[media-types] Re: [IANA #1450625] application/vnd.vi mina.vma registration request
"Murray S. Kucherawy" <[email protected]> Tue, 12 May 2026 13:55:08 -0700
| Newsgroups | gmane.ietf.types |
|---|---|
| Message-ID | <CAL0qLwYrNnkjjYjr4aFXYGEXUG5f_KP_rJUmcz1EYi8uu4=PHA@mail.gmail.com> |
Approved. -MSK On Thu, Apr 30, 2026 at 11:42 AM Amanda Baber via RT < [email protected]> wrote: > Hi Murray, > > Could you check this revised registration request? They provided this list > of changes: > > 1. Security considerations: Added an explicit statement that the payload > is executable, per RFC 6838. > 2. Section 2.1: Expanded with a concrete checklist of what reviewers > should look for in untrusted scripts. > 3. Interoperability considerations: Provided a brief rationale explaining > why this is the correct answer for a vendor-specific type handled by the > Vimina runtime. > 4. Published specification: Verified and updated the URL to ensure it is > publicly accessible. > > thanks, > Amanda > > ===== > > Name: Sunny Lynn > > Email: [email protected] > > Media type name: application > > Media subtype name: vnd.vimina.vma > > Required parameters: N/A > > Optional parameters: charset,version > > Encoding considerations: binary > > Security considerations: > > This media type defines an executable payload. VMA files contain > automation scripts that are interpreted and executed by the Vimina runtime > environment. > > 1.Script Execution > VMA scripts can control mouse and keyboard input, which may pose security > risks if scripts from untrusted sources are executed. > > 2.Recommended Practices > 2.1. Review scripts before execution > Before executing scripts from external sources, reviewers should examine > the script for: > Unauthorized input injection, keystroke capture, or credential harvesting > Unexpected or unauthorized execution of external programs > Unauthorized file system access, modification, or exfiltration > Unintended network communication or data transmission > Attempts to modify system settings or escalate privileges > 2.2. Use sandboxing for untrusted scripts > 2.3. Limit script permissions when possible > 2.4. Log all script actions for audit purposes > > 3.Dangerous Operations > The following operations should require user confirmation: > Sending input to password fields > Executing external programs > Modifying system settings > > Interoperability considerations: > This media type uses a text-based script format fully interpreted by the > Vimina runtime. As a vendor-specific type intended primarily for the Vimina > desktop automation tool, interoperability is governed by the Vimina > implementation and its specification. The format does not depend on > external encoding schemes or platform-specific binary structures. > > Published specification: > https://github.com/Sunse666/Vimina/blob/main/docs/VMA-Specification.md > https://sunse666.github.io/Vimina-docs/ > > Applications which use this media: Vimina desktop automation tool > > Fragment identifier considerations: N/A > > Restrictions on usage: N/A > > Provisional registration? (standards tree only): No > > Additional information: > > 1.Deprecated alias names for this type: N/A > 2.Magic number(s): N/A > 3.File extension(s): .vma > 4.Macintosh file type code: N/A > 5.Object Identifiers: N/A > > General Comments: N/A > > Person to contact for further information: > > 1.Name: Sunny Lynn > 2.Email: [email protected] > > Intended usage: COMMON > > Author/Change controller: Sunny Lynn > _______________________________________________ media-types mailing list -- [email protected] To unsubscribe send an email to [email protected]