From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!.POSTED!not-for-mail From: Glenn Morris Newsgroups: gmane.emacs.bugs Subject: bug#33587: [PROPOSED] Default to disabling ImageMagick Date: Tue, 04 Dec 2018 12:00:48 -0500 Message-ID: References: <20181202180919.32270-1-eggert@cs.ucla.edu> <4qo9a2xwb6.fsf@fencepost.gnu.org> <87tvjtkzgg.fsf@randomsample> NNTP-Posting-Host: blaine.gmane.org Mime-Version: 1.0 Content-Type: text/plain X-Trace: blaine.gmane.org 1543943573 10389 195.159.176.226 (4 Dec 2018 17:12:53 GMT) X-Complaints-To: usenet@blaine.gmane.org NNTP-Posting-Date: Tue, 4 Dec 2018 17:12:53 +0000 (UTC) User-Agent: Gnus (www.gnus.org), GNU Emacs (www.gnu.org/software/emacs/) Cc: Paul Eggert , 33587@debbugs.gnu.org To: David Engster Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Tue Dec 04 18:12:49 2018 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by blaine.gmane.org with esmtp (Exim 4.84_2) (envelope-from ) id 1gUEFc-0002a2-Bg for geb-bug-gnu-emacs@m.gmane.org; Tue, 04 Dec 2018 18:12:48 +0100 Original-Received: from localhost ([::1]:58167 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1gUEHi-0006ej-Ga for geb-bug-gnu-emacs@m.gmane.org; Tue, 04 Dec 2018 12:14:58 -0500 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:48026) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1gUEEp-00030i-Vj for bug-gnu-emacs@gnu.org; Tue, 04 Dec 2018 12:12:06 -0500 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1gUE5F-0007kN-3B for bug-gnu-emacs@gnu.org; Tue, 04 Dec 2018 12:02:07 -0500 Original-Received: from debbugs.gnu.org ([208.118.235.43]:56614) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1gUE5E-0007jo-Du for bug-gnu-emacs@gnu.org; Tue, 04 Dec 2018 12:02:05 -0500 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1gUE5C-0003kI-BY for bug-gnu-emacs@gnu.org; Tue, 04 Dec 2018 12:02:04 -0500 X-Loop: help-debbugs@gnu.org Resent-From: Glenn Morris Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Tue, 04 Dec 2018 17:02:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 33587 X-GNU-PR-Package: emacs X-GNU-PR-Keywords: security Original-Received: via spool by 33587-submit@debbugs.gnu.org id=B33587.154394287614332 (code B ref 33587); Tue, 04 Dec 2018 17:02:02 +0000 Original-Received: (at 33587) by debbugs.gnu.org; 4 Dec 2018 17:01:16 +0000 Original-Received: from localhost ([127.0.0.1]:60872 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1gUE4Q-0003j1-D1 for submit@debbugs.gnu.org; Tue, 04 Dec 2018 12:01:14 -0500 Original-Received: from eggs.gnu.org ([208.118.235.92]:34560) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1gUE4O-0003in-2W for 33587@debbugs.gnu.org; Tue, 04 Dec 2018 12:01:12 -0500 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1gUE4H-00072F-LP for 33587@debbugs.gnu.org; Tue, 04 Dec 2018 12:01:06 -0500 Original-Received: from fencepost.gnu.org ([2001:4830:134:3::e]:58499) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1gUE41-0006ug-TC; Tue, 04 Dec 2018 12:00:49 -0500 Original-Received: from rgm by fencepost.gnu.org with local (Exim 4.82) (envelope-from ) id 1gUE40-0001Cx-F3; Tue, 04 Dec 2018 12:00:48 -0500 X-Spook: doctrine Sarin Semtex Waco, Texas Albanian Irish X-Ran: %5(Q;V`GpJvP[*>QLW*/c-0' (David Engster's message of "Tue, 04 Dec 2018 17:51:11 +0100") X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] X-Received-From: 208.118.235.43 X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Original-Sender: "bug-gnu-emacs" Xref: news.gmane.org gmane.emacs.bugs:153067 Archived-At: David Engster wrote: > Question is: will disabling Imagemagick by default also have an impact > on how Emacs is shipped in distributions? I don't know. It depends whether they go with the default configure options or not. > I don't think so, at least as long as they don't drop Imagemagick > completely. Note that Red Hat Enterprise Linux 8 _will_ drop ImageMagick completely (though it will probably be available from an add-on repository), presumably because they don't feel able to keep up with the security issues. That's what prompted me to first raise this in http://lists.gnu.org/r/emacs-devel/2018-12/msg00036.html > If for instance Debian has to take care of Imagemagick security issues > anyway, why shouldn't Emacs link to it? (For reference: https://security-tracker.debian.org/tracker/source-package/imagemagick ) Because one can never guarantee all security issues are fixed, and if a project has a history of having a lot of them, it may be considered likely to be insecure. Also there are the various Emacs crash reports due to ImageMagick.