Commit b3fb0fb04 for imagemagick.org

commit b3fb0fb042f71c21779a3064fc2eec4199d87db7
Author: Cristy <urban-warrior@imagemagick.org>
Date:   Sun Oct 4 07:43:42 2026 -0400

    clarify comments

diff --git a/config/policy-limited.xml b/config/policy-limited.xml
index 4d20045fa..ab49c6d82 100644
--- a/config/policy-limited.xml
+++ b/config/policy-limited.xml
@@ -16,98 +16,122 @@
     value   CDATA   #IMPLIED
   >
 ]>
+
 <!--
-  Creating a security policy that fits your specific local environment
-  before making use of ImageMagick is highly advised. You can find guidance on
-  setting up this policy at https://imagemagick.org/script/security-policy.php,
-  and it's important to verify your policy using the validation tool located
-  at https://imagemagick-secevaluator.doyensec.com/. We also strongly
-  recommend that all users validate their security assumptions by testing their
-  configurations after making any policy changes. This helps ensure that the
-  intended restrictions are functioning as expected in their specific
-  deployment environment.
-
-
-  Limited ImageMagick security policy:
-
-  The primary objective of the limited security policy is to find a
-  middle ground between convenience and security. This policy involves the
-  deactivation of potentially hazardous functionalities, like specific coders
-  such as SVG or HTTP. Furthermore, it establishes several constraints on
-  the utilization of resources like memory, storage, and processing duration,
-  all of which are adjustable. This policy proves advantageous in situations
-  where there's a need to mitigate the potential threat of handling possibly
-  malicious or demanding images, all while retaining essential capabilities
-  for prevalent image formats.
+  ImageMagick Security Policy
+
+  This policy is intended for general-purpose deployments that process
+  potentially untrusted images while maintaining support for common image
+  formats and workflows.
+
+  The policy balances usability and security by:
+
+    * Limiting resource consumption (CPU time, memory, disk usage, image
+      dimensions, and sequence length).
+    * Blocking potentially dangerous path access methods such as indirect
+      reads (@files) and pipes.
+    * Preventing access to sensitive filesystem locations.
+    * Restricting high-risk coders that have historically been involved in
+      external content processing, scripting, or complex parsers.
+    * Limiting large allocation requests that could otherwise lead to
+      excessive memory consumption.
+
+  After modifying this policy, test and validate the resulting behavior in
+  your environment to ensure the restrictions are operating as intended.
+
+  Documentation:
+    https://imagemagick.org/script/security-policy.php
+
+  Policy Evaluator:
+    https://imagemagick-secevaluator.doyensec.com/
 -->
+
 <policymap>
-  <!-- Set maximum parallel threads. -->
+
+  <!-- Maximum number of worker threads. -->
   <policy domain="resource" name="thread" value="4"/>
-  <!-- Set maximum time in seconds. When this limit is exceeded, an exception
-       is thrown and processing stops. -->
+
+  <!-- Maximum execution time (seconds) before processing is terminated. -->
   <policy domain="resource" name="time" value="240"/>
-  <!-- Set maximum number of open pixel cache files. When this limit is
-       exceeded, any subsequent pixels cached to disk are closed and reopened
-       on demand. -->
+
+  <!-- Maximum number of simultaneously open pixel cache files. -->
   <policy domain="resource" name="file" value="768"/>
-  <!-- Set maximum amount of memory in bytes to allocate for the pixel cache
-       from the heap. When this limit is exceeded, the image pixels are cached
-       to memory-mapped disk. -->
+
+  <!-- Maximum heap memory used for pixel cache data. Excess pixels are
+       stored in mapped or disk-backed cache. -->
   <policy domain="resource" name="memory" value="768MiB"/>
-  <!-- Set maximum amount of memory map in bytes to allocate for the pixel
-       cache. When this limit is exceeded, the image pixels are cached to
-       disk. -->
+
+  <!-- Maximum memory-mapped pixel cache size. Excess cache data is
+       written to disk. -->
   <policy domain="resource" name="map" value="2GiB"/>
-  <!-- Set the maximum width * height of an image that can reside in the pixel
-       cache memory. Images that exceed the area limit are cached to disk. -->
+
+  <!-- Maximum in-memory image area before pixels are cached to disk. -->
   <policy domain="resource" name="area" value="32MP"/>
-  <!-- Set maximum amount of disk space in bytes permitted for use by the pixel
-       cache. When this limit is exceeded, the pixel cache is not created
-       and an exception is thrown. -->
+
+  <!-- Maximum disk space available for pixel cache operations. -->
   <policy domain="resource" name="disk" value="2GiB"/>
-  <!-- Set the maximum length of an image sequence.  When this limit is
-       exceeded, an exception is thrown. -->
+
+  <!-- Maximum number of images permitted in a sequence. -->
   <policy domain="resource" name="list-length" value="64"/>
-  <!-- Set the maximum width of an image.  When this limit is exceeded, an
-       exception is thrown. -->
+
+  <!-- Maximum image width. -->
   <policy domain="resource" name="width" value="16KP"/>
-  <!-- Set the maximum height of an image.  When this limit is exceeded, an
-       exception is thrown. -->
+
+  <!-- Maximum image height. -->
   <policy domain="resource" name="height" value="16KP"/>
-  <!-- Periodically yield the CPU for at least the time specified in
-       milliseconds. -->
+
+  <!-- Optional: periodically yield CPU time to improve system responsiveness. -->
   <!-- <policy domain="resource" name="throttle" value="2"/> -->
-  <!-- Do not create temporary files in the default shared directories, instead
-       specify a private area to store only ImageMagick temporary files. -->
+
+  <!-- Optional: store temporary files in a dedicated private directory. -->
   <!-- <policy domain="resource" name="temporary-path" value="/magick/tmp/"/> -->
-  <!-- Force memory initialization by memory mapping select memory
-       allocations. -->
+
+  <!-- Optional: force anonymous memory mapping for selected cache allocations. -->
   <!-- <policy domain="cache" name="memory-map" value="anonymous"/> -->
-  <!-- Ensure all image data is fully flushed and synchronized to disk. -->
+
+  <!-- Optional: fully synchronize image cache data to disk before closing. -->
   <!-- <policy domain="cache" name="synchronize" value="true"/> -->
-  <!-- Replace passphrase for secure distributed processing -->
-  <!-- <policy domain="cache" name="shared-secret" value="secret-passphrase" stealth="true"/> -->
-  <!-- Do not permit any delegates to execute. -->
+
+  <!-- Optional: shared secret used by distributed pixel cache operations.
+       Replace with a site-specific value if enabled. -->
+  <!-- <policy domain="cache" name="shared-secret"
+            value="secret-passphrase" stealth="true"/> -->
+
+  <!-- Optional: disable execution of all delegates. -->
   <!-- <policy domain="delegate" rights="none" pattern="*"/> -->
-  <!-- Do not permit any image filters to load. -->
+
+  <!-- Optional: disable loading of all image filter modules. -->
   <!-- <policy domain="filter" rights="none" pattern="*"/> -->
-  <!-- Don't read/write from/to stdin/stdout. -->
+
+  <!-- Optional: disable stdin/stdout image processing ("-"). -->
   <!-- <policy domain="path" rights="none" pattern="-"/> -->
-  <!-- don't read sensitive paths. -->
+
+  <!-- Prevent access to sensitive system configuration files. -->
   <policy domain="path" rights="none" pattern="/etc/*"/>
-  <!-- Indirect reads are not permitted. -->
+
+  <!-- Prevent indirect file reads using @filename syntax. -->
   <policy domain="path" rights="none" pattern="@*"/>
-  <!-- Pipes are not permitted. -->
+
+  <!-- Prevent use of pipes for reading or writing image data. -->
   <policy domain="path" rights="none" pattern="|*"/>
-  <!-- These image types are security risks on read, but write is fine -->
-  <policy domain="module" rights="write" pattern="{MSL,MVG,PDF,PS,SVG,TXT,URL,XPS}"/>
-  <!-- This policy sets the number of times to replace content of certain
-       memory buffers and temporary files before they are freed or deleted. -->
+
+  <!--
+    Restrict high-risk coders.
+
+    Read access is denied while write access remains permitted.
+    This allows ImageMagick to generate these formats without accepting
+    potentially untrusted input through them.
+  -->
+  <policy domain="module" rights="write"
+          pattern="{MSL,MVG,PDF,PS,SVG,TXT,URL,XPS}"/>
+
+  <!-- Optional: overwrite temporary files and buffers before deletion. -->
   <!-- <policy domain="system" name="shred" value="1"/> -->
-  <!-- Enable the initialization of buffers with zeros, resulting in a minor
-       performance penalty but with improved security. -->
+
+  <!-- Optional: initialize allocated memory with zeros for improved security. -->
   <!-- <policy domain="system" name="memory-map" value="anonymous"/> -->
-  <!-- Set the maximum amount of memory in bytes that are permitted for
-       allocation requests. -->
+
+  <!-- Maximum size of a single allocation request. -->
   <policy domain="system" name="max-memory-request" value="512MiB"/>
+
 </policymap>
diff --git a/config/policy-open.xml b/config/policy-open.xml
index 4c3c8f36e..44edfc97a 100644
--- a/config/policy-open.xml
+++ b/config/policy-open.xml
@@ -1,9 +1,7 @@
 <?xml version="1.0" encoding="UTF-8"?>
 <!DOCTYPE policymap [
   <!ELEMENT policymap (policy)*>
-  <!ATTLIST policymap
-    xmlns CDATA #FIXED ""
-  >
+  <!ATTLIST policymap xmlns CDATA #FIXED "">

   <!ELEMENT policy EMPTY>
   <!ATTLIST policy
@@ -16,157 +14,206 @@
     value   CDATA   #IMPLIED
   >
 ]>
+
 <!--
-  Creating a security policy that fits your specific local environment
-  before making use of ImageMagick is highly advised. You can find guidance on
-  setting up this policy at https://imagemagick.org/script/security-policy.php,
-  and it's important to verify your policy using the validation tool located
-  at https://imagemagick-secevaluator.doyensec.com/. We also strongly
-  recommend that all users validate their security assumptions by testing their
-  configurations after making any policy changes. This helps ensure that the
-  intended restrictions are functioning as expected in their specific
-  deployment environment.
+  ImageMagick Security Policy Configuration
+  ========================================

+  This file provides the default "open" ImageMagick security policy along with
+  numerous optional hardening examples. The default configuration permits broad
+  functionality and is appropriate only for trusted environments such as
+  systems protected by firewalls, isolated containers, or tightly controlled
+  internal workloads.

-  Open ImageMagick security policy:
+  For untrusted input or multi-tenant environments, review and customize this
+  policy to match your security requirements.

-  The default policy for ImageMagick installations is the open security
-  policy. This policy is designed for usage in secure settings like those
-  protected by firewalls or within Docker containers. Within this framework,
-  ImageMagick enjoys broad access to resources and functionalities. This policy
-  provides convenient and adaptable options for image manipulation. However,
-  it's important to note that it might present security vulnerabilities in
-  less regulated conditions. Thus, organizations should thoroughly assess
-  the appropriateness of the open policy according to their particular use
-  case and security prerequisites.
+  Additional documentation:
+    https://imagemagick.org/script/security-policy.php

-  ImageMagick security policies in a nutshell:
+  Security policy validator:
+    https://imagemagick-secevaluator.doyensec.com/

-  Domains include system, delegate, coder, filter, module, path, or resource.
+  Important:
+    * Security policies should be reviewed for your specific deployment.
+    * Test all policy changes to confirm they behave as expected.
+    * Rules are processed in order.
+    * Policy names, domains, and patterns are case-sensitive.

-  Rights include none, read, write, execute and all.  Use | to combine them,
-  for example: "read | write" to permit read from, or write to, a path.
+  Domains:
+    system, resource, cache, delegate, filter, module, path, and coder

-  Use a glob expression as a pattern.
+  Rights:
+    none, read, write, execute, all

-  Suppose we do not want users to process MPEG video images, use this policy:
+  Multiple rights may be combined:
+    rights="read|write"

-    <policy domain="module" rights="none" pattern="video" />
+  Patterns use ImageMagick glob matching.

-  Here we do not want users reading images from HTTP:
+  Example: disable all video modules

-    <policy domain="coder" rights="none" pattern="HTTP" />
+    <policy domain="module" rights="none" pattern="VIDEO"/>

-  The /repository file system is restricted to read only.  We use a glob
-  expression to match all paths that start with /repository:
+  Example: disable HTTP image reads

-    <policy domain="path" rights="read" pattern="/repository/*" />
+    <policy domain="coder" rights="none" pattern="HTTP"/>

-  Prevent users from executing any image filters:
+  Example: permit read-only access to a repository

-    <policy domain="filter" rights="none" pattern="*" />
+    <policy domain="path" rights="read"
+      pattern="/repository/*"/>

-  Cache large images to disk rather than memory:
+  Example: disable all image filters

-    <policy domain="resource" name="area" value="1GP"/>
+    <policy domain="filter" rights="none" pattern="*"/>

-  Use the default system font unless overridden by the application:
+  Example: restrict processing to common web-safe formats

-    <policy domain="system" name="font" value="/usr/share/fonts/favorite.ttf"/>
+    <policy domain="delegate" rights="none" pattern="*"/>
+    <policy domain="filter" rights="none" pattern="*"/>
+    <policy domain="coder" rights="none" pattern="*"/>
+    <policy domain="coder" rights="read|write"
+      pattern="{GIF,JPEG,PNG,WEBP}"/>
+-->

-  Define arguments for the memory, map, area, width, height and disk resources
-  with SI prefixes (.e.g 100MB).  In addition, resource policies are maximums
-  for each instance of ImageMagick (e.g. policy memory limit 1GB, -limit 2GB
-  exceeds policy maximum so memory limit is 1GB).
+<policymap>

-  Rules are processed in order.  Here we want to restrict ImageMagick to only
-  read or write a small subset of proven web-safe image types:
+  <!-- Deny use of undefined domains. -->
+  <policy domain="Undefined" rights="none"/>

-    <policy domain="delegate" rights="none" pattern="*" />
-    <policy domain="filter" rights="none" pattern="*" />
-    <policy domain="coder" rights="none" pattern="*" />
-    <policy domain="coder" rights="read|write" pattern="{GIF,JPEG,PNG,WEBP}" />
+  <!-- ================================================================== -->
+  <!-- Resource Policies                                                   -->
+  <!-- ================================================================== -->

-  See https://imagemagick.org/script/security-policy.php for a deeper
-  understanding of ImageMagick security policies.
--->
-<policymap>
-  <policy domain="Undefined" rights="none"/>
-  <!-- Set maximum parallel threads. -->
+  <!-- Maximum number of worker threads. -->
   <!-- <policy domain="resource" name="thread" value="2"/> -->
-  <!-- Set maximum time to live in seconds or mnemonics, e.g. "2 minutes". When
-       this limit is exceeded, an exception is thrown and processing stops. -->
+
+  <!-- Maximum execution time before processing is aborted. -->
   <!-- <policy domain="resource" name="time" value="120"/> -->
-  <!-- Set maximum number of open pixel cache files. When this limit is
-       exceeded, any subsequent pixels cached to disk are closed and reopened
-       on demand. -->
+
+  <!-- Maximum number of open pixel cache files. -->
   <!-- <policy domain="resource" name="file" value="768"/> -->
-  <!-- Set maximum amount of memory in bytes to allocate for the pixel cache
-       from the heap. When this limit is exceeded, the image pixels are cached
-       to memory-mapped disk. -->
+
+  <!-- Maximum heap memory available to the pixel cache. -->
   <!-- <policy domain="resource" name="memory" value="256MiB"/> -->
-  <!-- Set maximum amount of memory map in bytes to allocate for the pixel
-       cache. When this limit is exceeded, the image pixels are cached to
-       disk. -->
+
+  <!-- Maximum memory-mapped cache allocation. -->
   <!-- <policy domain="resource" name="map" value="512MiB"/> -->
-  <!-- Set the maximum width * height of an image that can reside in the pixel
-       cache memory. Images that exceed the area limit are cached to disk. -->
+
+  <!-- Maximum image area (width × height) cached in memory. -->
   <!-- <policy domain="resource" name="area" value="16KP"/> -->
-  <!-- Set maximum amount of disk space in bytes permitted for use by the pixel
-       cache. When this limit is exceeded, the pixel cache is not created
-       and an exception is thrown. -->
+
+  <!-- Maximum disk space available to the pixel cache. -->
   <!-- <policy domain="resource" name="disk" value="1GiB"/> -->
-  <!-- Set the maximum length of an image sequence.  When this limit is
-       exceeded, an exception is thrown. -->
+
+  <!-- Maximum number of images permitted in a sequence. -->
   <!-- <policy domain="resource" name="list-length" value="32"/> -->
-  <!-- Set the maximum width of an image.  When this limit is exceeded, an
-       exception is thrown. -->
+
+  <!-- Maximum image width. -->
   <!-- <policy domain="resource" name="width" value="8KP"/> -->
-  <!-- Set the maximum height of an image.  When this limit is exceeded, an
-       exception is thrown. -->
+
+  <!-- Maximum image height. -->
   <!-- <policy domain="resource" name="height" value="8KP"/> -->
-  <!-- Periodically yield the CPU for at least the time specified in
-       milliseconds. -->
+
+  <!-- Yield the CPU periodically (milliseconds). -->
   <!-- <policy domain="resource" name="throttle" value="2"/> -->
-  <!-- Do not create temporary files in the default shared directories, instead
-       specify a private area to store only ImageMagick temporary files. -->
-  <!-- <policy domain="resource" name="temporary-path" value="/magick/tmp/"/> -->
-  <!-- Force memory initialization by memory mapping select memory
-       allocations. -->
-  <!-- <policy domain="cache" name="memory-map" value="anonymous"/> -->
-  <!-- Ensure all image data is fully flushed and synchronized to disk. -->
-  <!-- <policy domain="cache" name="synchronize" value="true"/> -->
-  <!-- Replace passphrase for secure distributed processing -->
-  <!-- <policy domain="cache" name="shared-secret" value="secret-passphrase" stealth="true"/> -->
-  <!-- Do not permit any delegates to execute. -->
+
+  <!-- Use a private directory for ImageMagick temporary files. -->
+  <!-- <policy domain="resource" name="temporary-path"
+             value="/magick/tmp/"/> -->
+
+  <!-- ================================================================== -->
+  <!-- Pixel Cache Policies                                                -->
+  <!-- ================================================================== -->
+
+  <!-- Use anonymous memory mapping to initialize cache memory. -->
+  <!-- <policy domain="cache" name="memory-map"
+             value="anonymous"/> -->
+
+  <!-- Force cache data to be flushed and synchronized to disk. -->
+  <!-- <policy domain="cache" name="synchronize"
+             value="true"/> -->
+
+  <!-- Shared secret for distributed pixel cache clients. -->
+  <!-- <policy domain="cache" name="shared-secret"
+             value="secret-passphrase" stealth="true"/> -->
+
+  <!-- Maximum authenticated distributed pixel cache clients. -->
+  <!-- <policy domain="cache" name="max-dpc-clients"
+             value="128"/> -->
+
+  <!-- Maximum unauthenticated distributed pixel cache clients. -->
+  <!-- <policy domain="cache"
+             name="max-dpc-unauthenticated-clients"
+             value="16"/> -->
+
+  <!-- ================================================================== -->
+  <!-- Delegate and Filter Policies                                        -->
+  <!-- ================================================================== -->
+
+  <!-- Disable execution of all delegates. -->
   <!-- <policy domain="delegate" rights="none" pattern="*"/> -->
-  <!-- Do not permit any image filters to load. -->
+
+  <!-- Disable loading of all image filters. -->
   <!-- <policy domain="filter" rights="none" pattern="*"/> -->
-  <!-- Don't read/write from/to stdin/stdout. -->
+
+  <!-- ================================================================== -->
+  <!-- Path Restrictions                                                   -->
+  <!-- ================================================================== -->
+
+  <!-- Disallow stdin and stdout image I/O. -->
   <!-- <policy domain="path" rights="none" pattern="-"/> -->
-  <!-- don't read sensitive paths. -->
+
+  <!-- Prevent access to sensitive system locations. -->
   <!-- <policy domain="path" rights="none" pattern="/etc/*"/> -->
-  <!-- Indirect reads are not permitted. -->
+
+  <!-- Disable indirect file reads (@filename). -->
   <!-- <policy domain="path" rights="none" pattern="@*"/> -->
-  <!-- Pipes are not permitted. -->
+
+  <!-- Disable pipe execution. -->
   <!-- <policy domain="path" rights="none" pattern="|*"/> -->
-  <!-- These image types are security risks on read, but write is fine -->
-  <!-- <policy domain="module" rights="write" pattern="{MSL,MVG,PDF,PS,SVG,TXT,URL,XPS}"/> -->
-  <!-- This policy sets the number of times to replace content of certain
-       memory buffers and temporary files before they are freed or deleted. -->
+
+  <!-- ================================================================== -->
+  <!-- Module Restrictions                                                 -->
+  <!-- ================================================================== -->
+
+  <!--
+    Disable reading of higher-risk formats while still permitting writes.
+
+    Common candidates include:
+      MSL, MVG, PDF, PS, SVG, TXT, URL, and XPS
+
+    Review carefully before enabling.
+  -->
+  <!-- <policy domain="module" rights="write"
+             pattern="{MSL,MVG,PDF,PS,SVG,TXT,URL,XPS}"/> -->
+
+  <!-- ================================================================== -->
+  <!-- System Policies                                                     -->
+  <!-- ================================================================== -->
+
+  <!-- Overwrite temporary data before release or deletion. -->
   <!-- <policy domain="system" name="shred" value="1"/> -->
-  <!-- Enable the initialization of buffers with zeros, resulting in a minor
-       performance penalty but with improved security. -->
-  <!-- <policy domain="system" name="memory-map" value="anonymous"/> -->
-  <!-- Set the maximum amount of memory in bytes that are permitted for
-       allocation requests. -->
-  <!-- <policy domain="system" name="max-memory-request" value="256MiB"/> -->
-  <!-- If the basename of path is a symbolic link, the open fails -->
-  <!-- <policy domain="system" name="symlink" rights="none" pattern="follow"/> -->
-  <!-- Blocks all SVG entity‑substitution attempts by denying the svg:substitute-entities define -->
-  <!-- <policy domain="system" name="svg" rights="none" pattern="substitute-entities"/> -->
-  <!-- Set the maximum distributed pixel cache clients -->
-  <!-- <policy domain="cache" name="max-dpc-clients" value="128"/> -->
-  <!-- Set the maximum distributed pixel cache unauthenticated clients -->
-  <!-- <policy domain="cache" name="max-dpc-unauthenticated-clients" value="16"/> -->
+
+  <!-- Initialize newly allocated memory with zeros. -->
+  <!-- <policy domain="system" name="memory-map"
+             value="anonymous"/> -->
+
+  <!-- Maximum permitted single memory allocation request. -->
+  <!-- <policy domain="system" name="max-memory-request"
+             value="256MiB"/> -->
+
+  <!-- Refuse paths whose basename is a symbolic link. -->
+  <!-- <policy domain="system"
+             name="symlink"
+             rights="none"
+             pattern="follow"/> -->
+
+  <!-- Disable SVG entity substitution. -->
+  <!-- <policy domain="system"
+             name="svg"
+             rights="none"
+             pattern="substitute-entities"/> -->
+
 </policymap>
diff --git a/config/policy-secure.xml b/config/policy-secure.xml
index 2fc9f3600..d90b3b765 100644
--- a/config/policy-secure.xml
+++ b/config/policy-secure.xml
@@ -16,109 +16,123 @@
     value   CDATA   #IMPLIED
   >
 ]>
+
 <!--
-  Creating a security policy that fits your specific local environment
-  before making use of ImageMagick is highly advised. You can find guidance on
-  setting up this policy at https://imagemagick.org/script/security-policy.php,
-  and it's important to verify your policy using the validation tool located
-  at https://imagemagick-secevaluator.doyensec.com/. We also strongly
-  recommend that all users validate their security assumptions by testing their
-  configurations after making any policy changes. This helps ensure that the
-  intended restrictions are functioning as expected in their specific
-  deployment environment.
-
-
-  Secure ImageMagick security policy:
-
-  This stringent security policy prioritizes the implementation of
-  rigorous controls and restricted resource utilization to establish a
-  profoundly secure setting while employing ImageMagick. It deactivates
-  conceivably hazardous functionalities, including specific coders like
-  SVG or HTTP. The policy promotes the tailoring of security measures to
-  harmonize with the requirements of the local environment and the guidelines
-  of the organization. This protocol encompasses explicit particulars like
-  limitations on memory consumption, sanctioned pathways for reading and
-  writing, confines on image sequences, the utmost permissible duration of
-  workflows, allocation of disk space intended for image data, and even an
-  undisclosed passphrase for remote connections. By adopting this robust
-  policy, entities can elevate their overall security stance and alleviate
-  potential vulnerabilities.
+  ImageMagick Security Policy
+
+  Creating a security policy that fits your specific environment before using
+  ImageMagick is highly recommended. Documentation is available at:
+
+    https://imagemagick.org/script/security-policy.php
+
+  Validate policy changes with the ImageMagick security policy evaluator:
+
+    https://imagemagick-secevaluator.doyensec.com/
+
+  After making policy changes, test and validate your configuration to ensure
+  restrictions are functioning as intended in your deployment environment.
+
+  This policy implements a restrictive security posture suitable for processing
+  untrusted images. It limits resource consumption, disables delegates and
+  filters, restricts filesystem access, blocks indirect reads and pipes, and
+  prevents reading several historically high-risk formats while continuing to
+  permit writing them when required. Review and adjust these settings to meet
+  your organization's operational and security requirements.
 -->
+
 <policymap>
-  <!-- Set maximum parallel threads. -->
+
+  <!-- Maximum number of processing threads. -->
   <policy domain="resource" name="thread" value="2"/>
-  <!-- Set maximum time in seconds. When this limit is exceeded, an exception
-       is thrown and processing stops. -->
+
+  <!-- Maximum execution time in seconds before processing is aborted. -->
   <policy domain="resource" name="time" value="120"/>
-  <!-- Set maximum number of open pixel cache files. When this limit is
-       exceeded, any subsequent pixels cached to disk are closed and reopened
-       on demand. -->
+
+  <!-- Maximum number of open pixel cache files. -->
   <policy domain="resource" name="file" value="768"/>
-  <!-- Set maximum amount of memory in bytes to allocate for the pixel cache
-       from the heap. When this limit is exceeded, the image pixels are cached
-       to memory-mapped disk. -->
+
+  <!-- Maximum heap memory available for pixel cache data. -->
   <policy domain="resource" name="memory" value="768MiB"/>
-  <!-- Set maximum amount of memory map in bytes to allocate for the pixel
-       cache. When this limit is exceeded, the image pixels are cached to
-       disk. -->
+
+  <!-- Maximum memory-mapped cache size before disk caching is required. -->
   <policy domain="resource" name="map" value="2GiB"/>
-  <!-- Set the maximum width * height of an image that can reside in the pixel
-       cache memory. Images that exceed the area limit are cached to disk. -->
+
+  <!-- Maximum image area allowed in memory before disk caching is used. -->
   <policy domain="resource" name="area" value="32MP"/>
-  <!-- Set maximum amount of disk space in bytes permitted for use by the pixel
-       cache. When this limit is exceeded, the pixel cache is not created
-       and an exception is thrown. -->
+
+  <!-- Maximum disk space available for the pixel cache. -->
   <policy domain="resource" name="disk" value="2GiB"/>
-  <!-- Set the maximum length of an image sequence.  When this limit is
-       exceeded, an exception is thrown. -->
+
+  <!-- Maximum number of images permitted in a sequence. -->
   <policy domain="resource" name="list-length" value="32"/>
-  <!-- Set the maximum width of an image.  When this limit is exceeded, an
-       exception is thrown. -->
+
+  <!-- Maximum permitted image width. -->
   <policy domain="resource" name="width" value="8KP"/>
-  <!-- Set the maximum height of an image.  When this limit is exceeded, an
-       exception is thrown. -->
+
+  <!-- Maximum permitted image height. -->
   <policy domain="resource" name="height" value="8KP"/>
-  <!-- Periodically yield the CPU for at least the time specified in
-       milliseconds. -->
+
+  <!-- Periodically yield CPU time (milliseconds). -->
   <!-- <policy domain="resource" name="throttle" value="2"/> -->
-  <!-- Dynamically yield the CPU relative to the system load average. -->
+
+  <!-- Dynamically adjust CPU usage based on system load. -->
   <!-- <policy domain="resource" name="dynamic-throttle" value="true"/> -->
-  <!-- Do not create temporary files in the default shared directories, instead
-       specify a private area to store only ImageMagick temporary files. -->
+
+  <!-- Use a dedicated directory for ImageMagick temporary files. -->
   <!-- <policy domain="resource" name="temporary-path" value="/magick/tmp/"/> -->
-  <!-- Force memory initialization by memory mapping select memory
-       allocations. -->
+
+  <!-- Zero-initialize selected allocations using anonymous memory mapping. -->
   <policy domain="cache" name="memory-map" value="anonymous"/>
-  <!-- Ensure all image data is fully flushed and synchronized to disk. -->
+
+  <!-- Force cache data to be synchronized to disk. -->
   <policy domain="cache" name="synchronize" value="true"/>
-  <!-- Replace passphrase for secure distributed processing -->
-  <!-- <policy domain="cache" name="shared-secret" value="secret-passphrase" stealth="true"/> -->
-  <!-- Do not permit any delegates to execute. -->
+
+  <!-- Shared secret for distributed cache operations. -->
+  <!-- <policy domain="cache" name="shared-secret"
+            value="secret-passphrase" stealth="true"/> -->
+
+  <!-- Disable execution of all delegates. -->
   <policy domain="delegate" rights="none" pattern="*"/>
-  <!-- Do not permit any image filters to load. -->
+
+  <!-- Disable loading of all image filters. -->
   <policy domain="filter" rights="none" pattern="*"/>
-  <!-- Don't read/write from/to stdin/stdout. -->
+
+  <!-- Prevent reading from stdin and writing to stdout. -->
   <policy domain="path" rights="none" pattern="-"/>
-  <policy domain="path" rights="none" pattern="[Ff][Dd]:*"/>
-  <!-- Sensitive paths are not permitted. -->
+
+  <!-- Prevent access to file descriptors. -->
+  <policy domain="path" rights="none" pattern="[Ff][Dd\]:*"/>
+
+  <!-- Prevent access to sensitive system directories. -->
   <policy domain="path" rights="none" pattern="/etc/*"/>
-  <!-- Relative paths are not permitted. -->
+
+  <!-- Prevent directory traversal via relative paths. -->
   <policy domain="path" rights="none" pattern="*../*"/>
-  <!-- Indirect reading is not permitted. -->
+
+  <!-- Disable indirect file reads (@filename syntax). -->
   <policy domain="path" rights="none" pattern="@*"/>
-  <!-- Pipes are not permitted. -->
+
+  <!-- Disable pipe-based I/O. -->
   <policy domain="path" rights="none" pattern="|*"/>
-  <!-- These image types are security risks on read, but write is fine -->
-  <policy domain="module" rights="write" pattern="{MSL,MVG,PDF,PS,SVG,TXT,URL,XPS}"/>
-  <!-- This policy sets the number of times to replace content of certain
-       memory buffers and temporary files before they are freed or deleted. -->
+
+  <!--
+    Permit writing, but not reading, of high-risk formats and pseudo-formats.
+    Reads are blocked; writes remain available when needed.
+  -->
+  <policy domain="module" rights="write"
+          pattern="{MSL,MVG,PDF,PS,SVG,TXT,URL,XPS}"/>
+
+  <!-- Number of overwrite passes before temporary data is deleted. -->
   <policy domain="system" name="shred" value="1"/>
-  <!-- Enable the initialization of buffers with zeros, resulting in a minor
-       performance penalty but with improved security. -->
+
+  <!-- Use anonymous memory mapping for improved memory safety. -->
   <policy domain="system" name="memory-map" value="anonymous"/>
-  <!-- Set the maximum amount of memory in bytes that are permitted for
-       allocation requests. -->
+
+  <!-- Maximum single memory allocation request. -->
   <policy domain="system" name="max-memory-request" value="256MiB"/>
-  <!-- If the basename of path is a symbolic link, the open fails -->
-  <policy domain="system" name="symlink" rights="none" pattern="follow"/>
+
+  <!-- Fail if the target path is a symbolic link. -->
+  <policy domain="system" name="symlink"
+          rights="none" pattern="follow"/>
+
 </policymap>
diff --git a/config/policy-websafe.xml b/config/policy-websafe.xml
index 16161fbc2..402c4f3f4 100644
--- a/config/policy-websafe.xml
+++ b/config/policy-websafe.xml
@@ -1,122 +1,127 @@
 <?xml version="1.0" encoding="UTF-8"?>
 <!DOCTYPE policymap [
   <!ELEMENT policymap (policy)*>
-  <!ATTLIST policymap
-    xmlns CDATA #FIXED ""
-  >
-
+  <!ATTLIST policymap xmlns CDATA #FIXED "">
   <!ELEMENT policy EMPTY>
-  <!ATTLIST policy
-    xmlns   CDATA   #FIXED ""
-    domain  NMTOKEN #REQUIRED
-    name    NMTOKEN #IMPLIED
-    pattern CDATA   #IMPLIED
-    rights  NMTOKEN #IMPLIED
-    stealth NMTOKEN #IMPLIED
-    value   CDATA   #IMPLIED
-  >
+  <!ATTLIST policy xmlns CDATA #FIXED "">
+  <!ATTLIST policy domain NMTOKEN #REQUIRED>
+  <!ATTLIST policy name NMTOKEN #IMPLIED>
+  <!ATTLIST policy pattern CDATA #IMPLIED>
+  <!ATTLIST policy rights NMTOKEN #IMPLIED>
+  <!ATTLIST policy stealth NMTOKEN #IMPLIED>
+  <!ATTLIST policy value CDATA #IMPLIED>
 ]>
+
 <!--
-  Creating a security policy that fits your specific local environment
-  before making use of ImageMagick is highly advised. You can find guidance on
-  setting up this policy at https://imagemagick.org/script/security-policy.php,
-  and it's important to verify your policy using the validation tool located
-  at https://imagemagick-secevaluator.doyensec.com/. We also strongly
-  recommend that all users validate their security assumptions by testing their
-  configurations after making any policy changes. This helps ensure that the
-  intended restrictions are functioning as expected in their specific
-  deployment environment.
-
-
-  Web-safe ImageMagick security policy:
-
-  This security protocol designed for web-safe usage focuses on situations
-  where ImageMagick is applied in publicly accessible contexts, like websites.
-  It deactivates the capability to read from or write to any image formats
-  other than web-safe formats like GIF, JPEG, and PNG. Additionally, this
-  policy prohibits the execution of image filters and indirect reads, thereby
-  thwarting potential security breaches. By implementing these limitations,
-  the web-safe policy fortifies the safeguarding of systems accessible to
-  the public, reducing the risk of exploiting ImageMagick's capabilities
-  for potential attacks.
+  ImageMagick Web-Safe Security Policy
+
+  This policy is intended for public-facing services that process untrusted
+  images. It reduces ImageMagick's attack surface while preserving support
+  for common raster image operations.
+
+  Security objectives:
+
+    * Limit CPU, memory, disk, and file resource consumption.
+    * Mitigate denial-of-service attacks through resource and runtime limits.
+    * Prevent access to sensitive local files and Linux virtual filesystems.
+    * Prevent indirect file reads via @filename expansion.
+    * Prevent use of stdin/stdout and file descriptor paths.
+    * Disable all delegates and loadable filters.
+    * Disable selected high-risk modules that provide scripting, vector
+      graphics processing, or URL access.
+
+  This policy does not restrict ImageMagick to a specific image format
+  allowlist. Additional coder or module restrictions may be added for
+  deployments requiring a stricter security posture.
+
+  References:
+
+    https://imagemagick.org/security-policy/
+    https://imagemagick-secevaluator.doyensec.com/
 -->
+
 <policymap>
-  <!-- Set maximum parallel threads. -->
+
+  <!-- ============================================================= -->
+  <!-- Resource Limits                                                -->
+  <!-- ============================================================= -->
+
+  <!-- Limit ImageMagick to at most two worker threads. -->
   <policy domain="resource" name="thread" value="2"/>
-  <!-- Set maximum time to live in seconds or mnemonics, e.g. "2 minutes". When
-       this limit is exceeded, an exception is thrown and processing stops. -->
-  <policy domain="resource" name="time" value="60"/>
-  <!-- Set maximum number of open pixel cache files. When this limit is
-       exceeded, any subsequent pixels cached to disk are closed and reopened
-       on demand. -->
+
+  <!-- Abort operations that exceed 30 seconds of processing time. -->
+  <policy domain="resource" name="time" value="30"/>
+
+  <!-- Maximum number of simultaneously open pixel-cache files. -->
   <policy domain="resource" name="file" value="768"/>
-  <!-- Set maximum amount of memory in bytes to allocate for the pixel cache
-       from the heap. When this limit is exceeded, the image pixels are cached
-       to memory-mapped disk. -->
-  <policy domain="resource" name="memory" value="768MiB"/>
-  <!-- Set maximum amount of memory map in bytes to allocate for the pixel
-       cache. When this limit is exceeded, the image pixels are cached to
-       disk. -->
-  <policy domain="resource" name="map" value="2GiB"/>
-  <!-- Set the maximum width * height of an image that can reside in the pixel
-       cache memory. Images that exceed the area limit are cached to disk. -->
+
+  <!-- Maximum heap memory available to the pixel cache. -->
+  <policy domain="resource" name="memory" value="512MiB"/>
+
+  <!-- Maximum amount of memory-mapped pixel cache storage. -->
+  <policy domain="resource" name="map" value="1024MiB"/>
+
+  <!-- Images larger than 32 megapixels spill to disk-backed cache. -->
   <policy domain="resource" name="area" value="32MP"/>
-  <!-- Set maximum amount of disk space in bytes permitted for use by the pixel
-       cache. When this limit is exceeded, the pixel cache is not created
-       and an exception is thrown. -->
+
+  <!-- Limit total disk usage for pixel cache and temporary files. -->
   <policy domain="resource" name="disk" value="2GiB"/>
-  <!-- Set the maximum length of an image sequence.  When this limit is
-       exceeded, an exception is thrown. -->
+
+  <!-- Limit the number of images permitted in a sequence. -->
   <policy domain="resource" name="list-length" value="16"/>
-  <!-- Set the maximum width of an image.  When this limit is exceeded, an
-       exception is thrown. -->
-  <policy domain="resource" name="width" value="4KP"/>
-  <!-- Set the maximum height of an image.  When this limit is exceeded, an
-       exception is thrown. -->
-  <policy domain="resource" name="height" value="4KP"/>
-  <!-- Periodically yield the CPU for at least the time specified in
-       milliseconds. -->
-  <!-- <policy domain="resource" name="throttle" value="2"/> -->
-  <!-- Dynamically yield the CPU relative to the system load average. -->
-  <policy domain="resource" name="dynamic-throttle" value="true"/>
-  <!-- Do not create temporary files in the default shared directories, instead
-       specify a private area to store only ImageMagick temporary files. -->
-  <!-- <policy domain="resource" name="temporary-path" value="/magick/tmp/"/> -->
-  <!-- Force memory initialization by memory mapping select memory
-       allocations. -->
-  <policy domain="cache" name="memory-map" value="anonymous"/>
-  <!-- Ensure all image data is fully flushed and synchronized to disk. -->
-  <policy domain="cache" name="synchronize" value="true"/>
-  <!-- Replace passphrase for secure distributed processing -->
-  <!-- <policy domain="cache" name="shared-secret" value="secret-passphrase" stealth="true"/> -->
-  <!-- Do not permit any delegates to execute. -->
-  <policy domain="delegate" rights="none" pattern="*"/>
-  <!-- Do not permit any image filters to load. -->
-  <policy domain="filter" rights="none" pattern="*"/>
-  <!-- Don't read/write from/to stdin/stdout. -->
+
+  <!-- Reject images wider than approximately 8192 pixels. -->
+  <policy domain="resource" name="width" value="8KP"/>
+
+  <!-- Reject images taller than approximately 8192 pixels. -->
+  <policy domain="resource" name="height" value="8KP"/>
+
+  <!-- Prevent excessively large single memory allocation requests. -->
+  <policy domain="system" name="max-memory-request" value="512MiB"/>
+
+  <!-- ============================================================= -->
+  <!-- Path Restrictions                                              -->
+  <!-- ============================================================= -->
+
+  <!-- Disallow reading from or writing to stdin/stdout via "-". -->
   <policy domain="path" rights="none" pattern="-"/>
-  <policy domain="path" rights="none" pattern="[Ff][Dd]:*"/>
-  <!-- Sensitive paths are not permitted. -->
-  <policy domain="path" rights="none" pattern="/etc/*"/>
-  <!-- Relative paths are not permitted. -->
-  <policy domain="path" rights="none" pattern="*../*"/>
-  <!-- Indirect reading is not permitted. -->
+
+  <!-- Disable indirect file reads such as @filename. -->
   <policy domain="path" rights="none" pattern="@*"/>
-  <!-- Pipes are not permitted. -->
-  <policy domain="path" rights="none" pattern="|*"/>
-  <!-- Deny all image modules and specifically exempt reading or writing
-       web-safe image formats. -->
-  <policy domain="module" rights="none" pattern="*" />
-  <policy domain="module" rights="read | write" pattern="{BMP,GIF,JPEG,PNG,TIFF,WEBP}"/>
-  <policy domain="module" rights="read | write" pattern="{MPC}" stealth="true"/>
-  <policy domain="module" rights="write" pattern="{JSON,INFO,PNM,PS}"/>
-  <!-- This policy sets the number of times to replace content of certain
-       memory buffers and temporary files before they are freed or deleted. -->
-  <policy domain="system" name="shred" value="1"/>
-  <!-- Enable the initialization of buffers with zeros, resulting in a minor
-       performance penalty but with improved security. -->
-  <policy domain="system" name="memory-map" value="anonymous"/>
-  <!-- Set the maximum amount of memory in bytes that are permitted for
-       allocation requests. -->
-  <policy domain="system" name="max-memory-request" value="256MiB"/>
+
+  <!-- Prevent access to file descriptors (fd:). -->
+  <policy domain="path" rights="none" pattern="[Ff][Dd\\]:*"/>
+
+  <!-- Prevent access to operating system configuration files. -->
+  <policy domain="path" rights="none" pattern="/etc/*"/>
+
+  <!-- Prevent access to Linux process and runtime information. -->
+  <policy domain="path" rights="none" pattern="/proc/*"/>
+
+  <!-- Prevent access to Linux kernel and device nformation. -->
+  <policy domain="path" rights="none" pattern="/sys/*"/>
+
+  <!-- ============================================================= -->
+  <!-- Feature Restrictions                                           -->
+  <!-- ============================================================= -->
+
+  <!-- Disable all external delegates (Ghostscript, ffmpeg, etc.). -->
+  <policy domain="delegate" rights="none" pattern="*"/>
+
+  <!-- Disable all loadable image filters. -->
+  <policy domain="filter" rights="none" pattern="*"/>
+
+  <!-- ============================================================= -->
+  <!-- High-Risk Module Restrictions                                  -->
+  <!-- ============================================================= -->
+
+  <!-- Disable the Magick Vector Graphics interpreter. -->
+  <policy domain="module" rights="none" pattern="MVG"/>
+
+  <!-- Disable the Magick Scripting Language interpreter. -->
+  <policy domain="module" rights="none" pattern="MSL"/>
+
+  <!-- Disable URL, HTTP, HTTPS, and related network access support. -->
+  <policy domain="module" rights="none" pattern="URL"/>
+
 </policymap>