Re: Might --enable-compile-inits make things more secure?
Chris Liddell <[email protected]> Thu, 13 Dec 2018 10:50:28 +0000
| Newsgroups | gmane.comp.printing.ghostscript.devel |
|---|---|
| Message-ID | <[email protected]> |
On 13/12/2018 10:15, Johannes Meixner wrote: > <SNIP> > Of course and when such PostScript features are needed > Ghostscript must be run in unrestricted mode. > > > Bottom line: > What I am basically asking for is a merciless restricted mode > where security takes precedence over "it just works", > cf. "Security: Make Things Not Just Work" in > https://en.opensuse.org/SDB:CUPS_and_SANE_Firewall_settings From the point of view of the vast majority of users, what you're asking for is a restricted mode where security takes precedence over "it works", which I think is a rather pointless exercise. Fundamentally breaking one of the most common ways of using Ghostscript (or any package) doesn't seem like a useful way to go, to me. Effectively, we'd be forcing practically everyone (cups and imagemagick included) to run in "unsafe mode". Chris