imagemagick is full of crusty old code, which was never written with security in mind. This task is about containing the scaling process with firejail.
Description
Details
Related Objects
- Mentioned In
- rOPUP4d8d6c717117: Install firejail von image/video scalers
rOPUP05538c3d5be3: Install firejail on image/video scalers
rOPUPf5b694ff4b9a: Install firejail on image/video scalers
rOPUP91ff88e657ac: Provide a firejail profile for the image scalers
rOPUP05478b9594bf: Provide a firejail profile for the image scalers
rOPUPe6cb6629c388: Provide a firejail profile for the image scalers
rOPUPf95a596861d3: Provide a firejail profile for the image scalers
rOPUPed7b634a2805: Add firejail profile and wrapper for ghostscript
rOPUPed6ddbc11a0a: Add firejail profile and wrapper for ghostscript
rOPUP3fbbcc64c500: Add firejail profile and wrapper for ghostscript
rOPUPbd9563de9528: Provide the firejail containment for imagemagick's convert(1) on all app servers
rOPUPa16f9792a7c8: Provide the firejail containment for imagemagick's convert(1) on all app servers
rOPUP9d9feea1df57: Provide the firejail containment for imagemagick's convert(1) on all app servers
rOPUP8653d7115b57: Install firejail profile for convert
rOPUP74f226dd476d: Install firejail profile for convert
rOPUP3fb3c17264f4: Provide the firejail containment for imagemagick's convert(1) on all app servers
rOPUP811faad18cf9: Add firejail profile and wrapper for ghostscript
rOPUP378f6463efb3: Provide a firejail profile for the image scalers
rOPUP2d6c5d6b880f: Install firejail on image/video scalers
Event Timeline
Change 288379 had a related patch set uploaded (by Muehlenhoff):
Install firejail von image/video scalers
Change 288390 had a related patch set uploaded (by Muehlenhoff):
WIP: Use firejail in image scaling
Change 290696 had a related patch set uploaded (by Muehlenhoff):
Provide a firejail profile for the image scalers
Change 288390 abandoned by Muehlenhoff:
WIP: Use firejail in image scaling
Reason:
This will be handled differently: The current patch doesn't work with the way the scaler extension shells out. Also since other extensions also invoke convert(1) this is now going to be handled via a wrapper (which was tested successfully). The respective new changes are 290696 and 290909
Change 290696 merged by Muehlenhoff:
Provide a firejail profile for the image scalers
Change 291202 had a related patch set uploaded (by Muehlenhoff):
Enable firejail for image scaling
Change 291924 had a related patch set uploaded (by Muehlenhoff):
Add firejail profile and wrapper for ghostscript
Change 291924 merged by Muehlenhoff:
Add firejail profile and wrapper for ghostscript
Change 293328 had a related patch set uploaded (by Muehlenhoff):
Provide the firejail containment for imagemagick's convert(1) on all app servers
Change 293328 merged by Muehlenhoff:
Provide the firejail containment for imagemagick's convert(1) on all app servers
Change 294458 had a related patch set uploaded (by Muehlenhoff):
Reenable firejail wrapper for imagemagick's convert
Change 294458 merged by Muehlenhoff:
Reenable firejail wrapper for imagemagick's convert
This is enabled on the image scalers (and app servers for the Score extensions) since last week