4. Technical Description
> Template Version: @(#)sac_nextcase %I% %G% SMI
> This information is Copyright 2008 Sun Microsystems
> 
> 1. Introduction
>    1.1. Project/Component Working Name:
> 
>         jokosher
> 
>    1.2. Name of Document Author/Supplier:
> 
>         Author:  Brian Cameron
> 
>    1.3  Date of This Document:
> 
>         12 May 2009
> 
>    1.4. Name of Major Document Customer(s)/Consumer(s):
>         1.4.1. The PAC or CPT you expect to review your project:
> 
>                Solaris PAC
> 
>         1.4.2. The ARC(s) you expect to review your project:
> 
>                LSARC
> 
>         1.4.3. The Director/VP who is "Sponsoring" this project:
> 
>                Robert O'Dea
> 
>         1.4.4. The name of your business unit:
> 
>                Software - OPG
> 
>    1.5. Email Aliases:
>         1.5.1. Responsible Manager: 
> 
>                leo.binchy@sun.com
> 
>         1.5.2. Responsible Engineer:
> 
>                brian.cameron@sun.com
> 
>         1.5.3  Marketing Manager:
> 
>                glynn.foster@sun.com
> 
>         1.5.4. Interest List: 
> 
>                desktop-discuss@opensolaris.org 
> 
> 2. Project Summary
>    2.1. Project Description:
> 
>         jokosher is a simple, yet powerful multi-track studio written in Python
>         that uses GStreamer and gnonlin.  With jokosher you can create and
>         record music, podcasts and more, all from an integrated simple
>         environment.  It supports recording, editing (e.g. splitting, trimming,
>         moving), mixing, and exporting audio.  It supports all audio formats
>         that are supported by GStreamer.  Users can, for example, purchase
>         plugins from Fluendo to enable MP3 or WindowsMedia Audio support.
> 
>         jokosher uses the GPL license and contains a license exception which
>         allows distribution with non-free GStreamer-plugins.
> 
> 4. Technical Description:
>    4.1. Details:
> 
>         Jokosher provides a multi-track interface for recording and mixing
>         audio.  Jokosher supports two workspace modes: the Recording Workspace
>         and the Mixing Workspace.  The user simply toggles between the two
>         modes by clicking on the "Audio Mixers" button in the toolbar.
> 
>         When in the Recording Workspace mode, the user may create multiple
>         audio tracks.  The tracks may either be an existing audio file which
>         the user can specify, or be an instrument.  The instrument setting is
>         intended to be used when the user intends to record the track into
>         jokosher.  
> 
>         Jokosher provides a set of Instrument files, which simply specify a
>         label and an icon for the instrument.  When a track is associated with
>         an instrument then the track is shown with this label and icon so that
>         the user can easily determine what instrument is associated with each
>         track.
> 
>         When in the Mixing Workspace mode the user can specify the volume level
>         and balance setting for each track.  Once the mix is specified, then
>         the user can use jokosher's "Mixdown" feature to save the final audio
>         mix to a file in the desired audio format.  The Mixdown dialog also
>         allows the user to run user-specified scripts to do any desired actions
>         once the mix is completed, such as to upload the file to a server or to
>         create a playlist.
> 
>         Jokosher projects can be saved in a file format with the extension
>         ".jokosher".  When reloaded, the track and mixing settings and all
>         preferences are restored so a user can continue working on a project.
>         These files are associated with the MIME type "application/x-jokosher".
> 
>         Jokosher provides extensions which allow third party developers to add
>         features to Jokosher to make it support file types or support 
>         additional functionality.  Jokosher includes an extensions manager
>         which allows users to add, remove, or configure extensions. [1]
> 
>         By default jokosher includes the following extensions:
> 
>         - A "Set Tempo" extension which allows the user to set the tempo for
>           a project by clicking on a button on each beat during playback.
>         - A "Minimal Mode" extension which changes the UI to a minimal
>           appearance
>         - An "Instrument Type Manager" extension which allows the user to 
>           specify the label and icon for new instruments, and to delete any
>           previously added instruments.
>         - A "Search FreeSound" extension which will search the FreeSound
>           library of freely licensable and usable sound clips.  The FreeSound
>           library can be found at http://www.freesound.org/.
>         - An "Extension Console" which provides a fully functional python
>           console with access to the jokosher extension API and jokosher
>           internals.  Useful for writing or debugging extension code.
>         - A "Jokosher D-Bus API" extension which allows other processes to 
>           call Jokosher extension API functions via D-Bus.
> 
>         Note that, by default, the jokosher FreeSound extension saves the
>         user's FreeSound username and password in plaintext in the user's
>         jokosher $HOME configuration.  When the plugin is used after initial
>         login, the username and password values are filled in for the user.
> 
>         However, on Solaris, we will patch the code so that this feature is
>         disabled, and the FreeSound extension will not save the username and
>         password information to the user's $HOME directory.  This will mean
>         the user will need to re-enter this information each time they restart
>         jokosher and wish to use this plugin.
>           
>    4.2. Interfaces:
>         
>       Exported Interfaces                          Stability   Comments
>       -------------------------------------------  ----------  ----------------
> 
>       /usr/bin/jokosher                            Volatile     Jokosher
>                                                                 application.
>       /usr/lib/python2.6/vendor-packages/Jokosher  Volatile     Jokosher python
>                                                                 implementation.
>       /usr/share/applications/jokosher.desktop     Volatile     Jokosher desktop
>                                                                 file.
>       /usr/share/gnome/help/jokosher               Volatile     Jokosher help
>                                                                 files.
>       /usr/share/jokosher                          Volatile     Jokosher
>                                                                 internal data.
>       /usr/share/jokosher/Instruments              Volatile     Jokosher
>                                                                 instrument
>                                                                 files.
>       /usr/share/jokosher/extensions               Volatile     Jokosher
>                                                                 extension files.
>       /usr/share/jokosher/pixmaps                  Project      Jokosher image
>                                                    Private      files.
>       /usr/share/icons/hicolor/48x48/apps/jokosher.png         
>                                                    Project      Jokosher
>                                                    Private      application
>                                                                 image.
>       /usr/share/pixmaps/jokosher.png              Project      Jokosher
>                                                    Private      application
>                                                                 image.
>       /usr/share/mime/packages/jokosher.xml        Volatile     Specifies the
>                                                                 MIME type for
>                                                                 jokosher files.
>       /usr/share/omf/jokosher                      Project      Jokosher OMF 
>                                                    Private      files.
>       $HOME/.local/share/jokosher                  Volatile     Jokosher user
>                                                                 configuration
> 
>       SUNWgnonlin                                  Uncommitted  Package.
>       SUNWjokosher                                 Uncommitted  Package.
> 
>  
>       Imported Interfaces    Stability          Comments
>       ---------------        ---------------    -----------------------
>       GNOME Base Libraries   Committed          LSARC 2006/202
>       GStreamer              Volatile           LSARC/2006/202
>       GNonLin                Volatile           Not yet filed
>       Python                 External           PSARC/2005/532  Python
>                              Evolving           Migration from /usr/sfw 
>                                                 to /usr and upgrade to v2.4.x
>       gst-python             Volatile           LSARC 2008/105
>       Pygtk, gnome-python    Unstable           LSARC 2005/506
>       D-Bus                  Volatile           LSARC 2006/368
>       Python Setuptools      Uncommitted        PSARC 2008/084
> 
>    4.3. Doc Impact:
> 
>         jokosher includes Help documentation.  Jokosher does not ship with any
>         developer documentation, but the help files do point to the Jokosher
>         developer webiste for more information about doing things like writing
>         extensions.
> 
>    4.4. Packaging & Delivery:
>         
>         SUNWjokosher - jokosher application.
> 
>    4.5. Dependencies:
> 
>         The ARC case for GNonLin, which is being submitted at the same time
>         as this case.  I will update this section and the Comments value for
>         GNonLin in the Imported Interface table to include the ARC number
>         when available.
> 
>    4.6. L10N Impact:
> 
>         The Desktop team and the G11N are working together to evaluate and
>         provide I18N/L10N support.
> 
>    4.7 Security Impact:
> 
>        None.
>        
> 5. Reference Documents:
> 
>        [1] Jokosher Extensions Documentation
>        http://userdocs.jokosher.org/Extensions/
> 
>        Jokosher Website and User Documentation:
>        http://www.jokosher.org/
>        http://userdocs.jokosher.org/
> 
> 6. Resources and Schedule
>     6.4. Steering Committee requested information
>    	6.4.1. Consolidation C-team Name:
> 		Desktop
>     6.5. ARC review type: FastTrack
>     6.6. ARC Exposure: open
> 
> 
> 6. Resources and Schedule
>     6.4. Steering Committee requested information
>    	6.4.1. Consolidation C-team Name:
> 		Desktop
>     6.5. ARC review type: FastTrack
>     6.6. ARC Exposure: open
> 
> _______________________________________________
> opensolaris-arc mailing list
> opensolaris-arc@opensolaris.org


From Darren.Moffat@sun.com Fri May 22 02:36:22 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n4M9aLJb028163
	for <LSARC-ext@sac.sfbay.sun.com>; Fri, 22 May 2009 02:36:22 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n4M9aGi0024378
	for <@sunmail2sca.sfbay.sun.com:LSARC-ext@sun.com>; Fri, 22 May 2009 10:36:20 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KK100J07HCI2G00@nwk-avmta-2.sfbay.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Fri, 22 May 2009 02:36:18 -0700 (PDT)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KK100HORHCH9X60@nwk-avmta-2.sfbay.sun.com> for
 LSARC-ext@sun.com (ORCPT LSARC-ext@sun.com); Fri,
 22 May 2009 02:36:18 -0700 (PDT)
Received: from fe-emea-10.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n4M9aHgW022398	for
 <LSARC-ext@sun.com>; Fri, 22 May 2009 09:36:17 +0000 (GMT)
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KK100C00GSUON00@fe-emea-10.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Fri, 22 May 2009 10:36:17 +0100 (BST)
Received: from [129.156.173.199] ([unknown] [129.156.173.199])
 by fe-emea-10.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 with ESMTPSA id <0KK100JA8HCBUU50@fe-emea-10.sun.com>; Fri,
 22 May 2009 10:36:11 +0100 (BST)
Date: Fri, 22 May 2009 10:36:11 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: Jokosher [LSARC/2009/314 FastTrack timeout 06/02/2009]
In-reply-to: <4A158877.2070803@sun.com>
Sender: Darren.Moffat@sun.com
To: Brian Cameron <Brian.Cameron@sun.com>
Cc: Brian Cameron <bc99092@sac.sfbay.sun.com>, LSARC-ext@sun.com,
        desktop-discuss@opensolaris.org
Message-id: <4A16720B.2000904@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905202058.n4KKwYjd011106@sac.sfbay.sun.com>
 <4A158877.2070803@sun.com>
User-Agent: Thunderbird 2.0.0.18 (X11/20090127)
Status: RO
Content-Length: 1334

Brian Cameron wrote:
> 
> To make the security issues with the FreeSound extension more clear, I 
> updated section 4.7 of the Jokosher ARC materials as follows:
> 
>    4.7 Security Impact:
> 
>        The Jokosher FreeSound extension allows users to login to
>        http://www.freesound.org with a username and password.  On
>        Solaris, the extension is modified to not save the username or
>        password information in the user's configuration for better
>        security.
> 
>        Note that a FreeSound account allows users to gain access to free
>        sound samples and to post messages on their forum.
> 
>        Also note that the FreeSound website does not use HTTPS, so
>        accessing the account via the Jokosher extension should have the
>        same security as accessing it via a normal web browser
>        application.
> 
> If anyone feels that it would be best to simply remove the FreeSound
> extension from Jokosher to avoid any sort of security concerns, that
> is also possible.  It is a nice-to-have feature, not a critical piece
> of Jokosher functionality.

That is in my opinion more than sufficient given what this really is 
for, and I wouldn't even have asked for that.  Ideally this should be 
pushed upstream or a change to use gnomekeyring pushed upstream.


-- 
Darren J Moffat

From John.Fischer@sun.com Wed Jun  3 08:08:36 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n53F8ZdB021622
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 3 Jun 2009 08:08:36 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n53F8VSp025604
	for <@sunmail2sca.sfbay.sun.com:LSARC-ext@sun.com>; Wed, 3 Jun 2009 23:08:34 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KKO00M0B4Q81000@nwk-avmta-1.sfbay.Sun.COM> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Wed, 03 Jun 2009 08:08:32 -0700 (PDT)
Received: from brmea-mail-2.sun.com ([192.18.98.43])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KKO00I8V4Q53220@nwk-avmta-1.sfbay.Sun.COM> for
 LSARC-ext@sun.com (ORCPT LSARC-ext@sun.com); Wed,
 03 Jun 2009 08:08:30 -0700 (PDT)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n53F8TJS011575	for
 <LSARC-ext@sun.com>; Wed, 03 Jun 2009 15:08:29 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KKO00C004GDSH00@mail-amer.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Wed, 03 Jun 2009 09:08:29 -0600 (MDT)
Received: from [10.71.0.72] ([unknown] [209.220.168.194])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7u2-7.02 64bit
 (built Apr 16 2009)) with ESMTPSA id <0KKO00BB14Q3VJ30@mail-amer.sun.com>; Wed,
 03 Jun 2009 09:08:27 -0600 (MDT)
Date: Wed, 03 Jun 2009 08:07:01 -0700
From: John Fischer <John.Fischer@sun.com>
Subject: Re: Jokosher [LSARC/2009/314 FastTrack timeout 06/02/2009]
In-reply-to: <4A158877.2070803@sun.com>
Sender: John.Fischer@sun.com
To: Brian Cameron <Brian.Cameron@sun.com>
Cc: Brian Cameron <bc99092@sac.sfbay.sun.com>, LSARC-ext@sun.com,
        desktop-discuss@opensolaris.org
Reply-to: John.Fischer@sun.com
Message-id: <4A269195.7060504@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905202058.n4KKwYjd011106@sac.sfbay.sun.com>
 <4A158877.2070803@sun.com>
User-Agent: Thunderbird 2.0.0.21 (X11/20090323)
Status: RO
Content-Length: 13001

+1

John

Brian Cameron wrote:
> 
> To make the security issues with the FreeSound extension more clear, I 
> updated section 4.7 of the Jokosher ARC materials as follows:
> 
>    4.7 Security Impact:
> 
>        The Jokosher FreeSound extension allows users to login to
>        http://www.freesound.org with a username and password.  On
>        Solaris, the extension is modified to not save the username or
>        password information in the user's configuration for better
>        security.
> 
>        Note that a FreeSound account allows users to gain access to free
>        sound samples and to post messages on their forum.
> 
>        Also note that the FreeSound website does not use HTTPS, so
>        accessing the account via the Jokosher extension should have the
>        same security as accessing it via a normal web browser
>        application.
> 
> If anyone feels that it would be best to simply remove the FreeSound
> extension from Jokosher to avoid any sort of security concerns, that
> is also possible.  It is a nice-to-have feature, not a critical piece
> of Jokosher functionality.
> 
> Brian
> 
> 
> Brian Cameron wrote:
>> Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
>> This information is Copyright 2009 Sun Microsystems
>> 1. Introduction
>>     1.1. Project/Component Working Name:
>>      Jokosher
>>     1.2. Name of Document Author/Supplier:
>>      Author:  Brian Cameron
>>     1.3  Date of This Document:
>>     20 May, 2009
>> 4. Technical Description
>> Template Version: @(#)sac_nextcase %I% %G% SMI
>> This information is Copyright 2008 Sun Microsystems
>>
>> 1. Introduction
>>    1.1. Project/Component Working Name:
>>
>>         jokosher
>>
>>    1.2. Name of Document Author/Supplier:
>>
>>         Author:  Brian Cameron
>>
>>    1.3  Date of This Document:
>>
>>         12 May 2009
>>
>>    1.4. Name of Major Document Customer(s)/Consumer(s):
>>         1.4.1. The PAC or CPT you expect to review your project:
>>
>>                Solaris PAC
>>
>>         1.4.2. The ARC(s) you expect to review your project:
>>
>>                LSARC
>>
>>         1.4.3. The Director/VP who is "Sponsoring" this project:
>>
>>                Robert O'Dea
>>
>>         1.4.4. The name of your business unit:
>>
>>                Software - OPG
>>
>>    1.5. Email Aliases:
>>         1.5.1. Responsible Manager:
>>                leo.binchy@sun.com
>>
>>         1.5.2. Responsible Engineer:
>>
>>                brian.cameron@sun.com
>>
>>         1.5.3  Marketing Manager:
>>
>>                glynn.foster@sun.com
>>
>>         1.5.4. Interest List:
>>                desktop-discuss@opensolaris.org
>> 2. Project Summary
>>    2.1. Project Description:
>>
>>         jokosher is a simple, yet powerful multi-track studio written 
>> in Python
>>         that uses GStreamer and gnonlin.  With jokosher you can create 
>> and
>>         record music, podcasts and more, all from an integrated simple
>>         environment.  It supports recording, editing (e.g. splitting, 
>> trimming,
>>         moving), mixing, and exporting audio.  It supports all audio 
>> formats
>>         that are supported by GStreamer.  Users can, for example, 
>> purchase
>>         plugins from Fluendo to enable MP3 or WindowsMedia Audio support.
>>
>>         jokosher uses the GPL license and contains a license exception 
>> which
>>         allows distribution with non-free GStreamer-plugins.
>>
>> 4. Technical Description:
>>    4.1. Details:
>>
>>         Jokosher provides a multi-track interface for recording and 
>> mixing
>>         audio.  Jokosher supports two workspace modes: the Recording 
>> Workspace
>>         and the Mixing Workspace.  The user simply toggles between the 
>> two
>>         modes by clicking on the "Audio Mixers" button in the toolbar.
>>
>>         When in the Recording Workspace mode, the user may create 
>> multiple
>>         audio tracks.  The tracks may either be an existing audio file 
>> which
>>         the user can specify, or be an instrument.  The instrument 
>> setting is
>>         intended to be used when the user intends to record the track 
>> into
>>         jokosher. 
>>         Jokosher provides a set of Instrument files, which simply 
>> specify a
>>         label and an icon for the instrument.  When a track is 
>> associated with
>>         an instrument then the track is shown with this label and icon 
>> so that
>>         the user can easily determine what instrument is associated 
>> with each
>>         track.
>>
>>         When in the Mixing Workspace mode the user can specify the 
>> volume level
>>         and balance setting for each track.  Once the mix is 
>> specified, then
>>         the user can use jokosher's "Mixdown" feature to save the 
>> final audio
>>         mix to a file in the desired audio format.  The Mixdown dialog 
>> also
>>         allows the user to run user-specified scripts to do any 
>> desired actions
>>         once the mix is completed, such as to upload the file to a 
>> server or to
>>         create a playlist.
>>
>>         Jokosher projects can be saved in a file format with the 
>> extension
>>         ".jokosher".  When reloaded, the track and mixing settings and 
>> all
>>         preferences are restored so a user can continue working on a 
>> project.
>>         These files are associated with the MIME type 
>> "application/x-jokosher".
>>
>>         Jokosher provides extensions which allow third party 
>> developers to add
>>         features to Jokosher to make it support file types or support 
>>         additional functionality.  Jokosher includes an extensions 
>> manager
>>         which allows users to add, remove, or configure extensions. [1]
>>
>>         By default jokosher includes the following extensions:
>>
>>         - A "Set Tempo" extension which allows the user to set the 
>> tempo for
>>           a project by clicking on a button on each beat during playback.
>>         - A "Minimal Mode" extension which changes the UI to a minimal
>>           appearance
>>         - An "Instrument Type Manager" extension which allows the user 
>> to           specify the label and icon for new instruments, and to 
>> delete any
>>           previously added instruments.
>>         - A "Search FreeSound" extension which will search the FreeSound
>>           library of freely licensable and usable sound clips.  The 
>> FreeSound
>>           library can be found at http://www.freesound.org/.
>>         - An "Extension Console" which provides a fully functional python
>>           console with access to the jokosher extension API and jokosher
>>           internals.  Useful for writing or debugging extension code.
>>         - A "Jokosher D-Bus API" extension which allows other 
>> processes to           call Jokosher extension API functions via D-Bus.
>>
>>         Note that, by default, the jokosher FreeSound extension saves the
>>         user's FreeSound username and password in plaintext in the user's
>>         jokosher $HOME configuration.  When the plugin is used after 
>> initial
>>         login, the username and password values are filled in for the 
>> user.
>>
>>         However, on Solaris, we will patch the code so that this 
>> feature is
>>         disabled, and the FreeSound extension will not save the 
>> username and
>>         password information to the user's $HOME directory.  This will 
>> mean
>>         the user will need to re-enter this information each time they 
>> restart
>>         jokosher and wish to use this plugin.
>>              4.2. Interfaces:
>>               Exported Interfaces                          Stability   
>> Comments
>>       -------------------------------------------  ----------  
>> ----------------
>>
>>       /usr/bin/jokosher                            Volatile     Jokosher
>>                                                                 
>> application.
>>       /usr/lib/python2.6/vendor-packages/Jokosher  Volatile     
>> Jokosher python
>>                                                                 
>> implementation.
>>       /usr/share/applications/jokosher.desktop     Volatile     
>> Jokosher desktop
>>                                                                 file.
>>       /usr/share/gnome/help/jokosher               Volatile     
>> Jokosher help
>>                                                                 files.
>>       /usr/share/jokosher                          Volatile     Jokosher
>>                                                                 
>> internal data.
>>       /usr/share/jokosher/Instruments              Volatile     Jokosher
>>                                                                 
>> instrument
>>                                                                 files.
>>       /usr/share/jokosher/extensions               Volatile     Jokosher
>>                                                                 
>> extension files.
>>       /usr/share/jokosher/pixmaps                  Project      
>> Jokosher image
>>                                                    Private      files.
>>       /usr/share/icons/hicolor/48x48/apps/jokosher.png         
>>                                                    Project      Jokosher
>>                                                    Private      
>> application
>>                                                                 image.
>>       /usr/share/pixmaps/jokosher.png              Project      Jokosher
>>                                                    Private      
>> application
>>                                                                 image.
>>       /usr/share/mime/packages/jokosher.xml        Volatile     
>> Specifies the
>>                                                                 MIME 
>> type for
>>                                                                 
>> jokosher files.
>>       /usr/share/omf/jokosher                      Project      
>> Jokosher OMF                                                    
>> Private      files.
>>       $HOME/.local/share/jokosher                  Volatile     
>> Jokosher user
>>                                                                 
>> configuration
>>
>>       SUNWgnonlin                                  Uncommitted  Package.
>>       SUNWjokosher                                 Uncommitted  Package.
>>
>>  
>>       Imported Interfaces    Stability          Comments
>>       ---------------        ---------------    -----------------------
>>       GNOME Base Libraries   Committed          LSARC 2006/202
>>       GStreamer              Volatile           LSARC/2006/202
>>       GNonLin                Volatile           Not yet filed
>>       Python                 External           PSARC/2005/532  Python
>>                              Evolving           Migration from 
>> /usr/sfw                                                 to /usr and 
>> upgrade to v2.4.x
>>       gst-python             Volatile           LSARC 2008/105
>>       Pygtk, gnome-python    Unstable           LSARC 2005/506
>>       D-Bus                  Volatile           LSARC 2006/368
>>       Python Setuptools      Uncommitted        PSARC 2008/084
>>
>>    4.3. Doc Impact:
>>
>>         jokosher includes Help documentation.  Jokosher does not ship 
>> with any
>>         developer documentation, but the help files do point to the 
>> Jokosher
>>         developer webiste for more information about doing things like 
>> writing
>>         extensions.
>>
>>    4.4. Packaging & Delivery:
>>                 SUNWjokosher - jokosher application.
>>
>>    4.5. Dependencies:
>>
>>         The ARC case for GNonLin, which is being submitted at the same 
>> time
>>         as this case.  I will update this section and the Comments 
>> value for
>>         GNonLin in the Imported Interface table to include the ARC number
>>         when available.
>>
>>    4.6. L10N Impact:
>>
>>         The Desktop team and the G11N are working together to evaluate 
>> and
>>         provide I18N/L10N support.
>>
>>    4.7 Security Impact:
>>
>>        None.
>>        5. Reference Documents:
>>
>>        [1] Jokosher Extensions Documentation
>>        http://userdocs.jokosher.org/Extensions/
>>
>>        Jokosher Website and User Documentation:
>>        http://www.jokosher.org/
>>        http://userdocs.jokosher.org/
>>
>> 6. Resources and Schedule
>>     6.4. Steering Committee requested information
>>        6.4.1. Consolidation C-team Name:
>>         Desktop
>>     6.5. ARC review type: FastTrack
>>     6.6. ARC Exposure: open
>>
>>
>> 6. Resources and Schedule
>>     6.4. Steering Committee requested information
>>        6.4.1. Consolidation C-team Name:
>>         Desktop
>>     6.5. ARC review type: FastTrack
>>     6.6. ARC Exposure: open
>>
>> _______________________________________________
>> opensolaris-arc mailing list
>> opensolaris-arc@opensolaris.org
> 

From Brian.Cameron@sun.com Wed Jun  3 17:19:25 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n540JORu020532
	for <LSARC-ext@sac.sfbay.sun.com>; Wed, 3 Jun 2009 17:19:25 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n540JGMR005809
	for <@sunmail2sca.sfbay.sun.com:LSARC-ext@sun.com>; Thu, 4 Jun 2009 08:19:23 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KKO00809U8AF100@brm-avmta-1.central.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Wed, 03 Jun 2009 18:19:22 -0600 (MDT)
Received: from brmea-mail-2.sun.com ([192.18.98.43])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KKO00M0BU896V70@brm-avmta-1.central.sun.com> for
 LSARC-ext@sun.com (ORCPT LSARC-ext@sun.com); Wed,
 03 Jun 2009 18:19:21 -0600 (MDT)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n540JLtA015184	for
 <LSARC-ext@sun.com>; Thu, 04 Jun 2009 00:19:21 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KKO00600U0KRX00@mail-amer.sun.com> for LSARC-ext@sun.com
 (ORCPT LSARC-ext@sun.com); Wed, 03 Jun 2009 18:19:21 -0600 (MDT)
Received: from [192.168.1.3] ([unknown] [99.135.187.56])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7u2-7.02 64bit
 (built Apr 16 2009)) with ESMTPSA id <0KKO007XTU83ZU00@mail-amer.sun.com>; Wed,
 03 Jun 2009 18:19:16 -0600 (MDT)
Date: Wed, 03 Jun 2009 19:19:17 -0500
From: Brian Cameron <Brian.Cameron@sun.com>
Subject: Re: Jokosher [LSARC/2009/314 FastTrack timeout 06/02/2009]
In-reply-to: <4A269195.7060504@sun.com>
Sender: Brian.Cameron@sun.com
To: John.Fischer@sun.com
Cc: Brian Cameron <bc99092@sac.sfbay.sun.com>, LSARC-ext@sun.com,
        desktop-discuss@opensolaris.org
Message-id: <4A271305.5020105@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905202058.n4KKwYjd011106@sac.sfbay.sun.com>
 <4A158877.2070803@sun.com> <4A269195.7060504@sun.com>
User-Agent: Thunderbird 2.0.0.21 (X11/20090505)
Status: RO
Content-Length: 13710


I am marking this case as closed approved 06/03/2009.  The only issue
raised was about the way the username/password is stored by the
FreeSound extension, but the security experts expressed that just
modifying the code to not save the username and password information
in the user's $HOME configuraiton is sufficient.

Brian


John Fischer wrote:
> +1
> 
> John
> 
> Brian Cameron wrote:
>>
>> To make the security issues with the FreeSound extension more clear, I 
>> updated section 4.7 of the Jokosher ARC materials as follows:
>>
>>    4.7 Security Impact:
>>
>>        The Jokosher FreeSound extension allows users to login to
>>        http://www.freesound.org with a username and password.  On
>>        Solaris, the extension is modified to not save the username or
>>        password information in the user's configuration for better
>>        security.
>>
>>        Note that a FreeSound account allows users to gain access to free
>>        sound samples and to post messages on their forum.
>>
>>        Also note that the FreeSound website does not use HTTPS, so
>>        accessing the account via the Jokosher extension should have the
>>        same security as accessing it via a normal web browser
>>        application.
>>
>> If anyone feels that it would be best to simply remove the FreeSound
>> extension from Jokosher to avoid any sort of security concerns, that
>> is also possible.  It is a nice-to-have feature, not a critical piece
>> of Jokosher functionality.
>>
>> Brian
>>
>>
>> Brian Cameron wrote:
>>> Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
>>> This information is Copyright 2009 Sun Microsystems
>>> 1. Introduction
>>>     1.1. Project/Component Working Name:
>>>      Jokosher
>>>     1.2. Name of Document Author/Supplier:
>>>      Author:  Brian Cameron
>>>     1.3  Date of This Document:
>>>     20 May, 2009
>>> 4. Technical Description
>>> Template Version: @(#)sac_nextcase %I% %G% SMI
>>> This information is Copyright 2008 Sun Microsystems
>>>
>>> 1. Introduction
>>>    1.1. Project/Component Working Name:
>>>
>>>         jokosher
>>>
>>>    1.2. Name of Document Author/Supplier:
>>>
>>>         Author:  Brian Cameron
>>>
>>>    1.3  Date of This Document:
>>>
>>>         12 May 2009
>>>
>>>    1.4. Name of Major Document Customer(s)/Consumer(s):
>>>         1.4.1. The PAC or CPT you expect to review your project:
>>>
>>>                Solaris PAC
>>>
>>>         1.4.2. The ARC(s) you expect to review your project:
>>>
>>>                LSARC
>>>
>>>         1.4.3. The Director/VP who is "Sponsoring" this project:
>>>
>>>                Robert O'Dea
>>>
>>>         1.4.4. The name of your business unit:
>>>
>>>                Software - OPG
>>>
>>>    1.5. Email Aliases:
>>>         1.5.1. Responsible Manager:
>>>                leo.binchy@sun.com
>>>
>>>         1.5.2. Responsible Engineer:
>>>
>>>                brian.cameron@sun.com
>>>
>>>         1.5.3  Marketing Manager:
>>>
>>>                glynn.foster@sun.com
>>>
>>>         1.5.4. Interest List:
>>>                desktop-discuss@opensolaris.org
>>> 2. Project Summary
>>>    2.1. Project Description:
>>>
>>>         jokosher is a simple, yet powerful multi-track studio written 
>>> in Python
>>>         that uses GStreamer and gnonlin.  With jokosher you can 
>>> create and
>>>         record music, podcasts and more, all from an integrated simple
>>>         environment.  It supports recording, editing (e.g. splitting, 
>>> trimming,
>>>         moving), mixing, and exporting audio.  It supports all audio 
>>> formats
>>>         that are supported by GStreamer.  Users can, for example, 
>>> purchase
>>>         plugins from Fluendo to enable MP3 or WindowsMedia Audio 
>>> support.
>>>
>>>         jokosher uses the GPL license and contains a license 
>>> exception which
>>>         allows distribution with non-free GStreamer-plugins.
>>>
>>> 4. Technical Description:
>>>    4.1. Details:
>>>
>>>         Jokosher provides a multi-track interface for recording and 
>>> mixing
>>>         audio.  Jokosher supports two workspace modes: the Recording 
>>> Workspace
>>>         and the Mixing Workspace.  The user simply toggles between 
>>> the two
>>>         modes by clicking on the "Audio Mixers" button in the toolbar.
>>>
>>>         When in the Recording Workspace mode, the user may create 
>>> multiple
>>>         audio tracks.  The tracks may either be an existing audio 
>>> file which
>>>         the user can specify, or be an instrument.  The instrument 
>>> setting is
>>>         intended to be used when the user intends to record the track 
>>> into
>>>         jokosher.         Jokosher provides a set of Instrument 
>>> files, which simply specify a
>>>         label and an icon for the instrument.  When a track is 
>>> associated with
>>>         an instrument then the track is shown with this label and 
>>> icon so that
>>>         the user can easily determine what instrument is associated 
>>> with each
>>>         track.
>>>
>>>         When in the Mixing Workspace mode the user can specify the 
>>> volume level
>>>         and balance setting for each track.  Once the mix is 
>>> specified, then
>>>         the user can use jokosher's "Mixdown" feature to save the 
>>> final audio
>>>         mix to a file in the desired audio format.  The Mixdown 
>>> dialog also
>>>         allows the user to run user-specified scripts to do any 
>>> desired actions
>>>         once the mix is completed, such as to upload the file to a 
>>> server or to
>>>         create a playlist.
>>>
>>>         Jokosher projects can be saved in a file format with the 
>>> extension
>>>         ".jokosher".  When reloaded, the track and mixing settings 
>>> and all
>>>         preferences are restored so a user can continue working on a 
>>> project.
>>>         These files are associated with the MIME type 
>>> "application/x-jokosher".
>>>
>>>         Jokosher provides extensions which allow third party 
>>> developers to add
>>>         features to Jokosher to make it support file types or support 
>>>         additional functionality.  Jokosher includes an extensions 
>>> manager
>>>         which allows users to add, remove, or configure extensions. [1]
>>>
>>>         By default jokosher includes the following extensions:
>>>
>>>         - A "Set Tempo" extension which allows the user to set the 
>>> tempo for
>>>           a project by clicking on a button on each beat during 
>>> playback.
>>>         - A "Minimal Mode" extension which changes the UI to a minimal
>>>           appearance
>>>         - An "Instrument Type Manager" extension which allows the 
>>> user to           specify the label and icon for new instruments, and 
>>> to delete any
>>>           previously added instruments.
>>>         - A "Search FreeSound" extension which will search the FreeSound
>>>           library of freely licensable and usable sound clips.  The 
>>> FreeSound
>>>           library can be found at http://www.freesound.org/.
>>>         - An "Extension Console" which provides a fully functional 
>>> python
>>>           console with access to the jokosher extension API and jokosher
>>>           internals.  Useful for writing or debugging extension code.
>>>         - A "Jokosher D-Bus API" extension which allows other 
>>> processes to           call Jokosher extension API functions via D-Bus.
>>>
>>>         Note that, by default, the jokosher FreeSound extension saves 
>>> the
>>>         user's FreeSound username and password in plaintext in the 
>>> user's
>>>         jokosher $HOME configuration.  When the plugin is used after 
>>> initial
>>>         login, the username and password values are filled in for the 
>>> user.
>>>
>>>         However, on Solaris, we will patch the code so that this 
>>> feature is
>>>         disabled, and the FreeSound extension will not save the 
>>> username and
>>>         password information to the user's $HOME directory.  This 
>>> will mean
>>>         the user will need to re-enter this information each time 
>>> they restart
>>>         jokosher and wish to use this plugin.
>>>              4.2. Interfaces:
>>>               Exported Interfaces                          
>>> Stability   Comments
>>>       -------------------------------------------  ----------  
>>> ----------------
>>>
>>>       /usr/bin/jokosher                            Volatile     Jokosher
>>>                                                                 
>>> application.
>>>       /usr/lib/python2.6/vendor-packages/Jokosher  Volatile     
>>> Jokosher python
>>>                                                                 
>>> implementation.
>>>       /usr/share/applications/jokosher.desktop     Volatile     
>>> Jokosher desktop
>>>                                                                 file.
>>>       /usr/share/gnome/help/jokosher               Volatile     
>>> Jokosher help
>>>                                                                 files.
>>>       /usr/share/jokosher                          Volatile     Jokosher
>>>                                                                 
>>> internal data.
>>>       /usr/share/jokosher/Instruments              Volatile     Jokosher
>>>                                                                 
>>> instrument
>>>                                                                 files.
>>>       /usr/share/jokosher/extensions               Volatile     Jokosher
>>>                                                                 
>>> extension files.
>>>       /usr/share/jokosher/pixmaps                  Project      
>>> Jokosher image
>>>                                                    Private      files.
>>>       /usr/share/icons/hicolor/48x48/apps/jokosher.png         
>>>                                                    Project      Jokosher
>>>                                                    Private      
>>> application
>>>                                                                 image.
>>>       /usr/share/pixmaps/jokosher.png              Project      Jokosher
>>>                                                    Private      
>>> application
>>>                                                                 image.
>>>       /usr/share/mime/packages/jokosher.xml        Volatile     
>>> Specifies the
>>>                                                                 MIME 
>>> type for
>>>                                                                 
>>> jokosher files.
>>>       /usr/share/omf/jokosher                      Project      
>>> Jokosher OMF                                                    
>>> Private      files.
>>>       $HOME/.local/share/jokosher                  Volatile     
>>> Jokosher user
>>>                                                                 
>>> configuration
>>>
>>>       SUNWgnonlin                                  Uncommitted  Package.
>>>       SUNWjokosher                                 Uncommitted  Package.
>>>
>>>  
>>>       Imported Interfaces    Stability          Comments
>>>       ---------------        ---------------    -----------------------
>>>       GNOME Base Libraries   Committed          LSARC 2006/202
>>>       GStreamer              Volatile           LSARC/2006/202
>>>       GNonLin                Volatile           Not yet filed
>>>       Python                 External           PSARC/2005/532  Python
>>>                              Evolving           Migration from 
>>> /usr/sfw                                                 to /usr and 
>>> upgrade to v2.4.x
>>>       gst-python             Volatile           LSARC 2008/105
>>>       Pygtk, gnome-python    Unstable           LSARC 2005/506
>>>       D-Bus                  Volatile           LSARC 2006/368
>>>       Python Setuptools      Uncommitted        PSARC 2008/084
>>>
>>>    4.3. Doc Impact:
>>>
>>>         jokosher includes Help documentation.  Jokosher does not ship 
>>> with any
>>>         developer documentation, but the help files do point to the 
>>> Jokosher
>>>         developer webiste for more information about doing things 
>>> like writing
>>>         extensions.
>>>
>>>    4.4. Packaging & Delivery:
>>>                 SUNWjokosher - jokosher application.
>>>
>>>    4.5. Dependencies:
>>>
>>>         The ARC case for GNonLin, which is being submitted at the 
>>> same time
>>>         as this case.  I will update this section and the Comments 
>>> value for
>>>         GNonLin in the Imported Interface table to include the ARC 
>>> number
>>>         when available.
>>>
>>>    4.6. L10N Impact:
>>>
>>>         The Desktop team and the G11N are working together to 
>>> evaluate and
>>>         provide I18N/L10N support.
>>>
>>>    4.7 Security Impact:
>>>
>>>        None.
>>>        5. Reference Documents:
>>>
>>>        [1] Jokosher Extensions Documentation
>>>        http://userdocs.jokosher.org/Extensions/
>>>
>>>        Jokosher Website and User Documentation:
>>>        http://www.jokosher.org/
>>>        http://userdocs.jokosher.org/
>>>
>>> 6. Resources and Schedule
>>>     6.4. Steering Committee requested information
>>>        6.4.1. Consolidation C-team Name:
>>>         Desktop
>>>     6.5. ARC review type: FastTrack
>>>     6.6. ARC Exposure: open
>>>
>>>
>>> 6. Resources and Schedule
>>>     6.4. Steering Committee requested information
>>>        6.4.1. Consolidation C-team Name:
>>>         Desktop
>>>     6.5. ARC review type: FastTrack
>>>     6.6. ARC Exposure: open
>>>
>>> _______________________________________________
>>> opensolaris-arc mailing list
>>> opensolaris-arc@opensolaris.org
>>


