phongn opened a new issue, #13774:
URL: https://github.com/apache/trafficserver/issues/13774
**Problem**
webp_transform passes origin response bodies to ImageMagick, which chooses a
coder by sniffing the bytes. The plugin never restricts ImageMagick, so the
effective policy is whatever `policy.xml` the host has. If none is found,
ImageMagick's built-in default allows everything.
Today `has_signature_for()` only lets through bodies that start with a JPEG,
PNG or WebP signature, so this is a defense-in-depth gap rather than a known
hole. But nothing inside ImageMagick enforces that restriction. If any path
ever reached it, ImageMagick would still parse SVG, MSL, PostScript (via
Ghostscript), TIFF, MNG and others. MNG and JNG are part of the same module as
PNG.
Related issues:
- **Animated WebP:** ImageMagick decodes every frame before Magick++ keeps
the first, so the work grows with the frame count up to the resource limits.
- **Host limits:** a host `policy.xml` can lower the plugin's decode limits.
When it does, conversions quietly turn into pass-throughs and nothing is logged.
- **The `websafe` policy doesn't fit.** ImageMagick's own websafe policy
isn't a drop-in fix:
- With the plugin's `disk(0)`, its 8000-pixel area limit fails nearly
every image.
- Its `dynamic-throttle` setting sleeps on event threads.
- It still allows GIF, BMP, TIFF, MNG and JNG.
- It's a build-time option only from ImageMagick 7.1.1-16.
**Proposal**
At init, install a policy specific to the plugin with
`SetMagickSecurityPolicy()`, which is available since IM6 6.9.10 and IM7 7.0.10:
- Allow only the coders and modules the plugin uses: read JPEG, PNG and
WebP; write JPEG and WebP.
- Deny delegates (external programs), filters and file paths.
- Limit decodes to single-frame images.
- Never re-allow anything the host policy denies. If the host denies a
format the plugin needs, log an error and disable the plugin.
- Check the result after installing the policy, and disable the plugin if it
didn't take effect.
- At startup, warn about host settings that quietly prevent conversions:
lowered limits, a time limit, dynamic throttling, or a small
`max-memory-request`.
The policy applies to the whole process, so it would also restrict other
ImageMagick users in the same `traffic_server`, such as the experimental
`magick` plugin. That should be documented.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]