> From [EMAIL PROTECTED] Tue Dec 11 18:26:57 2001
> Date: Tue, 11 Dec 2001 20:19:34 -0500
> From: Alan McConnell <[EMAIL PROTECTED]>
> To: [EMAIL PROTECTED]
> Subject: LPRng: An ifhp Anomaly
>
> Dear Printer-Strugglers,
>
> I have a problem with some extra lines of "reprobation" that ifhp seems
> to add to a print job.  The basic problem: printing a .ps file.
        I have found a "fix" to the problem of ifhp adding the extra
        text to my PCL file.  Mr Powell provided the clue, when he wrote:
"I suspect that you have upgraded your GhostScript,  right?
And the GhostScript writers have read the security alert that
I put out,  which demonstrated how you can use GhostScript to
print files on the print server.

"So they plugged the leak.  Now when you use '-dSAFER',  it does
not allow you to open ANY files... including  the -sOutputFile...
   gs -q -sDEVICE=laserjet -sPAPERSIZE=letter -dNOPAUSE -dSAFER
         -sOutputFile='/tmp/$1.READY.TO.PRINT' $1

"So you need to use:
   gs -q -sDEVICE=laserjet -sPAPERSIZE=letter -dNOPAUSE -dSAFER -sOutputFile=-
          >"/tmp/$1.READY.TO.PRINT" $1

Isn't security WONDERFUL???"
        <G>  But that is not quite the problem.

My ghostscript is indeed 7.00.  And, following the suggestions in ifhp
about security, I had changed my . . ./7.00/lib/gs_init.ps as follows

%  Alan inserted the following two lines, following ifhp suggestion
%   If the /run line is uncommented, gv doesn't run, but ghostview does! ?
  /file { /invalidfileaccess signalerror } odef
% /run { /invalidfileaccess signalerror } odef

This was the way the file was from the time I installed ifhp until today.
(I had quickly commented back in the "/run" line, as I noted, since I
like gv<g>)

So today I commented back  the "/file" line.  I.e. my gs_init.ps now looks
like:

%  Alan inserted the following two lines, following ifhp suggestion
%   If the /run line is uncommented, gv doesn't run, but ghostview does! ?
%  Alan, on 19 Dec, commented up both lines, to fix the "%stdout" error
% /file { /invalidfileaccess signalerror } odef
% /run { /invalidfileaccess signalerror } odef

And indeed, I no longer get the extra sheet of paper with "%stdout" as
the only mark on it.

So far so good.  But I don't understand Mr Powell's two examples of
gs commands given above.  Both these commands have worked, and worked
since "time immemorial", without producing the extra sheet of paper.

So my hope is that, somehow, something can be added to gs_init.ps so
that I don't someday catch a postscript file with malevolent crud in it.
This is as we all know one of the main Linux security dangers.

The question:  why can I, with the above gs_init.ps lines _un_commented
run the gs command as Mr Powell gave it,  but ifhp produces the bothersome
paper-consuming error?

I know that this is complicated, and I'm probably not explaining it
optimally.  I crave everyone's patience, in particular Mr Powell's<g>

Best wishes,

Alan

-- 
Alan McConnell      By night our missiles rain on them / By day we drop
http://patriot.     them bread. / They should be grateful for the food --
net/users/alan      / Unless, of course, they're dead. (Calvin Trillin)

-----------------------------------------------------------------------------
YOU MUST BE A LIST MEMBER IN ORDER TO POST TO THE LPRNG MAILING LIST
The address you post from MUST be your subscription address

If you need help, send email to [EMAIL PROTECTED] (or lprng-requests
or lprng-digest-requests) with the word 'help' in the body.  For the impatient,
to subscribe to a list with name LIST,  send mail to [EMAIL PROTECTED]
with:                           | example:
subscribe LIST <mailaddr>       |  subscribe lprng-digest [EMAIL PROTECTED]
unsubscribe LIST <mailaddr>     |  unsubscribe lprng [EMAIL PROTECTED]

If you have major problems,  send email to [EMAIL PROTECTED] with the word
LPRNGLIST in the SUBJECT line.
-----------------------------------------------------------------------------

Reply via email to