Re: Might --enable-compile-inits make things more secure?

Chris Liddell <[email protected]> Thu, 13 Dec 2018 10:50:28 +0000
Newsgroups gmane.comp.printing.ghostscript.devel
Message-ID <[email protected]>
On 13/12/2018 10:15, Johannes Meixner wrote:
> 
<SNIP>
> Of course and when such PostScript features are needed
> Ghostscript must be run in unrestricted mode.
> 
> 
> Bottom line:
> What I am basically asking for is a merciless restricted mode
> where security takes precedence over "it just works",
> cf. "Security: Make Things Not Just Work" in
> https://en.opensuse.org/SDB:CUPS_and_SANE_Firewall_settings

From the point of view of the vast majority of users, what you're asking
for is a restricted mode where security takes precedence over "it
works", which I think is a rather pointless exercise.

Fundamentally breaking one of the most common ways of using Ghostscript
(or any package) doesn't seem like a useful way to go, to me.

Effectively, we'd be forcing practically everyone (cups and imagemagick
included) to run in "unsafe mode".

Chris