[Opensim-users] oddities with SecondInventory and Opensim 770x

Lc lcc1967 at gmail.com
Mon Dec 15 17:00:37 UTC 2008


well, Justin raised a good issue : Opensim need to be "clients proof" , ie
checking for any odditites a a tainted client could inject in the system.
I'm sure as soon as currencies will be implemented at intergrid level, we
will see some kind of attacks coming from tainted clients .


SM

On Mon, Dec 15, 2008 at 5:55 PM, Lc <lcc1967 at gmail.com> wrote:

> what i found until now :
>
> The previously inventory items are still in the db, at least the inventory
> table is not altered whatsoever, but the freshly uploaded items are not
> inserted.
>
> I need to "sql" the association inventory / Asset now.
>
> Sacha
>
>
> On Mon, Dec 15, 2008 at 5:35 PM, Justin Clark-Casey <
> jjustincc at googlemail.com> wrote:
>
>> James Stallings II wrote:
>> > Interesting choice of words: "... since OS
>> > appears to be vulnerable to any application using libSL, browsers
>> > included."
>> >
>> > This begs the questions: can opensim distinguish between clients? Should
>> > it as a part of the core functionality?
>> >
>> > I think the answer to the former, at least, is a resounding 'No".
>> >
>> > In any event, last I heard, use of third-party inventory transfer
>> > systems was not supported by the opensim team, if not actively
>> > discouraged (at least, that was the case in the past).
>>
>> I don't think there is either active encouragement or discouragement of
>> the use of such systems.  I think it has little
>> to do with the OpenSim project.
>>
>> However, I believe that we should aim to be robust in the face of clients
>> that do unexpected things - the client is in
>> the hands of the enemy, as Raph Koster said.
>>
>> >
>> > I think that at the very least, it is safe to say "use at your own
>> risk".
>> >
>> > There are numerous good reasons why - not the least of which is that
>> > they may in fact damage your inventory, not to mention the
>> > near-impossible task of supporting someone else's closed-source
>> application.
>> >
>> > I am *truly* sorry that Sacha is having a problem with this, but I
>> > really think he needs to seek out support from the vendor.
>> >
>> > In the interim, if there is in fact a problem with SI corrupting
>> > inventories, we should perhaps investigate some method of controlling
>> > its use.
>> >
>> > Cheers
>> > James
>> >
>> >
>> > On Mon, Dec 15, 2008 at 9:41 AM, John Hopkin
>> > <opensim at jfhopkin.karoo.co.uk <mailto:opensim at jfhopkin.karoo.co.uk>>
>> wrote:
>> >
>> >     With all due respect, surely:
>> >
>> >     (a) This doesn't look like the cache glitch - with that, you see
>> your
>> >     pre-existing inv items, just not the new ones.  It looks to me like
>> >     Sacha is saying the inventory is actually rendered unusable
>> (permanent
>> >     "loading" message).
>> >
>> >     (b) If (a) is correct, this is *not* purely a SI problem, since OS
>> >     appears to be vulnerable to any application using libSL, browsers
>> >     included.  An application using a standard API should not be able to
>> >     cause damage to the underlying database.
>> >
>> >     Even if SI had actually deleted the entire inventory or something,
>> >     surely you'd just see an empty inv, not "loading"?
>> >
>> >     All the best
>> >     John
>> >
>> >     James Stallings II wrote:
>> >
>> >      >Sacha, typically, from what I understand, a cache-clear is req'd
>> >     before any
>> >      >inventory imported with second inventory will be seen in the av's
>> >     inventory.
>> >      >
>> >      >That being said, second inventory questions are perhaps best asked
>> >      >elsewhere.
>> >      >
>> >      >Cheers
>> >      >James
>> >      >
>> >      >
>> >      >On Mon, Dec 15, 2008 at 7:24 AM, Lc <lcc1967 at gmail.com
>> >     <mailto:lcc1967 at gmail.com>> wrote:
>> >      >
>> >      >> Hello all,
>> >      >>
>> >      >> Some users report me that issue and I'd appreciate if someone
>> >     can reproduce
>> >      >> that :
>> >      >> Beware, the avatar won't recover the inventory, please don't
>> >     test that with
>> >      >> your regular "you"
>> >      >>
>> >      >> Create a new avatar
>> >      >> go InWolrd
>> >      >> Grab some object / skin / shape / items in order to fill its
>> >     inventory
>> >      >> Check the inventory = No issue, all should be there.
>> >      >> Eventually logOff/On to countercheck
>> >      >>
>> >      >> Now the "odd" part :
>> >      >>
>> >      >> Start SecondInventory
>> >      >> upload any object/skin whatever inworld
>> >      >> Stop SI
>> >      >>
>> >      >> Log the avatar inworld
>> >      >> Now the inventory will stay "loading"
>> >      >> No shape / skin is loaded
>> >      >> you are ruthed
>> >      >>
>> >      >> I looked in the DB and couldn't find any items loaded with
>> >     SecondInventory
>> >      >>
>> >      >> Can someone test that ?
>> >      >>
>> >      >> thanks
>> >      >>
>> >      >> Sacha
>> >      >>
>> >      >> _______________________________________________
>> >      >> Opensim-users mailing list
>> >      >> Opensim-users at lists.berlios.de
>> >     <mailto:Opensim-users at lists.berlios.de>
>> >      >> https://lists.berlios.de/mailman/listinfo/opensim-users
>> >      >>
>> >      >>
>> >     _______________________________________________
>> >     Opensim-users mailing list
>> >     Opensim-users at lists.berlios.de <mailto:
>> Opensim-users at lists.berlios.de>
>> >     https://lists.berlios.de/mailman/listinfo/opensim-users
>> >
>> >
>> >
>> >
>> > --
>> > ===================================
>> > The wind
>> > scours the earth for prayers
>> > The night obscures them
>> >
>> > http://osgrid.org
>> > http://del.icio.us/SPQR
>> > http://twitter.com/jstallings2
>> > http://www.linkedin.com/pub/5/770/a49
>> >
>> >
>> > ------------------------------------------------------------------------
>> >
>> > _______________________________________________
>> > Opensim-users mailing list
>> > Opensim-users at lists.berlios.de
>> > https://lists.berlios.de/mailman/listinfo/opensim-users
>>
>>
>> --
>> justincc
>> Justin Clark-Casey
>> http://justincc.wordpress.com
>> _______________________________________________
>> Opensim-users mailing list
>> Opensim-users at lists.berlios.de
>> https://lists.berlios.de/mailman/listinfo/opensim-users
>>
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://opensimulator.org/pipermail/opensim-users/attachments/20081215/e09c8c37/attachment.html>


More information about the Opensim-users mailing list