mirror of
https://github.com/ImageMagick/ImageMagick.git
synced 2026-10-05 17:35:35 +02:00
139 lines
4.9 KiB
XML
139 lines
4.9 KiB
XML
<?xml version="1.0" encoding="UTF-8"?>
|
|
<!DOCTYPE policymap [
|
|
<!ELEMENT policymap (policy)*>
|
|
<!ATTLIST policymap
|
|
xmlns CDATA #FIXED ""
|
|
>
|
|
|
|
<!ELEMENT policy EMPTY>
|
|
<!ATTLIST policy
|
|
xmlns CDATA #FIXED ""
|
|
domain NMTOKEN #REQUIRED
|
|
name NMTOKEN #IMPLIED
|
|
pattern CDATA #IMPLIED
|
|
rights NMTOKEN #IMPLIED
|
|
stealth NMTOKEN #IMPLIED
|
|
value CDATA #IMPLIED
|
|
>
|
|
]>
|
|
|
|
<!--
|
|
ImageMagick Security Policy
|
|
|
|
Creating a security policy that fits your specific environment before using
|
|
ImageMagick is highly recommended. Documentation is available at:
|
|
|
|
https://imagemagick.org/script/security-policy.php
|
|
|
|
Validate policy changes with the ImageMagick security policy evaluator:
|
|
|
|
https://imagemagick-secevaluator.doyensec.com/
|
|
|
|
After making policy changes, test and validate your configuration to ensure
|
|
restrictions are functioning as intended in your deployment environment.
|
|
|
|
This policy implements a restrictive security posture suitable for processing
|
|
untrusted images. It limits resource consumption, disables delegates and
|
|
filters, restricts filesystem access, blocks indirect reads and pipes, and
|
|
prevents reading several historically high-risk formats while continuing to
|
|
permit writing them when required. Review and adjust these settings to meet
|
|
your organization's operational and security requirements.
|
|
-->
|
|
|
|
<policymap>
|
|
|
|
<!-- Maximum number of processing threads. -->
|
|
<policy domain="resource" name="thread" value="2"/>
|
|
|
|
<!-- Maximum execution time in seconds before processing is aborted. -->
|
|
<policy domain="resource" name="time" value="120"/>
|
|
|
|
<!-- Maximum number of open pixel cache files. -->
|
|
<policy domain="resource" name="file" value="768"/>
|
|
|
|
<!-- Maximum heap memory available for pixel cache data. -->
|
|
<policy domain="resource" name="memory" value="768MiB"/>
|
|
|
|
<!-- Maximum memory-mapped cache size before disk caching is required. -->
|
|
<policy domain="resource" name="map" value="2GiB"/>
|
|
|
|
<!-- Maximum image area allowed in memory before disk caching is used. -->
|
|
<policy domain="resource" name="area" value="32MP"/>
|
|
|
|
<!-- Maximum disk space available for the pixel cache. -->
|
|
<policy domain="resource" name="disk" value="2GiB"/>
|
|
|
|
<!-- Maximum number of images permitted in a sequence. -->
|
|
<policy domain="resource" name="list-length" value="32"/>
|
|
|
|
<!-- Maximum permitted image width. -->
|
|
<policy domain="resource" name="width" value="8KP"/>
|
|
|
|
<!-- Maximum permitted image height. -->
|
|
<policy domain="resource" name="height" value="8KP"/>
|
|
|
|
<!-- Periodically yield CPU time (milliseconds). -->
|
|
<!-- <policy domain="resource" name="throttle" value="2"/> -->
|
|
|
|
<!-- Dynamically adjust CPU usage based on system load. -->
|
|
<!-- <policy domain="resource" name="dynamic-throttle" value="true"/> -->
|
|
|
|
<!-- Use a dedicated directory for ImageMagick temporary files. -->
|
|
<!-- <policy domain="resource" name="temporary-path" value="/magick/tmp/"/> -->
|
|
|
|
<!-- Zero-initialize selected allocations using anonymous memory mapping. -->
|
|
<policy domain="cache" name="memory-map" value="anonymous"/>
|
|
|
|
<!-- Force cache data to be synchronized to disk. -->
|
|
<policy domain="cache" name="synchronize" value="true"/>
|
|
|
|
<!-- Shared secret for distributed cache operations. -->
|
|
<!-- <policy domain="cache" name="shared-secret"
|
|
value="secret-passphrase" stealth="true"/> -->
|
|
|
|
<!-- Disable execution of all delegates. -->
|
|
<policy domain="delegate" rights="none" pattern="*"/>
|
|
|
|
<!-- Disable loading of all image filters. -->
|
|
<policy domain="filter" rights="none" pattern="*"/>
|
|
|
|
<!-- Prevent reading from stdin and writing to stdout. -->
|
|
<policy domain="path" rights="none" pattern="-"/>
|
|
|
|
<!-- Prevent access to file descriptors. -->
|
|
<policy domain="path" rights="none" pattern="[Ff][Dd\]:*"/>
|
|
|
|
<!-- Prevent access to sensitive system directories. -->
|
|
<policy domain="path" rights="none" pattern="/etc/*"/>
|
|
|
|
<!-- Prevent directory traversal via relative paths. -->
|
|
<policy domain="path" rights="none" pattern="*../*"/>
|
|
|
|
<!-- Disable indirect file reads (@filename syntax). -->
|
|
<policy domain="path" rights="none" pattern="@*"/>
|
|
|
|
<!-- Disable pipe-based I/O. -->
|
|
<policy domain="path" rights="none" pattern="|*"/>
|
|
|
|
<!--
|
|
Permit writing, but not reading, of high-risk formats and pseudo-formats.
|
|
Reads are blocked; writes remain available when needed.
|
|
-->
|
|
<policy domain="module" rights="write"
|
|
pattern="{MSL,MVG,PDF,PS,SVG,TXT,URL,XPS}"/>
|
|
|
|
<!-- Number of overwrite passes before temporary data is deleted. -->
|
|
<policy domain="system" name="shred" value="1"/>
|
|
|
|
<!-- Use anonymous memory mapping for improved memory safety. -->
|
|
<policy domain="system" name="memory-map" value="anonymous"/>
|
|
|
|
<!-- Maximum single memory allocation request. -->
|
|
<policy domain="system" name="max-memory-request" value="256MiB"/>
|
|
|
|
<!-- Fail if the target path is a symbolic link. -->
|
|
<policy domain="system" name="symlink"
|
|
rights="none" pattern="follow"/>
|
|
|
|
</policymap>
|