Re: [oS-EN] Image magick refuses to convert a true jpg file

"Carlos E. R." <[email protected]>
Newsgroups gmane.linux.suse.general
Message-ID <[email protected]>
On 2026-06-16 14:14, Simon Lees wrote:
> On 16/6/26 19:31, Carlos E. R. wrote:
>> On 2026-06-16 11:57, Simon Lees wrote:
>>> On 16/6/26 11:04, Masaru Nomiya wrote:
>>>> Hello,
>>>>
>>>> In the Message;
>>>>
>>>>    Subject    : Re: [oS-EN] Image magick refuses to convert a true 
>>>> jpg file
>>>>    Message-ID : <[email protected]>
>>>>    Date & Time: Tue, 16 Jun 2026 10:19:20 +0930
>>>>
>>>> [SL] == Simon Lees <[email protected]> has written:
>>>>
>>>> SL>  On 16/6/26 03:51, Carlos E. R. wrote:
>>>>
>>>> CER>> cer@Laicolasse:~/Photos/Para compartir con...> magick convert
>>>> CER>> IMG_20260615_195853218.jpg F_IMG_20260615_195853218.jpg
>>>> CER>> WARNING: The convert command is deprecated in IMv7, use 
>>>> "magick" instead of
>>>> CER>> "convert" or "magick convert"
>>>> CER>> convert: attempt to perform an operation not allowed by the
>>>> CER>> security policy
>>>> [...]
>>>>
>>>> SL>  It seems like it was a change in security policies. I had to
>>>> SL>  install ImageMagick-config-7-upstream-open to fix a bunch of my
>>>> SL>  package builds that were doing something similar.
>>>>
>>>> In that case, wouldn't the risk of vulnerabilities increase, since
>>>> only some resource limits are set but there are virtually no security
>>>> restrictions in place?
>>>>
>>>> In other words, I think the configuration Carlos is using is desirable
>>>> because it closely resembles the "web safe" security policy
>>>> recommended in the official ImageMagick documentation, don't you
>>>> think?
>>>
>>> The "web safe" version is designed for handling untrusted images that 
>>> users upload to your webserver that you may then use imagemagick to 
>>> do things like creating thumbnails.
>>>
>>> If your images come from a trusted source then using one of the other 
>>> security policies is fine.
>>>
>>> In my case I use imagemagick to recolor icons and other images that 
>>> are part of enlightenment themes, to do this with my existing script 
>>> I need to use the more flexible open policy. Because I know that all 
>>> the images I am using with imagemagick were either created by the 
>>> upstream enlightenment devs I know this is perfectly safe. If I was 
>>> using imagemagick to process images uploaded to a pastebin site then 
>>> it would not be.
>>
>> Should I open a bug report?
>>
>> I am using the default policy of Leap 16.0
> 
> I believe this is the intended behavior, imagemagick in Leap comes from 
> SLES where having a very safe policy by default and allowing admins to 
> open it up as needed is most certainly the desired behavior.
> 
> Its probably also the desired behavior for a percentage of Leap machines 
> as well and its not like its the sort of package that sees regular use 
> on the desktop to the point you may consider shipping a different policy 
> if the user selects a desktop pattern.


The problem is the "..." in the name of one directory.

-- 
Cheers / Saludos,

		Carlos E. R.

   (from openSUSE 16.0 (Laicolasse))
OpenPGP_signature.asc (application/pgp-signature, 203 B)
-----BEGIN PGP SIGNATURE-----

wmMEABEIACMWIQQZEb51mJKK1KpcU/W1MxgcbY1H1QUCajFJIgUDAAAAAAAKCRC1MxgcbY1H1RuN
AJ99DJhMG9sECIJYRhnCnvh8KZusdwCfelDwpparQ54aGxHmOAQ+aYzLW/s=
=PPdf
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.