Re: [oS-EN] Image magick refuses to convert a true jpg file
Simon Lees <[email protected]>
| Newsgroups | gmane.linux.suse.general |
|---|---|
| Message-ID | <[email protected]> |
On 16/6/26 19:31, Carlos E. R. wrote: > On 2026-06-16 11:57, Simon Lees wrote: >> On 16/6/26 11:04, Masaru Nomiya wrote: >>> Hello, >>> >>> In the Message; >>> >>> Subject : Re: [oS-EN] Image magick refuses to convert a true >>> jpg file >>> Message-ID : <[email protected]> >>> Date & Time: Tue, 16 Jun 2026 10:19:20 +0930 >>> >>> [SL] == Simon Lees <[email protected]> has written: >>> >>> SL> On 16/6/26 03:51, Carlos E. R. wrote: >>> >>> CER>> cer@Laicolasse:~/Photos/Para compartir con...> magick convert >>> CER>> IMG_20260615_195853218.jpg F_IMG_20260615_195853218.jpg >>> CER>> WARNING: The convert command is deprecated in IMv7, use >>> "magick" instead of >>> CER>> "convert" or "magick convert" >>> CER>> convert: attempt to perform an operation not allowed by the >>> CER>> security policy >>> [...] >>> >>> SL> It seems like it was a change in security policies. I had to >>> SL> install ImageMagick-config-7-upstream-open to fix a bunch of my >>> SL> package builds that were doing something similar. >>> >>> In that case, wouldn't the risk of vulnerabilities increase, since >>> only some resource limits are set but there are virtually no security >>> restrictions in place? >>> >>> In other words, I think the configuration Carlos is using is desirable >>> because it closely resembles the "web safe" security policy >>> recommended in the official ImageMagick documentation, don't you >>> think? >> >> The "web safe" version is designed for handling untrusted images that >> users upload to your webserver that you may then use imagemagick to do >> things like creating thumbnails. >> >> If your images come from a trusted source then using one of the other >> security policies is fine. >> >> In my case I use imagemagick to recolor icons and other images that >> are part of enlightenment themes, to do this with my existing script I >> need to use the more flexible open policy. Because I know that all the >> images I am using with imagemagick were either created by the upstream >> enlightenment devs I know this is perfectly safe. If I was using >> imagemagick to process images uploaded to a pastebin site then it >> would not be. > > Should I open a bug report? > > I am using the default policy of Leap 16.0 I believe this is the intended behavior, imagemagick in Leap comes from SLES where having a very safe policy by default and allowing admins to open it up as needed is most certainly the desired behavior. Its probably also the desired behavior for a percentage of Leap machines as well and its not like its the sort of package that sees regular use on the desktop to the point you may consider shipping a different policy if the user selects a desktop pattern. -- Simon Lees (Simotek) http://simotek.net Emergency Update Team keybase.io/simotek SUSE Linux Adelaide Australia, UTC+10:30 GPG Fingerprint: 5B87 DB9D 88DC F606 E489 CEC5 0922 C246 02F0 014B