Re: [oS-EN] Image magick refuses to convert a true jpg file
"Carlos E. R." <[email protected]>
| Newsgroups | gmane.linux.suse.general |
|---|---|
| Message-ID | <[email protected]> |
On 2026-06-16 11:57, Simon Lees wrote: > On 16/6/26 11:04, Masaru Nomiya wrote: >> Hello, >> >> In the Message; >> >> Subject : Re: [oS-EN] Image magick refuses to convert a true jpg >> file >> Message-ID : <[email protected]> >> Date & Time: Tue, 16 Jun 2026 10:19:20 +0930 >> >> [SL] == Simon Lees <[email protected]> has written: >> >> SL> On 16/6/26 03:51, Carlos E. R. wrote: >> >> CER>> cer@Laicolasse:~/Photos/Para compartir con...> magick convert >> CER>> IMG_20260615_195853218.jpg F_IMG_20260615_195853218.jpg >> CER>> WARNING: The convert command is deprecated in IMv7, use "magick" >> instead of >> CER>> "convert" or "magick convert" >> CER>> convert: attempt to perform an operation not allowed by the >> CER>> security policy >> [...] >> >> SL> It seems like it was a change in security policies. I had to >> SL> install ImageMagick-config-7-upstream-open to fix a bunch of my >> SL> package builds that were doing something similar. >> >> In that case, wouldn't the risk of vulnerabilities increase, since >> only some resource limits are set but there are virtually no security >> restrictions in place? >> >> In other words, I think the configuration Carlos is using is desirable >> because it closely resembles the "web safe" security policy >> recommended in the official ImageMagick documentation, don't you >> think? > > The "web safe" version is designed for handling untrusted images that > users upload to your webserver that you may then use imagemagick to do > things like creating thumbnails. > > If your images come from a trusted source then using one of the other > security policies is fine. > > In my case I use imagemagick to recolor icons and other images that are > part of enlightenment themes, to do this with my existing script I need > to use the more flexible open policy. Because I know that all the images > I am using with imagemagick were either created by the upstream > enlightenment devs I know this is perfectly safe. If I was using > imagemagick to process images uploaded to a pastebin site then it would > not be. Should I open a bug report? I am using the default policy of Leap 16.0 -- Cheers / Saludos, Carlos E. R. (from openSUSE 16.0 (Laicolasse))
OpenPGP_signature.asc
(application/pgp-signature, 203 B)
-----BEGIN PGP SIGNATURE----- wmMEABEIACMWIQQZEb51mJKK1KpcU/W1MxgcbY1H1QUCajEe9QUDAAAAAAAKCRC1MxgcbY1H1QCz AJ905NDtuAnbl4lsv4YynCPoSkdVMQCeLMNXGWH3y8i3OCGFlKmOmF8O1/4= =bNsr -----END PGP SIGNATURE-----