Commit b3fb0fb04 for imagemagick.org
commit b3fb0fb042f71c21779a3064fc2eec4199d87db7
Author: Cristy <urban-warrior@imagemagick.org>
Date: Sun Oct 4 07:43:42 2026 -0400
clarify comments
diff --git a/config/policy-limited.xml b/config/policy-limited.xml
index 4d20045fa..ab49c6d82 100644
--- a/config/policy-limited.xml
+++ b/config/policy-limited.xml
@@ -16,98 +16,122 @@
value CDATA #IMPLIED
>
]>
+
<!--
- Creating a security policy that fits your specific local environment
- before making use of ImageMagick is highly advised. You can find guidance on
- setting up this policy at https://imagemagick.org/script/security-policy.php,
- and it's important to verify your policy using the validation tool located
- at https://imagemagick-secevaluator.doyensec.com/. We also strongly
- recommend that all users validate their security assumptions by testing their
- configurations after making any policy changes. This helps ensure that the
- intended restrictions are functioning as expected in their specific
- deployment environment.
-
-
- Limited ImageMagick security policy:
-
- The primary objective of the limited security policy is to find a
- middle ground between convenience and security. This policy involves the
- deactivation of potentially hazardous functionalities, like specific coders
- such as SVG or HTTP. Furthermore, it establishes several constraints on
- the utilization of resources like memory, storage, and processing duration,
- all of which are adjustable. This policy proves advantageous in situations
- where there's a need to mitigate the potential threat of handling possibly
- malicious or demanding images, all while retaining essential capabilities
- for prevalent image formats.
+ ImageMagick Security Policy
+
+ This policy is intended for general-purpose deployments that process
+ potentially untrusted images while maintaining support for common image
+ formats and workflows.
+
+ The policy balances usability and security by:
+
+ * Limiting resource consumption (CPU time, memory, disk usage, image
+ dimensions, and sequence length).
+ * Blocking potentially dangerous path access methods such as indirect
+ reads (@files) and pipes.
+ * Preventing access to sensitive filesystem locations.
+ * Restricting high-risk coders that have historically been involved in
+ external content processing, scripting, or complex parsers.
+ * Limiting large allocation requests that could otherwise lead to
+ excessive memory consumption.
+
+ After modifying this policy, test and validate the resulting behavior in
+ your environment to ensure the restrictions are operating as intended.
+
+ Documentation:
+ https://imagemagick.org/script/security-policy.php
+
+ Policy Evaluator:
+ https://imagemagick-secevaluator.doyensec.com/
-->
+
<policymap>
- <!-- Set maximum parallel threads. -->
+
+ <!-- Maximum number of worker threads. -->
<policy domain="resource" name="thread" value="4"/>
- <!-- Set maximum time in seconds. When this limit is exceeded, an exception
- is thrown and processing stops. -->
+
+ <!-- Maximum execution time (seconds) before processing is terminated. -->
<policy domain="resource" name="time" value="240"/>
- <!-- Set maximum number of open pixel cache files. When this limit is
- exceeded, any subsequent pixels cached to disk are closed and reopened
- on demand. -->
+
+ <!-- Maximum number of simultaneously open pixel cache files. -->
<policy domain="resource" name="file" value="768"/>
- <!-- Set maximum amount of memory in bytes to allocate for the pixel cache
- from the heap. When this limit is exceeded, the image pixels are cached
- to memory-mapped disk. -->
+
+ <!-- Maximum heap memory used for pixel cache data. Excess pixels are
+ stored in mapped or disk-backed cache. -->
<policy domain="resource" name="memory" value="768MiB"/>
- <!-- Set maximum amount of memory map in bytes to allocate for the pixel
- cache. When this limit is exceeded, the image pixels are cached to
- disk. -->
+
+ <!-- Maximum memory-mapped pixel cache size. Excess cache data is
+ written to disk. -->
<policy domain="resource" name="map" value="2GiB"/>
- <!-- Set the maximum width * height of an image that can reside in the pixel
- cache memory. Images that exceed the area limit are cached to disk. -->
+
+ <!-- Maximum in-memory image area before pixels are cached to disk. -->
<policy domain="resource" name="area" value="32MP"/>
- <!-- Set maximum amount of disk space in bytes permitted for use by the pixel
- cache. When this limit is exceeded, the pixel cache is not created
- and an exception is thrown. -->
+
+ <!-- Maximum disk space available for pixel cache operations. -->
<policy domain="resource" name="disk" value="2GiB"/>
- <!-- Set the maximum length of an image sequence. When this limit is
- exceeded, an exception is thrown. -->
+
+ <!-- Maximum number of images permitted in a sequence. -->
<policy domain="resource" name="list-length" value="64"/>
- <!-- Set the maximum width of an image. When this limit is exceeded, an
- exception is thrown. -->
+
+ <!-- Maximum image width. -->
<policy domain="resource" name="width" value="16KP"/>
- <!-- Set the maximum height of an image. When this limit is exceeded, an
- exception is thrown. -->
+
+ <!-- Maximum image height. -->
<policy domain="resource" name="height" value="16KP"/>
- <!-- Periodically yield the CPU for at least the time specified in
- milliseconds. -->
+
+ <!-- Optional: periodically yield CPU time to improve system responsiveness. -->
<!-- <policy domain="resource" name="throttle" value="2"/> -->
- <!-- Do not create temporary files in the default shared directories, instead
- specify a private area to store only ImageMagick temporary files. -->
+
+ <!-- Optional: store temporary files in a dedicated private directory. -->
<!-- <policy domain="resource" name="temporary-path" value="/magick/tmp/"/> -->
- <!-- Force memory initialization by memory mapping select memory
- allocations. -->
+
+ <!-- Optional: force anonymous memory mapping for selected cache allocations. -->
<!-- <policy domain="cache" name="memory-map" value="anonymous"/> -->
- <!-- Ensure all image data is fully flushed and synchronized to disk. -->
+
+ <!-- Optional: fully synchronize image cache data to disk before closing. -->
<!-- <policy domain="cache" name="synchronize" value="true"/> -->
- <!-- Replace passphrase for secure distributed processing -->
- <!-- <policy domain="cache" name="shared-secret" value="secret-passphrase" stealth="true"/> -->
- <!-- Do not permit any delegates to execute. -->
+
+ <!-- Optional: shared secret used by distributed pixel cache operations.
+ Replace with a site-specific value if enabled. -->
+ <!-- <policy domain="cache" name="shared-secret"
+ value="secret-passphrase" stealth="true"/> -->
+
+ <!-- Optional: disable execution of all delegates. -->
<!-- <policy domain="delegate" rights="none" pattern="*"/> -->
- <!-- Do not permit any image filters to load. -->
+
+ <!-- Optional: disable loading of all image filter modules. -->
<!-- <policy domain="filter" rights="none" pattern="*"/> -->
- <!-- Don't read/write from/to stdin/stdout. -->
+
+ <!-- Optional: disable stdin/stdout image processing ("-"). -->
<!-- <policy domain="path" rights="none" pattern="-"/> -->
- <!-- don't read sensitive paths. -->
+
+ <!-- Prevent access to sensitive system configuration files. -->
<policy domain="path" rights="none" pattern="/etc/*"/>
- <!-- Indirect reads are not permitted. -->
+
+ <!-- Prevent indirect file reads using @filename syntax. -->
<policy domain="path" rights="none" pattern="@*"/>
- <!-- Pipes are not permitted. -->
+
+ <!-- Prevent use of pipes for reading or writing image data. -->
<policy domain="path" rights="none" pattern="|*"/>
- <!-- These image types are security risks on read, but write is fine -->
- <policy domain="module" rights="write" pattern="{MSL,MVG,PDF,PS,SVG,TXT,URL,XPS}"/>
- <!-- This policy sets the number of times to replace content of certain
- memory buffers and temporary files before they are freed or deleted. -->
+
+ <!--
+ Restrict high-risk coders.
+
+ Read access is denied while write access remains permitted.
+ This allows ImageMagick to generate these formats without accepting
+ potentially untrusted input through them.
+ -->
+ <policy domain="module" rights="write"
+ pattern="{MSL,MVG,PDF,PS,SVG,TXT,URL,XPS}"/>
+
+ <!-- Optional: overwrite temporary files and buffers before deletion. -->
<!-- <policy domain="system" name="shred" value="1"/> -->
- <!-- Enable the initialization of buffers with zeros, resulting in a minor
- performance penalty but with improved security. -->
+
+ <!-- Optional: initialize allocated memory with zeros for improved security. -->
<!-- <policy domain="system" name="memory-map" value="anonymous"/> -->
- <!-- Set the maximum amount of memory in bytes that are permitted for
- allocation requests. -->
+
+ <!-- Maximum size of a single allocation request. -->
<policy domain="system" name="max-memory-request" value="512MiB"/>
+
</policymap>
diff --git a/config/policy-open.xml b/config/policy-open.xml
index 4c3c8f36e..44edfc97a 100644
--- a/config/policy-open.xml
+++ b/config/policy-open.xml
@@ -1,9 +1,7 @@
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE policymap [
<!ELEMENT policymap (policy)*>
- <!ATTLIST policymap
- xmlns CDATA #FIXED ""
- >
+ <!ATTLIST policymap xmlns CDATA #FIXED "">
<!ELEMENT policy EMPTY>
<!ATTLIST policy
@@ -16,157 +14,206 @@
value CDATA #IMPLIED
>
]>
+
<!--
- Creating a security policy that fits your specific local environment
- before making use of ImageMagick is highly advised. You can find guidance on
- setting up this policy at https://imagemagick.org/script/security-policy.php,
- and it's important to verify your policy using the validation tool located
- at https://imagemagick-secevaluator.doyensec.com/. We also strongly
- recommend that all users validate their security assumptions by testing their
- configurations after making any policy changes. This helps ensure that the
- intended restrictions are functioning as expected in their specific
- deployment environment.
+ ImageMagick Security Policy Configuration
+ ========================================
+ This file provides the default "open" ImageMagick security policy along with
+ numerous optional hardening examples. The default configuration permits broad
+ functionality and is appropriate only for trusted environments such as
+ systems protected by firewalls, isolated containers, or tightly controlled
+ internal workloads.
- Open ImageMagick security policy:
+ For untrusted input or multi-tenant environments, review and customize this
+ policy to match your security requirements.
- The default policy for ImageMagick installations is the open security
- policy. This policy is designed for usage in secure settings like those
- protected by firewalls or within Docker containers. Within this framework,
- ImageMagick enjoys broad access to resources and functionalities. This policy
- provides convenient and adaptable options for image manipulation. However,
- it's important to note that it might present security vulnerabilities in
- less regulated conditions. Thus, organizations should thoroughly assess
- the appropriateness of the open policy according to their particular use
- case and security prerequisites.
+ Additional documentation:
+ https://imagemagick.org/script/security-policy.php
- ImageMagick security policies in a nutshell:
+ Security policy validator:
+ https://imagemagick-secevaluator.doyensec.com/
- Domains include system, delegate, coder, filter, module, path, or resource.
+ Important:
+ * Security policies should be reviewed for your specific deployment.
+ * Test all policy changes to confirm they behave as expected.
+ * Rules are processed in order.
+ * Policy names, domains, and patterns are case-sensitive.
- Rights include none, read, write, execute and all. Use | to combine them,
- for example: "read | write" to permit read from, or write to, a path.
+ Domains:
+ system, resource, cache, delegate, filter, module, path, and coder
- Use a glob expression as a pattern.
+ Rights:
+ none, read, write, execute, all
- Suppose we do not want users to process MPEG video images, use this policy:
+ Multiple rights may be combined:
+ rights="read|write"
- <policy domain="module" rights="none" pattern="video" />
+ Patterns use ImageMagick glob matching.
- Here we do not want users reading images from HTTP:
+ Example: disable all video modules
- <policy domain="coder" rights="none" pattern="HTTP" />
+ <policy domain="module" rights="none" pattern="VIDEO"/>
- The /repository file system is restricted to read only. We use a glob
- expression to match all paths that start with /repository:
+ Example: disable HTTP image reads
- <policy domain="path" rights="read" pattern="/repository/*" />
+ <policy domain="coder" rights="none" pattern="HTTP"/>
- Prevent users from executing any image filters:
+ Example: permit read-only access to a repository
- <policy domain="filter" rights="none" pattern="*" />
+ <policy domain="path" rights="read"
+ pattern="/repository/*"/>
- Cache large images to disk rather than memory:
+ Example: disable all image filters
- <policy domain="resource" name="area" value="1GP"/>
+ <policy domain="filter" rights="none" pattern="*"/>
- Use the default system font unless overridden by the application:
+ Example: restrict processing to common web-safe formats
- <policy domain="system" name="font" value="/usr/share/fonts/favorite.ttf"/>
+ <policy domain="delegate" rights="none" pattern="*"/>
+ <policy domain="filter" rights="none" pattern="*"/>
+ <policy domain="coder" rights="none" pattern="*"/>
+ <policy domain="coder" rights="read|write"
+ pattern="{GIF,JPEG,PNG,WEBP}"/>
+-->
- Define arguments for the memory, map, area, width, height and disk resources
- with SI prefixes (.e.g 100MB). In addition, resource policies are maximums
- for each instance of ImageMagick (e.g. policy memory limit 1GB, -limit 2GB
- exceeds policy maximum so memory limit is 1GB).
+<policymap>
- Rules are processed in order. Here we want to restrict ImageMagick to only
- read or write a small subset of proven web-safe image types:
+ <!-- Deny use of undefined domains. -->
+ <policy domain="Undefined" rights="none"/>
- <policy domain="delegate" rights="none" pattern="*" />
- <policy domain="filter" rights="none" pattern="*" />
- <policy domain="coder" rights="none" pattern="*" />
- <policy domain="coder" rights="read|write" pattern="{GIF,JPEG,PNG,WEBP}" />
+ <!-- ================================================================== -->
+ <!-- Resource Policies -->
+ <!-- ================================================================== -->
- See https://imagemagick.org/script/security-policy.php for a deeper
- understanding of ImageMagick security policies.
--->
-<policymap>
- <policy domain="Undefined" rights="none"/>
- <!-- Set maximum parallel threads. -->
+ <!-- Maximum number of worker threads. -->
<!-- <policy domain="resource" name="thread" value="2"/> -->
- <!-- Set maximum time to live in seconds or mnemonics, e.g. "2 minutes". When
- this limit is exceeded, an exception is thrown and processing stops. -->
+
+ <!-- Maximum execution time before processing is aborted. -->
<!-- <policy domain="resource" name="time" value="120"/> -->
- <!-- Set maximum number of open pixel cache files. When this limit is
- exceeded, any subsequent pixels cached to disk are closed and reopened
- on demand. -->
+
+ <!-- Maximum number of open pixel cache files. -->
<!-- <policy domain="resource" name="file" value="768"/> -->
- <!-- Set maximum amount of memory in bytes to allocate for the pixel cache
- from the heap. When this limit is exceeded, the image pixels are cached
- to memory-mapped disk. -->
+
+ <!-- Maximum heap memory available to the pixel cache. -->
<!-- <policy domain="resource" name="memory" value="256MiB"/> -->
- <!-- Set maximum amount of memory map in bytes to allocate for the pixel
- cache. When this limit is exceeded, the image pixels are cached to
- disk. -->
+
+ <!-- Maximum memory-mapped cache allocation. -->
<!-- <policy domain="resource" name="map" value="512MiB"/> -->
- <!-- Set the maximum width * height of an image that can reside in the pixel
- cache memory. Images that exceed the area limit are cached to disk. -->
+
+ <!-- Maximum image area (width × height) cached in memory. -->
<!-- <policy domain="resource" name="area" value="16KP"/> -->
- <!-- Set maximum amount of disk space in bytes permitted for use by the pixel
- cache. When this limit is exceeded, the pixel cache is not created
- and an exception is thrown. -->
+
+ <!-- Maximum disk space available to the pixel cache. -->
<!-- <policy domain="resource" name="disk" value="1GiB"/> -->
- <!-- Set the maximum length of an image sequence. When this limit is
- exceeded, an exception is thrown. -->
+
+ <!-- Maximum number of images permitted in a sequence. -->
<!-- <policy domain="resource" name="list-length" value="32"/> -->
- <!-- Set the maximum width of an image. When this limit is exceeded, an
- exception is thrown. -->
+
+ <!-- Maximum image width. -->
<!-- <policy domain="resource" name="width" value="8KP"/> -->
- <!-- Set the maximum height of an image. When this limit is exceeded, an
- exception is thrown. -->
+
+ <!-- Maximum image height. -->
<!-- <policy domain="resource" name="height" value="8KP"/> -->
- <!-- Periodically yield the CPU for at least the time specified in
- milliseconds. -->
+
+ <!-- Yield the CPU periodically (milliseconds). -->
<!-- <policy domain="resource" name="throttle" value="2"/> -->
- <!-- Do not create temporary files in the default shared directories, instead
- specify a private area to store only ImageMagick temporary files. -->
- <!-- <policy domain="resource" name="temporary-path" value="/magick/tmp/"/> -->
- <!-- Force memory initialization by memory mapping select memory
- allocations. -->
- <!-- <policy domain="cache" name="memory-map" value="anonymous"/> -->
- <!-- Ensure all image data is fully flushed and synchronized to disk. -->
- <!-- <policy domain="cache" name="synchronize" value="true"/> -->
- <!-- Replace passphrase for secure distributed processing -->
- <!-- <policy domain="cache" name="shared-secret" value="secret-passphrase" stealth="true"/> -->
- <!-- Do not permit any delegates to execute. -->
+
+ <!-- Use a private directory for ImageMagick temporary files. -->
+ <!-- <policy domain="resource" name="temporary-path"
+ value="/magick/tmp/"/> -->
+
+ <!-- ================================================================== -->
+ <!-- Pixel Cache Policies -->
+ <!-- ================================================================== -->
+
+ <!-- Use anonymous memory mapping to initialize cache memory. -->
+ <!-- <policy domain="cache" name="memory-map"
+ value="anonymous"/> -->
+
+ <!-- Force cache data to be flushed and synchronized to disk. -->
+ <!-- <policy domain="cache" name="synchronize"
+ value="true"/> -->
+
+ <!-- Shared secret for distributed pixel cache clients. -->
+ <!-- <policy domain="cache" name="shared-secret"
+ value="secret-passphrase" stealth="true"/> -->
+
+ <!-- Maximum authenticated distributed pixel cache clients. -->
+ <!-- <policy domain="cache" name="max-dpc-clients"
+ value="128"/> -->
+
+ <!-- Maximum unauthenticated distributed pixel cache clients. -->
+ <!-- <policy domain="cache"
+ name="max-dpc-unauthenticated-clients"
+ value="16"/> -->
+
+ <!-- ================================================================== -->
+ <!-- Delegate and Filter Policies -->
+ <!-- ================================================================== -->
+
+ <!-- Disable execution of all delegates. -->
<!-- <policy domain="delegate" rights="none" pattern="*"/> -->
- <!-- Do not permit any image filters to load. -->
+
+ <!-- Disable loading of all image filters. -->
<!-- <policy domain="filter" rights="none" pattern="*"/> -->
- <!-- Don't read/write from/to stdin/stdout. -->
+
+ <!-- ================================================================== -->
+ <!-- Path Restrictions -->
+ <!-- ================================================================== -->
+
+ <!-- Disallow stdin and stdout image I/O. -->
<!-- <policy domain="path" rights="none" pattern="-"/> -->
- <!-- don't read sensitive paths. -->
+
+ <!-- Prevent access to sensitive system locations. -->
<!-- <policy domain="path" rights="none" pattern="/etc/*"/> -->
- <!-- Indirect reads are not permitted. -->
+
+ <!-- Disable indirect file reads (@filename). -->
<!-- <policy domain="path" rights="none" pattern="@*"/> -->
- <!-- Pipes are not permitted. -->
+
+ <!-- Disable pipe execution. -->
<!-- <policy domain="path" rights="none" pattern="|*"/> -->
- <!-- These image types are security risks on read, but write is fine -->
- <!-- <policy domain="module" rights="write" pattern="{MSL,MVG,PDF,PS,SVG,TXT,URL,XPS}"/> -->
- <!-- This policy sets the number of times to replace content of certain
- memory buffers and temporary files before they are freed or deleted. -->
+
+ <!-- ================================================================== -->
+ <!-- Module Restrictions -->
+ <!-- ================================================================== -->
+
+ <!--
+ Disable reading of higher-risk formats while still permitting writes.
+
+ Common candidates include:
+ MSL, MVG, PDF, PS, SVG, TXT, URL, and XPS
+
+ Review carefully before enabling.
+ -->
+ <!-- <policy domain="module" rights="write"
+ pattern="{MSL,MVG,PDF,PS,SVG,TXT,URL,XPS}"/> -->
+
+ <!-- ================================================================== -->
+ <!-- System Policies -->
+ <!-- ================================================================== -->
+
+ <!-- Overwrite temporary data before release or deletion. -->
<!-- <policy domain="system" name="shred" value="1"/> -->
- <!-- Enable the initialization of buffers with zeros, resulting in a minor
- performance penalty but with improved security. -->
- <!-- <policy domain="system" name="memory-map" value="anonymous"/> -->
- <!-- Set the maximum amount of memory in bytes that are permitted for
- allocation requests. -->
- <!-- <policy domain="system" name="max-memory-request" value="256MiB"/> -->
- <!-- If the basename of path is a symbolic link, the open fails -->
- <!-- <policy domain="system" name="symlink" rights="none" pattern="follow"/> -->
- <!-- Blocks all SVG entity‑substitution attempts by denying the svg:substitute-entities define -->
- <!-- <policy domain="system" name="svg" rights="none" pattern="substitute-entities"/> -->
- <!-- Set the maximum distributed pixel cache clients -->
- <!-- <policy domain="cache" name="max-dpc-clients" value="128"/> -->
- <!-- Set the maximum distributed pixel cache unauthenticated clients -->
- <!-- <policy domain="cache" name="max-dpc-unauthenticated-clients" value="16"/> -->
+
+ <!-- Initialize newly allocated memory with zeros. -->
+ <!-- <policy domain="system" name="memory-map"
+ value="anonymous"/> -->
+
+ <!-- Maximum permitted single memory allocation request. -->
+ <!-- <policy domain="system" name="max-memory-request"
+ value="256MiB"/> -->
+
+ <!-- Refuse paths whose basename is a symbolic link. -->
+ <!-- <policy domain="system"
+ name="symlink"
+ rights="none"
+ pattern="follow"/> -->
+
+ <!-- Disable SVG entity substitution. -->
+ <!-- <policy domain="system"
+ name="svg"
+ rights="none"
+ pattern="substitute-entities"/> -->
+
</policymap>
diff --git a/config/policy-secure.xml b/config/policy-secure.xml
index 2fc9f3600..d90b3b765 100644
--- a/config/policy-secure.xml
+++ b/config/policy-secure.xml
@@ -16,109 +16,123 @@
value CDATA #IMPLIED
>
]>
+
<!--
- Creating a security policy that fits your specific local environment
- before making use of ImageMagick is highly advised. You can find guidance on
- setting up this policy at https://imagemagick.org/script/security-policy.php,
- and it's important to verify your policy using the validation tool located
- at https://imagemagick-secevaluator.doyensec.com/. We also strongly
- recommend that all users validate their security assumptions by testing their
- configurations after making any policy changes. This helps ensure that the
- intended restrictions are functioning as expected in their specific
- deployment environment.
-
-
- Secure ImageMagick security policy:
-
- This stringent security policy prioritizes the implementation of
- rigorous controls and restricted resource utilization to establish a
- profoundly secure setting while employing ImageMagick. It deactivates
- conceivably hazardous functionalities, including specific coders like
- SVG or HTTP. The policy promotes the tailoring of security measures to
- harmonize with the requirements of the local environment and the guidelines
- of the organization. This protocol encompasses explicit particulars like
- limitations on memory consumption, sanctioned pathways for reading and
- writing, confines on image sequences, the utmost permissible duration of
- workflows, allocation of disk space intended for image data, and even an
- undisclosed passphrase for remote connections. By adopting this robust
- policy, entities can elevate their overall security stance and alleviate
- potential vulnerabilities.
+ ImageMagick Security Policy
+
+ Creating a security policy that fits your specific environment before using
+ ImageMagick is highly recommended. Documentation is available at:
+
+ https://imagemagick.org/script/security-policy.php
+
+ Validate policy changes with the ImageMagick security policy evaluator:
+
+ https://imagemagick-secevaluator.doyensec.com/
+
+ After making policy changes, test and validate your configuration to ensure
+ restrictions are functioning as intended in your deployment environment.
+
+ This policy implements a restrictive security posture suitable for processing
+ untrusted images. It limits resource consumption, disables delegates and
+ filters, restricts filesystem access, blocks indirect reads and pipes, and
+ prevents reading several historically high-risk formats while continuing to
+ permit writing them when required. Review and adjust these settings to meet
+ your organization's operational and security requirements.
-->
+
<policymap>
- <!-- Set maximum parallel threads. -->
+
+ <!-- Maximum number of processing threads. -->
<policy domain="resource" name="thread" value="2"/>
- <!-- Set maximum time in seconds. When this limit is exceeded, an exception
- is thrown and processing stops. -->
+
+ <!-- Maximum execution time in seconds before processing is aborted. -->
<policy domain="resource" name="time" value="120"/>
- <!-- Set maximum number of open pixel cache files. When this limit is
- exceeded, any subsequent pixels cached to disk are closed and reopened
- on demand. -->
+
+ <!-- Maximum number of open pixel cache files. -->
<policy domain="resource" name="file" value="768"/>
- <!-- Set maximum amount of memory in bytes to allocate for the pixel cache
- from the heap. When this limit is exceeded, the image pixels are cached
- to memory-mapped disk. -->
+
+ <!-- Maximum heap memory available for pixel cache data. -->
<policy domain="resource" name="memory" value="768MiB"/>
- <!-- Set maximum amount of memory map in bytes to allocate for the pixel
- cache. When this limit is exceeded, the image pixels are cached to
- disk. -->
+
+ <!-- Maximum memory-mapped cache size before disk caching is required. -->
<policy domain="resource" name="map" value="2GiB"/>
- <!-- Set the maximum width * height of an image that can reside in the pixel
- cache memory. Images that exceed the area limit are cached to disk. -->
+
+ <!-- Maximum image area allowed in memory before disk caching is used. -->
<policy domain="resource" name="area" value="32MP"/>
- <!-- Set maximum amount of disk space in bytes permitted for use by the pixel
- cache. When this limit is exceeded, the pixel cache is not created
- and an exception is thrown. -->
+
+ <!-- Maximum disk space available for the pixel cache. -->
<policy domain="resource" name="disk" value="2GiB"/>
- <!-- Set the maximum length of an image sequence. When this limit is
- exceeded, an exception is thrown. -->
+
+ <!-- Maximum number of images permitted in a sequence. -->
<policy domain="resource" name="list-length" value="32"/>
- <!-- Set the maximum width of an image. When this limit is exceeded, an
- exception is thrown. -->
+
+ <!-- Maximum permitted image width. -->
<policy domain="resource" name="width" value="8KP"/>
- <!-- Set the maximum height of an image. When this limit is exceeded, an
- exception is thrown. -->
+
+ <!-- Maximum permitted image height. -->
<policy domain="resource" name="height" value="8KP"/>
- <!-- Periodically yield the CPU for at least the time specified in
- milliseconds. -->
+
+ <!-- Periodically yield CPU time (milliseconds). -->
<!-- <policy domain="resource" name="throttle" value="2"/> -->
- <!-- Dynamically yield the CPU relative to the system load average. -->
+
+ <!-- Dynamically adjust CPU usage based on system load. -->
<!-- <policy domain="resource" name="dynamic-throttle" value="true"/> -->
- <!-- Do not create temporary files in the default shared directories, instead
- specify a private area to store only ImageMagick temporary files. -->
+
+ <!-- Use a dedicated directory for ImageMagick temporary files. -->
<!-- <policy domain="resource" name="temporary-path" value="/magick/tmp/"/> -->
- <!-- Force memory initialization by memory mapping select memory
- allocations. -->
+
+ <!-- Zero-initialize selected allocations using anonymous memory mapping. -->
<policy domain="cache" name="memory-map" value="anonymous"/>
- <!-- Ensure all image data is fully flushed and synchronized to disk. -->
+
+ <!-- Force cache data to be synchronized to disk. -->
<policy domain="cache" name="synchronize" value="true"/>
- <!-- Replace passphrase for secure distributed processing -->
- <!-- <policy domain="cache" name="shared-secret" value="secret-passphrase" stealth="true"/> -->
- <!-- Do not permit any delegates to execute. -->
+
+ <!-- Shared secret for distributed cache operations. -->
+ <!-- <policy domain="cache" name="shared-secret"
+ value="secret-passphrase" stealth="true"/> -->
+
+ <!-- Disable execution of all delegates. -->
<policy domain="delegate" rights="none" pattern="*"/>
- <!-- Do not permit any image filters to load. -->
+
+ <!-- Disable loading of all image filters. -->
<policy domain="filter" rights="none" pattern="*"/>
- <!-- Don't read/write from/to stdin/stdout. -->
+
+ <!-- Prevent reading from stdin and writing to stdout. -->
<policy domain="path" rights="none" pattern="-"/>
- <policy domain="path" rights="none" pattern="[Ff][Dd]:*"/>
- <!-- Sensitive paths are not permitted. -->
+
+ <!-- Prevent access to file descriptors. -->
+ <policy domain="path" rights="none" pattern="[Ff][Dd\]:*"/>
+
+ <!-- Prevent access to sensitive system directories. -->
<policy domain="path" rights="none" pattern="/etc/*"/>
- <!-- Relative paths are not permitted. -->
+
+ <!-- Prevent directory traversal via relative paths. -->
<policy domain="path" rights="none" pattern="*../*"/>
- <!-- Indirect reading is not permitted. -->
+
+ <!-- Disable indirect file reads (@filename syntax). -->
<policy domain="path" rights="none" pattern="@*"/>
- <!-- Pipes are not permitted. -->
+
+ <!-- Disable pipe-based I/O. -->
<policy domain="path" rights="none" pattern="|*"/>
- <!-- These image types are security risks on read, but write is fine -->
- <policy domain="module" rights="write" pattern="{MSL,MVG,PDF,PS,SVG,TXT,URL,XPS}"/>
- <!-- This policy sets the number of times to replace content of certain
- memory buffers and temporary files before they are freed or deleted. -->
+
+ <!--
+ Permit writing, but not reading, of high-risk formats and pseudo-formats.
+ Reads are blocked; writes remain available when needed.
+ -->
+ <policy domain="module" rights="write"
+ pattern="{MSL,MVG,PDF,PS,SVG,TXT,URL,XPS}"/>
+
+ <!-- Number of overwrite passes before temporary data is deleted. -->
<policy domain="system" name="shred" value="1"/>
- <!-- Enable the initialization of buffers with zeros, resulting in a minor
- performance penalty but with improved security. -->
+
+ <!-- Use anonymous memory mapping for improved memory safety. -->
<policy domain="system" name="memory-map" value="anonymous"/>
- <!-- Set the maximum amount of memory in bytes that are permitted for
- allocation requests. -->
+
+ <!-- Maximum single memory allocation request. -->
<policy domain="system" name="max-memory-request" value="256MiB"/>
- <!-- If the basename of path is a symbolic link, the open fails -->
- <policy domain="system" name="symlink" rights="none" pattern="follow"/>
+
+ <!-- Fail if the target path is a symbolic link. -->
+ <policy domain="system" name="symlink"
+ rights="none" pattern="follow"/>
+
</policymap>
diff --git a/config/policy-websafe.xml b/config/policy-websafe.xml
index 16161fbc2..402c4f3f4 100644
--- a/config/policy-websafe.xml
+++ b/config/policy-websafe.xml
@@ -1,122 +1,127 @@
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE policymap [
<!ELEMENT policymap (policy)*>
- <!ATTLIST policymap
- xmlns CDATA #FIXED ""
- >
-
+ <!ATTLIST policymap xmlns CDATA #FIXED "">
<!ELEMENT policy EMPTY>
- <!ATTLIST policy
- xmlns CDATA #FIXED ""
- domain NMTOKEN #REQUIRED
- name NMTOKEN #IMPLIED
- pattern CDATA #IMPLIED
- rights NMTOKEN #IMPLIED
- stealth NMTOKEN #IMPLIED
- value CDATA #IMPLIED
- >
+ <!ATTLIST policy xmlns CDATA #FIXED "">
+ <!ATTLIST policy domain NMTOKEN #REQUIRED>
+ <!ATTLIST policy name NMTOKEN #IMPLIED>
+ <!ATTLIST policy pattern CDATA #IMPLIED>
+ <!ATTLIST policy rights NMTOKEN #IMPLIED>
+ <!ATTLIST policy stealth NMTOKEN #IMPLIED>
+ <!ATTLIST policy value CDATA #IMPLIED>
]>
+
<!--
- Creating a security policy that fits your specific local environment
- before making use of ImageMagick is highly advised. You can find guidance on
- setting up this policy at https://imagemagick.org/script/security-policy.php,
- and it's important to verify your policy using the validation tool located
- at https://imagemagick-secevaluator.doyensec.com/. We also strongly
- recommend that all users validate their security assumptions by testing their
- configurations after making any policy changes. This helps ensure that the
- intended restrictions are functioning as expected in their specific
- deployment environment.
-
-
- Web-safe ImageMagick security policy:
-
- This security protocol designed for web-safe usage focuses on situations
- where ImageMagick is applied in publicly accessible contexts, like websites.
- It deactivates the capability to read from or write to any image formats
- other than web-safe formats like GIF, JPEG, and PNG. Additionally, this
- policy prohibits the execution of image filters and indirect reads, thereby
- thwarting potential security breaches. By implementing these limitations,
- the web-safe policy fortifies the safeguarding of systems accessible to
- the public, reducing the risk of exploiting ImageMagick's capabilities
- for potential attacks.
+ ImageMagick Web-Safe Security Policy
+
+ This policy is intended for public-facing services that process untrusted
+ images. It reduces ImageMagick's attack surface while preserving support
+ for common raster image operations.
+
+ Security objectives:
+
+ * Limit CPU, memory, disk, and file resource consumption.
+ * Mitigate denial-of-service attacks through resource and runtime limits.
+ * Prevent access to sensitive local files and Linux virtual filesystems.
+ * Prevent indirect file reads via @filename expansion.
+ * Prevent use of stdin/stdout and file descriptor paths.
+ * Disable all delegates and loadable filters.
+ * Disable selected high-risk modules that provide scripting, vector
+ graphics processing, or URL access.
+
+ This policy does not restrict ImageMagick to a specific image format
+ allowlist. Additional coder or module restrictions may be added for
+ deployments requiring a stricter security posture.
+
+ References:
+
+ https://imagemagick.org/security-policy/
+ https://imagemagick-secevaluator.doyensec.com/
-->
+
<policymap>
- <!-- Set maximum parallel threads. -->
+
+ <!-- ============================================================= -->
+ <!-- Resource Limits -->
+ <!-- ============================================================= -->
+
+ <!-- Limit ImageMagick to at most two worker threads. -->
<policy domain="resource" name="thread" value="2"/>
- <!-- Set maximum time to live in seconds or mnemonics, e.g. "2 minutes". When
- this limit is exceeded, an exception is thrown and processing stops. -->
- <policy domain="resource" name="time" value="60"/>
- <!-- Set maximum number of open pixel cache files. When this limit is
- exceeded, any subsequent pixels cached to disk are closed and reopened
- on demand. -->
+
+ <!-- Abort operations that exceed 30 seconds of processing time. -->
+ <policy domain="resource" name="time" value="30"/>
+
+ <!-- Maximum number of simultaneously open pixel-cache files. -->
<policy domain="resource" name="file" value="768"/>
- <!-- Set maximum amount of memory in bytes to allocate for the pixel cache
- from the heap. When this limit is exceeded, the image pixels are cached
- to memory-mapped disk. -->
- <policy domain="resource" name="memory" value="768MiB"/>
- <!-- Set maximum amount of memory map in bytes to allocate for the pixel
- cache. When this limit is exceeded, the image pixels are cached to
- disk. -->
- <policy domain="resource" name="map" value="2GiB"/>
- <!-- Set the maximum width * height of an image that can reside in the pixel
- cache memory. Images that exceed the area limit are cached to disk. -->
+
+ <!-- Maximum heap memory available to the pixel cache. -->
+ <policy domain="resource" name="memory" value="512MiB"/>
+
+ <!-- Maximum amount of memory-mapped pixel cache storage. -->
+ <policy domain="resource" name="map" value="1024MiB"/>
+
+ <!-- Images larger than 32 megapixels spill to disk-backed cache. -->
<policy domain="resource" name="area" value="32MP"/>
- <!-- Set maximum amount of disk space in bytes permitted for use by the pixel
- cache. When this limit is exceeded, the pixel cache is not created
- and an exception is thrown. -->
+
+ <!-- Limit total disk usage for pixel cache and temporary files. -->
<policy domain="resource" name="disk" value="2GiB"/>
- <!-- Set the maximum length of an image sequence. When this limit is
- exceeded, an exception is thrown. -->
+
+ <!-- Limit the number of images permitted in a sequence. -->
<policy domain="resource" name="list-length" value="16"/>
- <!-- Set the maximum width of an image. When this limit is exceeded, an
- exception is thrown. -->
- <policy domain="resource" name="width" value="4KP"/>
- <!-- Set the maximum height of an image. When this limit is exceeded, an
- exception is thrown. -->
- <policy domain="resource" name="height" value="4KP"/>
- <!-- Periodically yield the CPU for at least the time specified in
- milliseconds. -->
- <!-- <policy domain="resource" name="throttle" value="2"/> -->
- <!-- Dynamically yield the CPU relative to the system load average. -->
- <policy domain="resource" name="dynamic-throttle" value="true"/>
- <!-- Do not create temporary files in the default shared directories, instead
- specify a private area to store only ImageMagick temporary files. -->
- <!-- <policy domain="resource" name="temporary-path" value="/magick/tmp/"/> -->
- <!-- Force memory initialization by memory mapping select memory
- allocations. -->
- <policy domain="cache" name="memory-map" value="anonymous"/>
- <!-- Ensure all image data is fully flushed and synchronized to disk. -->
- <policy domain="cache" name="synchronize" value="true"/>
- <!-- Replace passphrase for secure distributed processing -->
- <!-- <policy domain="cache" name="shared-secret" value="secret-passphrase" stealth="true"/> -->
- <!-- Do not permit any delegates to execute. -->
- <policy domain="delegate" rights="none" pattern="*"/>
- <!-- Do not permit any image filters to load. -->
- <policy domain="filter" rights="none" pattern="*"/>
- <!-- Don't read/write from/to stdin/stdout. -->
+
+ <!-- Reject images wider than approximately 8192 pixels. -->
+ <policy domain="resource" name="width" value="8KP"/>
+
+ <!-- Reject images taller than approximately 8192 pixels. -->
+ <policy domain="resource" name="height" value="8KP"/>
+
+ <!-- Prevent excessively large single memory allocation requests. -->
+ <policy domain="system" name="max-memory-request" value="512MiB"/>
+
+ <!-- ============================================================= -->
+ <!-- Path Restrictions -->
+ <!-- ============================================================= -->
+
+ <!-- Disallow reading from or writing to stdin/stdout via "-". -->
<policy domain="path" rights="none" pattern="-"/>
- <policy domain="path" rights="none" pattern="[Ff][Dd]:*"/>
- <!-- Sensitive paths are not permitted. -->
- <policy domain="path" rights="none" pattern="/etc/*"/>
- <!-- Relative paths are not permitted. -->
- <policy domain="path" rights="none" pattern="*../*"/>
- <!-- Indirect reading is not permitted. -->
+
+ <!-- Disable indirect file reads such as @filename. -->
<policy domain="path" rights="none" pattern="@*"/>
- <!-- Pipes are not permitted. -->
- <policy domain="path" rights="none" pattern="|*"/>
- <!-- Deny all image modules and specifically exempt reading or writing
- web-safe image formats. -->
- <policy domain="module" rights="none" pattern="*" />
- <policy domain="module" rights="read | write" pattern="{BMP,GIF,JPEG,PNG,TIFF,WEBP}"/>
- <policy domain="module" rights="read | write" pattern="{MPC}" stealth="true"/>
- <policy domain="module" rights="write" pattern="{JSON,INFO,PNM,PS}"/>
- <!-- This policy sets the number of times to replace content of certain
- memory buffers and temporary files before they are freed or deleted. -->
- <policy domain="system" name="shred" value="1"/>
- <!-- Enable the initialization of buffers with zeros, resulting in a minor
- performance penalty but with improved security. -->
- <policy domain="system" name="memory-map" value="anonymous"/>
- <!-- Set the maximum amount of memory in bytes that are permitted for
- allocation requests. -->
- <policy domain="system" name="max-memory-request" value="256MiB"/>
+
+ <!-- Prevent access to file descriptors (fd:). -->
+ <policy domain="path" rights="none" pattern="[Ff][Dd\\]:*"/>
+
+ <!-- Prevent access to operating system configuration files. -->
+ <policy domain="path" rights="none" pattern="/etc/*"/>
+
+ <!-- Prevent access to Linux process and runtime information. -->
+ <policy domain="path" rights="none" pattern="/proc/*"/>
+
+ <!-- Prevent access to Linux kernel and device nformation. -->
+ <policy domain="path" rights="none" pattern="/sys/*"/>
+
+ <!-- ============================================================= -->
+ <!-- Feature Restrictions -->
+ <!-- ============================================================= -->
+
+ <!-- Disable all external delegates (Ghostscript, ffmpeg, etc.). -->
+ <policy domain="delegate" rights="none" pattern="*"/>
+
+ <!-- Disable all loadable image filters. -->
+ <policy domain="filter" rights="none" pattern="*"/>
+
+ <!-- ============================================================= -->
+ <!-- High-Risk Module Restrictions -->
+ <!-- ============================================================= -->
+
+ <!-- Disable the Magick Vector Graphics interpreter. -->
+ <policy domain="module" rights="none" pattern="MVG"/>
+
+ <!-- Disable the Magick Scripting Language interpreter. -->
+ <policy domain="module" rights="none" pattern="MSL"/>
+
+ <!-- Disable URL, HTTP, HTTPS, and related network access support. -->
+ <policy domain="module" rights="none" pattern="URL"/>
+
</policymap>