[media-types] Re: [IANA #1450625] application/vnd.vi mina.vma registration request

"Murray S. Kucherawy" <[email protected]> Tue, 12 May 2026 13:55:08 -0700
Newsgroups gmane.ietf.types
Message-ID <CAL0qLwYrNnkjjYjr4aFXYGEXUG5f_KP_rJUmcz1EYi8uu4=PHA@mail.gmail.com>
Approved.

-MSK

On Thu, Apr 30, 2026 at 11:42 AM Amanda Baber via RT <
[email protected]> wrote:

> Hi Murray,
>
> Could you check this revised registration request? They provided this list
> of changes:
>
> 1. Security considerations: Added an explicit statement that the payload
> is executable, per RFC 6838.
> 2. Section 2.1: Expanded with a concrete checklist of what reviewers
> should look for in untrusted scripts.
> 3. Interoperability considerations: Provided a brief rationale explaining
> why this is the correct answer for a vendor-specific type handled by the
> Vimina runtime.
> 4. Published specification: Verified and updated the URL to ensure it is
> publicly accessible.
>
> thanks,
> Amanda
>
> =====
>
> Name: Sunny Lynn
>
> Email: [email protected]
>
> Media type name: application
>
> Media subtype name: vnd.vimina.vma
>
> Required parameters: N/A
>
> Optional parameters: charset,version
>
> Encoding considerations: binary
>
> Security considerations:
>
> This media type defines an executable payload. VMA files contain
> automation scripts that are interpreted and executed by the Vimina runtime
> environment.
>
> 1.Script Execution
> VMA scripts can control mouse and keyboard input, which may pose security
> risks if scripts from untrusted sources are executed.
>
> 2.Recommended Practices
> 2.1. Review scripts before execution
> Before executing scripts from external sources, reviewers should examine
> the script for:
> Unauthorized input injection, keystroke capture, or credential harvesting
> Unexpected or unauthorized execution of external programs
> Unauthorized file system access, modification, or exfiltration
> Unintended network communication or data transmission
> Attempts to modify system settings or escalate privileges
> 2.2. Use sandboxing for untrusted scripts
> 2.3. Limit script permissions when possible
> 2.4. Log all script actions for audit purposes
>
> 3.Dangerous Operations
> The following operations should require user confirmation:
> Sending input to password fields
> Executing external programs
> Modifying system settings
>
> Interoperability considerations:
> This media type uses a text-based script format fully interpreted by the
> Vimina runtime. As a vendor-specific type intended primarily for the Vimina
> desktop automation tool, interoperability is governed by the Vimina
> implementation and its specification. The format does not depend on
> external encoding schemes or platform-specific binary structures.
>
> Published specification:
> https://github.com/Sunse666/Vimina/blob/main/docs/VMA-Specification.md
> https://sunse666.github.io/Vimina-docs/
>
> Applications which use this media: Vimina desktop automation tool
>
> Fragment identifier considerations: N/A
>
> Restrictions on usage: N/A
>
> Provisional registration? (standards tree only): No
>
> Additional information:
>
> 1.Deprecated alias names for this type: N/A
> 2.Magic number(s): N/A
> 3.File extension(s): .vma
> 4.Macintosh file type code: N/A
> 5.Object Identifiers: N/A
>
> General Comments: N/A
>
> Person to contact for further information:
>
> 1.Name: Sunny Lynn
> 2.Email: [email protected]
>
> Intended usage: COMMON
>
> Author/Change controller: Sunny Lynn
>

_______________________________________________
media-types mailing list -- [email protected]
To unsubscribe send an email to [email protected]