Files
2026-10-04 07:43:42 -04:00

139 lines
4.9 KiB
XML

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE policymap [
<!ELEMENT policymap (policy)*>
<!ATTLIST policymap
xmlns CDATA #FIXED ""
>
<!ELEMENT policy EMPTY>
<!ATTLIST policy
xmlns CDATA #FIXED ""
domain NMTOKEN #REQUIRED
name NMTOKEN #IMPLIED
pattern CDATA #IMPLIED
rights NMTOKEN #IMPLIED
stealth NMTOKEN #IMPLIED
value CDATA #IMPLIED
>
]>
<!--
ImageMagick Security Policy
Creating a security policy that fits your specific environment before using
ImageMagick is highly recommended. Documentation is available at:
https://imagemagick.org/script/security-policy.php
Validate policy changes with the ImageMagick security policy evaluator:
https://imagemagick-secevaluator.doyensec.com/
After making policy changes, test and validate your configuration to ensure
restrictions are functioning as intended in your deployment environment.
This policy implements a restrictive security posture suitable for processing
untrusted images. It limits resource consumption, disables delegates and
filters, restricts filesystem access, blocks indirect reads and pipes, and
prevents reading several historically high-risk formats while continuing to
permit writing them when required. Review and adjust these settings to meet
your organization's operational and security requirements.
-->
<policymap>
<!-- Maximum number of processing threads. -->
<policy domain="resource" name="thread" value="2"/>
<!-- Maximum execution time in seconds before processing is aborted. -->
<policy domain="resource" name="time" value="120"/>
<!-- Maximum number of open pixel cache files. -->
<policy domain="resource" name="file" value="768"/>
<!-- Maximum heap memory available for pixel cache data. -->
<policy domain="resource" name="memory" value="768MiB"/>
<!-- Maximum memory-mapped cache size before disk caching is required. -->
<policy domain="resource" name="map" value="2GiB"/>
<!-- Maximum image area allowed in memory before disk caching is used. -->
<policy domain="resource" name="area" value="32MP"/>
<!-- Maximum disk space available for the pixel cache. -->
<policy domain="resource" name="disk" value="2GiB"/>
<!-- Maximum number of images permitted in a sequence. -->
<policy domain="resource" name="list-length" value="32"/>
<!-- Maximum permitted image width. -->
<policy domain="resource" name="width" value="8KP"/>
<!-- Maximum permitted image height. -->
<policy domain="resource" name="height" value="8KP"/>
<!-- Periodically yield CPU time (milliseconds). -->
<!-- <policy domain="resource" name="throttle" value="2"/> -->
<!-- Dynamically adjust CPU usage based on system load. -->
<!-- <policy domain="resource" name="dynamic-throttle" value="true"/> -->
<!-- Use a dedicated directory for ImageMagick temporary files. -->
<!-- <policy domain="resource" name="temporary-path" value="/magick/tmp/"/> -->
<!-- Zero-initialize selected allocations using anonymous memory mapping. -->
<policy domain="cache" name="memory-map" value="anonymous"/>
<!-- Force cache data to be synchronized to disk. -->
<policy domain="cache" name="synchronize" value="true"/>
<!-- Shared secret for distributed cache operations. -->
<!-- <policy domain="cache" name="shared-secret"
value="secret-passphrase" stealth="true"/> -->
<!-- Disable execution of all delegates. -->
<policy domain="delegate" rights="none" pattern="*"/>
<!-- Disable loading of all image filters. -->
<policy domain="filter" rights="none" pattern="*"/>
<!-- Prevent reading from stdin and writing to stdout. -->
<policy domain="path" rights="none" pattern="-"/>
<!-- Prevent access to file descriptors. -->
<policy domain="path" rights="none" pattern="[Ff][Dd\]:*"/>
<!-- Prevent access to sensitive system directories. -->
<policy domain="path" rights="none" pattern="/etc/*"/>
<!-- Prevent directory traversal via relative paths. -->
<policy domain="path" rights="none" pattern="*../*"/>
<!-- Disable indirect file reads (@filename syntax). -->
<policy domain="path" rights="none" pattern="@*"/>
<!-- Disable pipe-based I/O. -->
<policy domain="path" rights="none" pattern="|*"/>
<!--
Permit writing, but not reading, of high-risk formats and pseudo-formats.
Reads are blocked; writes remain available when needed.
-->
<policy domain="module" rights="write"
pattern="{MSL,MVG,PDF,PS,SVG,TXT,URL,XPS}"/>
<!-- Number of overwrite passes before temporary data is deleted. -->
<policy domain="system" name="shred" value="1"/>
<!-- Use anonymous memory mapping for improved memory safety. -->
<policy domain="system" name="memory-map" value="anonymous"/>
<!-- Maximum single memory allocation request. -->
<policy domain="system" name="max-memory-request" value="256MiB"/>
<!-- Fail if the target path is a symbolic link. -->
<policy domain="system" name="symlink"
rights="none" pattern="follow"/>
</policymap>