summaryrefslogtreecommitdiff
path: root/graphics/GraphicsMagick/Makefile
AgeCommit message (Collapse)AuthorFilesLines
2022-11-23massive revision bump after textproc/icu updateadam1-2/+2
2022-10-26*: bump PKGREVISION for libunistring shlib major bumpwiz1-2/+2
2022-06-28*: recursive bump for perl 5.36wiz1-2/+2
2022-04-18revbump for textproc/icu updateadam1-1/+2
2021-12-14GraphicsMagick: updated to 1.3.37adam1-2/+1
1.3.37 (December ?, 2021) ========================== Special Issues: * The FTP site ftp.graphicsmagick.org is now shut down due to a lack of bandwith, extremely abusive users (including from Google and customers of Amazon Web Services), and a lack of support from the user community. Another factor is that FTP support has been removed from popular web browsers. This is very unfortunate since the site served multiple usages, including providing a lot of historical data (e.g. related to PNG) which may not be available elsewhere. * The Microsoft Visual Studio build has not been updated for this release (although it does compile and the results do work fine) and I will not be providing any Windows installation packages corresponding to this release. The problem is that the third-party 'delegate' libraries are out of date and they need to be updated since some of them are known to contain severe security vulnerabilities. Several third-party 'delegate' libraries now require real C'99 support, which means that Visual Studio 2015 or later would be required to build them. The 'configure' program used to build the Visual Studio project files needs to be updated since otherwise a 20 minute project upgrade cycle is needed when using Visual Studio 2019, and to make minor path changes to avoid a multitude of project-file warnings while building. The installation requirements for Visual Studio 2015 or later are different (related to run-time "redistributables", which are now very onerous) and so the Inno Setup installer needs some minor (or major) changes. Many pleas for assistance have been made (e.g. even to help with testing to see if the software executes at all) but thus far the Microsoft Windows user community has not been helpful with regards to the Microsoft Visual Studio build. * GraphicsMagick really does need some additional productive volunteers. For several years now, the burden has entirely been on me. I have been sheparding the project for 19 years already (and contributed to ImageMagick and GraphicsMagick combined for 25 years already). It is not reasonable to expect someone with a full time job (and expecting to retire in a couple of years) to do all of the work. Security Fixes: * GraphicsMagick is participating in Google's oss-fuzz project due to the contributions and assistance of Alex Gaynor. Since February 4 2018, 590 issues have been opened by oss-fuzz and 23 issues remain open (most of which are in third-party software such as development JasPer). The issues list is available at https://bugs.chromium.org/p/oss-fuzz/issues/list under search term "graphicsmagick". Issues are available for anyone to view and duplicate if they have been in "Verified" status for 30 days, or if they have been in "New" status for 90 days. Please consult the GraphicsMagick ChangeLog file, Mercurial repository commit log, and the oss-fuzz issues list for details. Bug fixes: * CAPTION: Eliminate an assertion upon deallocation. * CMYK: Fix broken reading of planar CMYK files (a regression since 1.3.27). * ExecuteModuleProcess(): Add missing error reporting related to the -module command option. * GIF: Handle GIF files where the 'opaque' index matches the number of colors by producing an extra colormap entry of transparent black. * JP2: Adaptations to compile cleanly with JasPer 2.0.20. * META: Fix types used to prefer unsigned types where possible and to use 'size_t' rather than 'int' for size values. * MSL: A great many MSL parser fixes. * Microsoft Windows: Detect and use Ghostscript point versions added after 9.52, after which the version number format was changed. * PCX: Fix problem that 16-colors are used rather than 256-colors * PDF: Fix MediaBox dimensions ("Incorrect MediaBox in PDF export"). * PDF: Use appropriate memory deallocator for memory returned by StringToList(). * RGB: Fix broken reading of planar RGB files (a regression since 1.3.27). * TIFF: Fix double-charging for memory allocations (a regression since 1.3.36). * TIFF: Make sure that loops using TIFFReadScanline(), etc, do quit upon first reported error. * WEBP: Enforce that embedded profiles provided by libWebP are not zero-sized. * WEBP: Use SetImagePixelsEx() rather than GetImagePixelsEx() in reader. * WriteBlob(): Use appropriate handle for bzip2. New Features: * None API Updates: * DisposeTypeToString(): New utility function to convert a DisposeType to a string. * StringToDisposeType(): New utility function to convert a string to a DisposeType. Feature improvements: * JP2: Support building using development JasPer 3.0.0 and request that it use our managed-memory allocators for resource control. * Pixel Cache: Memory cache implementation of pixel cache now uses resource limited memory allocator. * Analyze filter module: Add OpenMP speed-ups. * IsImagesEqual(): Allow comparing images when the 'matte' channel flag differs. Windows Delegate Updates/Additions: * Remove bundled hp2xx.exe, mpeg2dec.exe, and mpeg2enc.exe. Build Changes: * Microsoft Windows: configure.ac fixes for gdi32 to depend on user32 as well. * Microsoft Windows: VisualMagick/All/All.vcproj.in updated to fix problem with not being able to load the 'All' project if the project supports the x64 target. * Autotools build, many more TAP tests have been added, including to exercise all of the 'convert' commands. * TIFF: Adaptations to compile cleanly for libtiff versions beyond 20201219. * Magick++: Support compiling with C++'98 through C++'17. * Autotools build, Add support for using an external 'graphicsmagick_snapshot_copy' script to copy files for the 'snapshot' target. This provides local control over how files are copied and where they are copied to. Behavior Changes: * TranslateTextEx(): If image resolution is impossibly small, then report the default resolution of 72 DPI, or the equivalent in centimeters if units is in pixels-per-centimeter.
2021-12-08revbump for icu and libffiadam1-2/+2
2021-09-29revbump for boost-libsadam1-2/+2
2021-05-24*: recursive bump for perl 5.34wiz1-2/+2
2021-04-21revbump for boost-libsadam1-2/+2
2021-04-21revbump for textproc/icuadam1-1/+2
2021-01-24graphicsmagick: Update to 1.3.36nia1-2/+1
1.3.36 (December 26, 2020) ========================== Special Issues: * None Security Fixes: * GraphicsMagick is participating in Google's oss-fuzz project due to the contributions and assistance of Alex Gaynor. Since February 4 2018, 454 issues have been opened by oss-fuzz (some of which were benign build issues such as SourceForge Mercurial not working correctly) and 7 issues remain open (all of which are marked in an "unreproducible" state). The issues list is available at https://bugs.chromium.org/p/oss-fuzz/issues/list under search term "graphicsmagick". Issues are available for anyone to view and duplicate if they have been in "Verified" status for 30 days, or if they have been in "New" status for 90 days. Please consult the GraphicsMagick ChangeLog file, Mercurial repository commit log, and the oss-fuzz issues list for details. * WPG: Fixes for heap buffer overflow. Bug fixes: * ConstituteImage(): Set image depth appropriately based on the storage size specified by StorageType and QuantumDepth. * GetImageBoundingBox(): Fix problem that MagickTrimImage with extreme fuzz values could produce an image with negative width. * ImageToFile(): Improve error handling to avoid possible deferred deletion of temporary files, causing unexpected excessive use of temporary file space. * JNG: Add validations for alpha compression method values and use this information to enforce decoding using the appropriate sub-format (rather than auto-detecting the format). Also, address memory leaks which may occur if the sub-decoder does something other than was expected. * MagickCondSignal(): Improvements to conditional signal handler registration (which avoids over-riding signal handlers previously registered by an API user). * ModifyCache(): Fix memory leak. * ReadCacheIndexes(): Don't blunder into accessing a null pointer if the using code has ignored a previous error report bubled-up from SetNexus(). * MNG: When doing image scaling and the image width or height is 1 then always use simple pixel replication as per the MNG specification. * MVG: Fixes to 'push clip-path foo' and 'pop clip-path foo' parsing to eliminate a class of malign behavior. * MVG: Place an aribrary limit on stroke dash polygon unit maximum length in order to avoid possibly rendering "forever". * PCL: No longer attempt to handle reading HP PCL format via the external 'hp2xx' program since it seems worthless for that task. * PS: Fix corrupt image when writing PseudoClass image with a colormap larger than two entries as bilevel. * SVG: Memory leak fixes. * SVG reader: Now support 'ping' support so the identify command works as expected. * TIFF: WEBP compression only supports a depth of 8 so force that value. * Wand MagickSetSamplingFactors(): Correct formatting of sampling factors string. New Features: * Logging is now fully programmable. * DPX format: Support dpx:swap-samples-read define which behaves similar to dpx:swap-samples, but is only applied when reading, as well as dpx:swap-samples-write, which is only applied when writing. This provides for use when there is both reading and writing in the same operation (otherwise the final result was no effect!). API Updates: * magick/api.h: Add "magick/enum_strings.h" to API headers. * New log settings accessor C functions: SetLogDefaultFileName(), SetLogDefaultFormat(), SetLogDefaultOutputType(), SetLogDefaultLogMethod(), SetLogDefaultLimit(), SetLogDefaultGenerations(), SetLogDefaultEventType(). These functions allow a program to set the same parameters which may be set by loading a "log.mgk" function. If a default logging callback was provided via SetLogDefaultLogMethod() such that MethodOutput is used, then the search for a "log.mgk" is avoided entirely. * New log settings accessor C++ functions: SetLogDefaultFileName(), SetLogDefaultFormat(), SetLogDefaultOutputType(), SetLogDefaultLogMethod(), SetLogDefaultLimit(), SetLogDefaultGenerations(), SetLogDefaultEventType(). These C++ functions just pass through to the equivalent C functions and provide the same benefits. Feature improvements: * A simple resource-limit respecting memory allocator has been developed for internal use wherever arbitrarily-large amounts of memory might be requested. This will gradually be added wherever it appears to be needed. The memory resource limits are at the overall process level. The MVG/SVG rendering code is updated to use this new allocator. Almost all of the coders (image format readers/writers) have now been updated to use this new allocator. This means that '-limit memory 300MB' would be more complete and meaningful now. Temporary allocations by the image processing algorithms (other than for the images themselves) are still not accounted for in the resource limiting. * MVG Renderer / DrawImage(): Use resource-limit respecting memory allocators for remaining large memory allocations. * PNG writer: Don't skip optional Exif identifier code if it isn't present. * DPX reader/writer: decode/encode of 10-bit packed DPX is now twice as fast due to code simplification. * TIFF reader: Apply the same resource limits to TIFF tile sizes as apply to the image itself. Windows Delegate Updates/Additions: * None Build Changes: * configure.ac: Update syntax to avoid using deprecated syntax according to Autoconf 2.69. Also added copious m4 quoting. * Magick++ Drawable base class no longer uses std::unary_function when compiled using C++'17 or later, since this feature has been removed from the language. * Support the configure option --disable-compressed-files to disable automatic decompress of gzip and bzip2 compressed files (e.g. files with extension 'gz' or 'bz2', and sometimes 'svgz', but sometimes posing as some other format). It turns out that there are some extremely compressed files (e.g. over 1000x compression ratio) which can take a long time to decompress and produce large temporary files. We currently normally wait for the whole file to be decompressed before decoding it. The only exception is for coders with native 'blob' support and which do not require seeking, and that the user forced forced the format by adding a magick prefix like "DPX:file.dpx" to avoid the automatic file format detection. * Support the configure option --without-gs to disable reading PS, EPS, and PDF formats via an external Ghostscript delegate program. This corresponds to the HasGS definition in the source code. * Support the configure option --without-gdi32 to support disabling use of the Microsoft Windows gdi32 library if it is not wanted. * The Automake-based test suite now applies a memory limit of 128MB for the Q8, or 256MB for the Q16, or 512MB for the Q32 build, as well as setting a disk space limit of 0. The limits place an upper bound on the resources required, while assuring that tests do pass with resource limits applied, while also assuring that disk-based pixel-cache files are not used. Behavior Changes: * Previously the formatting settings from "log.mgk" were only used when writing to a file, or to the console, via a file handle. Now the log formatting has been normalized so that the settings provided by "log.mgk" (or SetLogDefaultFormat()) will always be used. It is possible this may result in some formatting changes. * In the Windows Visual Studio build, the ProvideDllMain option is now disabled by default (can still be enabled) since it causes InitializeMagick() to be invoked prior to when the program's main() routine is called, thereby blocking configuration activities or use of InitializeMagickEx(). With this change it is even more imperative that InitializeMagick() be explicitly invoked by all programs using GraphicsMagick.
2020-12-04Revbump for openpam cppflags change months ago, belatedly.riastradh1-2/+2
2020-11-05*: Recursive revbump from textproc/icu-68.1ryoon1-2/+2
2020-10-22GraphicsMagick: Skip a file with CTF issues.jperkin1-1/+3
2020-08-31*: bump PKGREVISION for perl-5.32.wiz1-2/+2
2020-08-17*: revbump after fontconfig bl3 changes (libuuid removal)leot1-2/+2
2020-06-02Revbump for icuadam1-2/+2
2020-05-22revbump after updating security/nettleadam1-2/+2
2020-05-03graphics/GraphicsMagick: remove unknown configure optionsrillig1-3/+1
2020-03-10librsvg: update bl3.mk to remove libcroco in rust casewiz1-2/+2
recursive bump for the dependency change
2020-03-08*: recursive bump for libffiwiz1-1/+2
2020-01-08GraphicsMagick: Update COMMENTnia1-2/+2
2020-01-08GraphicsMagick: Update to 1.3.34nia1-2/+1
1.3.34 (December 24, 2019) ========================== Special Issues: * It has been discovered that the 'ICU' library (a perhaps 30MB C++ library) which is now often a libxml2 dependendency causes huge process initialization overhead. This is noticed as unexpected slowness when GraphicsMagick utilities are used to process small to medium sized files. The time to initialize the 'ICU' library is often longer than the time that GraphicsMagick would otherwise require to read the input file, process the image, and write the output file. If the 'ICU' dependency can not be avoided, then make sure to use the modules build so there is only impact for file formats which require libxml2. Please lobby the 'ICU' library developers to change their implementation to avoid long start-up times due to merely linking with the library. Security Fixes: * GraphicsMagick is now participating in Google's oss-fuzz project due to the contributions and assistance of Alex Gaynor. Since February 4 2018, 386 issues have been opened by oss-fuzz (some of which were benign build issues) and 376 of those issues have been resolved. The issues list is available at https://bugs.chromium.org/p/oss-fuzz/issues/list under search term "graphicsmagick". Issues are available for anyone to view and duplicate if they have been in "Verified" status for 30 days, or if they have been in "New" status for 90 days. There are too many fixes to list here. Please consult the GraphicsMagick ChangeLog file, Mercurial repository commit log, and the oss-fuzz issues list for details. Bug fixes: * DPS: Eliminate a memory leak. * Debug Trace: Only output text to terminate an XML format log file if XML format is active. * EXIF Parser: Detect non-terminal parsing and report an error. * EXIF Parser: Eliminate heap buffer overflows. * HuffmanDecodeImage(): Fix heap overflow in 32-bit applications. * MAT: Implement subimage/subrange support. * MVG: Address non-terminal loops, excessive run-time, thrown assertions, divide-by-zero, heap overflow, and memory leaks. * OpenModule(): Now properly case-insensitive, as it used to be. * PCX: Verify that pixel region is not negative. Assure that opacity channel is initialized to opaqueOpacity. Update DirectClass representation while PseudoClass representation is updated. Improve read performance with uncompressed PCX. * PICT: Fix heap overflow in PICT writer. * PNG: Fix validation of raw profile length. * PNG: Skip coalescing layers if there is only one layer. * PNM: Fix denial of service opportunity by limiting the length of PNM comment text. * WPG: Avoid Avoid dereferencing a null pointer. * WPG: Implement subimage/subrange support. * WPG: Improve performance when reading an embedded image. * Wand library: In MagickClearException(), destroy any existing exception info before re-initializing the exception info or else there will be a memory leak. * XPM: Rquire that image properties appear in the first 512 bytes of the XPM file header. New Features: * Visual Studio build supports JBIG and WebP compression in TIFF format. API Updates: * None Feature improvements: * Compliles clean using GCC 9. Windows Delegate Updates/Additions: * bzlib: bzip is updated to 1.0.8 release. * jbig: jbigkit is updated to 2.1 release. * lcms: lcms2 is updated to 2.9 release. * libxml: libxml2 is updated to 2.9.10 release. * png: libpng is updated to 1.6.37 release. * tiff: libtiff is updated to 4.1.0 release. * webp: libwebp is updated to the 1.0.3 release. * zlib: zlib is updated to 1.2.11 release. * TIFF: Now also supports reading JBIG-compressed TIFF, and reading/writing WebP-compressed TIFF. A number of libtiff feature options which are now commonly enabled were disabled and are now enabled by default. Build Changes: * MinGW: Static and shared library builds were not working. Only the modules build was actually working! * Python scripts related to the build (enabled by --enable-maintainer-mode) are now compatible with Python 3. * Now supports using Google gperftools tcmalloc library for the memory allocator. This improves performance for certain repetitive work-loads and heavily-threaded algorithms. * Configure now reports the status of zstd (FaceBook Zstandard) compression in its configuration summary. * TclMagick: Address many issues mentioned by SourceForge issue #420 "TclMagick issues and patch". Behavior Changes: * PNG: Post-processing to convert the image type in the PNG reader based on a specified magick prefix string is now disabled. This can (and should) be done after the image has been returned. * Trace Logging: The compiled-in logging default is always to stderr, which may be over-ridden using log.mgk as soon as it is loaded. * Windows Build: Search registry key HKEY_CURRENT_USER as well as HKEY_LOCAL_MACHINE when searching for Ghostscript. By following the procedure documented in SourceForge bug 615 "GhostScript installation check", this allows for local user installations without "administrator" privileges.
2019-08-11Bump PKGREVISIONs for perl 5.30.0wiz1-1/+2
2019-08-08{p5-}GraphicsMagick: Update to 1.3.33nia1-2/+1
1.3.33 (July 20, 2019) ========================== Special Issues: * It has been discovered that the 'ICU' library (a perhaps 30MB C++ library) which is now often a libxml2 dependendency causes huge process initialization overhead. This is noticed as unexpected slowness when GraphicsMagick utilities are used to process small to medium sized files. The time to initialize is often longer than the time to read the input file, process the image, and write the output file. If the 'ICU' dependency can not be avoided, then make sure to use the modules build. Please lobby the 'ICU' library developers to change their implementation to avoid long start-up times due to merely linking with the library. Security Fixes: * GraphicsMagick is now participating in Google's oss-fuzz project due to the contributions and assistance of Alex Gaynor. Since February 4 2018, 353 issues have been opened by oss-fuzz and 338 of those issues have been resolved. The issues list is available at https://bugs.chromium.org/p/oss-fuzz/issues/list under search term "graphicsmagick". Issues are available for anyone to view and duplicate if they have been in "Verified" status for 30 days, or if they have been in "New" status for 90 days. There are too many fixes to list here. Please consult the GraphicsMagick ChangeLog file, Mercurial repository commit log, and the oss-fuzz issues list for details. * Documentation has been added regarding security hazards due to commands which support a '@filename' syntax. * MontageImages(): Fix wrong length argument to strlcat() when building montage directory, which could allow heap overwrite. Bug fixes: * PNG: Pass correct size value to strlcat() in module registration code. This bug is noticed to cause problems for Apple's OS X and Linux Alpine with musl libc. This fixes a regression introduced by the 1.3.32 release. * Re-implement command-line utility `'@'` file inclusion support for `-comment`, `-draw`, `-format`, and `-label` which was removed for the 1.3.32 release. The new implementation is isolated to command-line utility implementation code rather than being deeply embedded in the library and exposed in other usage contexts. This fixes a regression introduced by the 1.3.32 release. * CAPTION: The The CAPTION reader did not appear to work at all any more. Now it works again, but still not very well. * MagickXDisplayImage(): Fix heap overwrite of windows->image.name and windows->image.icon_name buffers. This bug has surely existed since early GraphicsMagick releases. * MagickXAnimateImages(): Fix memory leak of scene_info.pixels. * AcquireTemporaryFileDescriptor(): Fix compilation under Cygwin. This fixes a regression introduced by the 1.3.32 release. * PNG: Fix saving to palette when mage has an alpha channel but no color is marked as transparent. * Compilation warnings in the Visual Studio WIN64 build due to the 'long' type being only 32-bits have been addressed. New Features: * None API Updates: * None Feature improvements: * None Windows Delegate Updates/Additions: * None Build Changes: * None Behavior Changes: * Support for `'@'` file inclusion support for `-comment`, `-draw`, `-format`, and `-label` has been restored.
2019-07-21*: recursive bump for gdk-pixbuf2-2.38.1wiz1-2/+2
2019-07-20*: recursive bump for nettle 3.5.1wiz1-2/+2
2019-07-16GraphicsMagick: Disable jp2 support by defaultnia1-1/+2
Re-enable it with the 'jasper' option. Part of the process of trying to minimize the potential impact of a vulnerable jasper. Bump PKGREVISION
2019-06-18{p5-}GraphicsMagick: updated to 1.3.32adam1-2/+1
1.3.32: Special Issues: It has been discovered that the 'ICU' library (a perhaps 30MB C++ library) which is now often a libxml2 dependendency causes huge process initialization overhead. This is noticed as unexpected slowness when GraphicsMagick utilities are used to process small to medium sized files. The time to initialize is often longer than the time to read the input file, process the image, and write the output file. If the 'ICU' dependency can not be avoided, then make sure to use the modules build. Please lobby the 'ICU' library developers to change their implementation to avoid long start-up times due to merely linking with the library. Security Fixes: GraphicsMagick is now participating in Google's oss-fuzz project due to the contributions and assistance of Alex Gaynor. Since February 4 2018, 343 issues have been opened by oss-fuzz and 331 of those issues have been resolved. The issues list is available at https://bugs.chromium.org/p/oss-fuzz/issues/list under search term "graphicsmagick". Issues are available for anyone to view and duplicate if they have been in "Verified" status for 30 days, or if they have been in "New" status for 90 days. There are too many fixes to list here. Please consult the GraphicsMagick ChangeLog file, Mercurial repository commit log, and the oss-fuzz issues list for details. BMP reader: Fix heap overflow in 32-bit build due to arithmetic overflow. Only happens if limits are changed from defaults. BMP reader/writer: Improve buffer-size calculations to guard against buffer overflows. DIB reader: Reject files which claim more than 8-bits per pixel but also claim to be colormapped. DIB reader/writer: Improve buffer-size calculations to guard against buffer overflows. MIFF reader: Detect end of file while reading RLE packets. MIFF reader: Fix heap overflow (for some files using RLE compression) caused by a typo in the code. MAT writer: Added missing error handling to avoid heap overflow. MNG reader: Fixed a small heap buffer overflow. SVG reader: Fixed a stack buffer overflow. TGA writer: Fix heap overflow when image rows/columns are larger than 65535. TIFF reader: Rationalize tile width/height to reject large tile sizes which are much larger than the image dimensions. TIFF reader: Apply memory resource limits to strip and tile allocations. WMF reader: Fixed a division by zero problem. XWD reader: Many heap buffer overflows and uses of uninitialized data were fixed. Pixel cache: Now apply resource limits to pixel nexus allocations using the same limits (total pixels, width, height, memory) as applied to the whole image since some requests are directly influenced by the input file. More tests are added for arithmetic overflow. Care was taken to minimize performance impact due to the many extra checks. Bug fixes: See above note about oss-fuzz fixes. Fixed include order of magick/api.h vs wand/wand_symbols.h. WriteImage(): Eliminate use of just-freed memory in clone_info->magick when throwing exception due to no support for format. Magick++/lib/Magick++/Drawable.h: Fix use of clang diagnostic syntax. DIB: Preserve PseudoClass opaque representation if ICO mask is opaque. JPEG reader: Restore ability to access detailed image properties while in 'ping' mode. JPEG reader: Base test for "Unreasonable dimensions" on original JPEG dimensions and not the scaled dimensions. JPEG reader: Allow input files to have a compression ratio as high as 2500. Extremely compressed files were being rejected. FreeType renderer: Fixed a memory leak. PDF writer: Fixed a memory leak. PDF writer: Fixed a thread safety problem. PICT reader: Fix a thread safety problem. Exception reporting: Throwing an exception was not thread safe. Now it is. Exception reporting: Handle the case where some passed character strings refer to existing exception character strings. Command-line parser now does not attempt to read a list of filenames from a file in '@name' syntax if the path '@name' exists. Previously it would attempt to read a list of file names from 'name' even if '@name' did exist. Rendering: Short-circuit path parsing and return and error immediately if an error occurs. New Features: Added support for writing the Braille image format (by Samuel Thibault). WebP writer: Support WebP 'use_sharp_yuv' option ("if needed, use sharp (and slow) RGB->YUV conversion") via -define webp:use-sharp-yuv=true. The version command output now reports the OpenMP specification number rather than just the integer version identifier. API Updates: ReallocateImageColormap() added to re-allocate an existing colormap. Some improperly-exposed globals are now static as they should have been.
2019-04-01Fix build of GraphicsMagick with ghostscript disabledabs1-2/+2
(No change to default build)
2019-03-18Recursive bump for ghostscript default changegdt1-1/+2
2018-11-22GraphicsMagick: commit missing patch, fix buildlink.mkadam1-3/+1
2018-11-22Build fix for GraphicsMagick 1.3.31 updateprlw11-1/+3
[It is worth building packages with PKG_DEVELOPER=yes set before committing updates.] GraphicsMagick 1.3.31 added PKG_CONFIG, PKG_CONFIG_PATH, and presumably PKG_CONFIG_LIBDIR to its build system, which then appear in the output of "gm version". Ignore the WRKDIR which appears listed there.
2018-11-20GraphicsMagick: updated to 1.3.31adam1-2/+4
1.3.31: Special Issues: Firmware and operating system updates to address the Spectre vulnerability (and possibly to some extent the Meltdown vulnerability) have substantially penalized GraphicsMagick's OpenMP performance. Performance is reduced even with GCC 7 and 8's improved optimizers. There does not appear to be anything we can do about this. Security Fixes: GraphicsMagick is now participating in Google's oss-fuzz project due to the contributions and assistance of Alex Gaynor. Since February 4 2018, 292 issues have been opened by oss-fuzz and 279 of those issues have been resolved. The issues list is available at https://bugs.chromium.org/p/oss-fuzz/issues/list under search term "graphicsmagick". Issues are available for anyone to view and duplicate if they have been in "Verified" status for 30 days, or if they have been in "New" status for 90 days. There are too many fixes to list here. Please consult the GraphicsMagick ChangeLog file, Mercurial repository commit log, and the oss-fuzz issues list for details. Bug fixes: See above note about oss-fuzz fixes. CINEON: Fix unexpected hang on a crafted Cineon image. SourceForge issue 571. Drawing recursion is limited to 100 and may be tuned via the MAX_DRAWIMAGE_RECURSION pre-processor definition. Fix reading MIFF files using legacy keyword 'color-profile' for ICC color profile as was used by ImageMagick 4.2.9. Fix reading/writing files when 'magick' is specified in lower case. This bug was a regression in 1.3.30. New Features: TIFF: Support Zstd compression in TIFF. This requires libtiff 4.0.10 or later. TIFF: Support WebP compression in TIFF. This requires libtiff 4.0.10 or later. API Updates: MagickMonitor() is marked as deprecated. Code should not be using this function any more. Feature improvements: The progress monitor callbacks (registered using MagickMonitor() or MagickMonitorFormatted()) are serialized via a common semaphore rather than via critical sections in OpenMP loops. OpenMP loops are updated to use OpenMP 'atomic' and 'flush' to update shared loop variables rather than using a OpenMP 'critical' construct, reducing contention. Performance on some targets is observed to have been improved by this change. Build Changes: There was already a 'compare' command installed with the '--enable-magick-compat' configure option was used but it did not function. Now it functions. There was no compare command in ImageMagick 5.5.2 and this compare command is only roughly similar to a compare command in some subsequent ImageMagick release. Removed Remove Ghostscript library support (--with-gslib) from configure script. The 'HasGS' pre-processor defines which were enabled by this remain in the source code so it is still possible to use this library if absolutely necessary (e.g. CPPFLAGS=-DHasGS LIBS=-lgs). No longer explicitly link with the OpenMP library when it will be supplied already due to CFLAGS. Behavior Changes: JPEG: Libjpeg-turbo is allowed 1/5th the memory resource limit provided for Graphicsmagick via the cinfo->mem->max_memory_to_use option, which is part of the IJG JPEG API/ABI, but usually not supported there. This feature works for libjpeg-turbo 1.5.2 and later. Limiting the memory usage is useful since libjpeg-turbo may otherwise consume arbitrary amounts of memory even before Graphicsmagick is informed of the image dimensions. JPEG: The maximum number of JPEG progressive scans is limited to 50. Otherwise some technically valid files could be read for almost forever.
2018-11-14Revbump after cairo 1.16.0 update.kleink1-2/+2
2018-11-12Recursive revbump from hardbuzz-2.1.1ryoon1-2/+2
2018-08-22Recursive bump for perl5-5.28.0wiz1-1/+2
2018-05-06GraphicsMagick: updated to 1.3.29adam1-2/+1
1.3.29: Security Fixes: GraphicsMagick is now participating in Google's oss-fuzz project due to the contributions and assistance of Alex Gaynor. Since February 4 2018, 180 issues have been opened by oss-fuzz and 173 of those issues have been resolved. The issues list is available at https://bugs.chromium.org/p/oss-fuzz/issues/list under search term "graphicsmagick". Issues are available for anyone to view and duplicate if they have been in "Verified" status for 30 days, or if they have been in "New" status for 90 days. There are too many fixes to list here. Please consult the GraphicsMagick ChangeLog file, Mercurial repository commit log, and the oss-fuzz issues list for details. JNG: Require that the embedded JPEG image have the same dimensions as the JNG image as provided by JHDR. Avoids a heap write overflow. MNG: Arbitrarily limit the number of loops which may be requested by the MNG LOOP chunk to 512 loops, and provide the '-define mng:maximum-loops=value' option in case the user wants to change the limit. This fixes a denial of service caused by large LOOP specifications. Bug fixes: Many oss-fuzz fixes are bug fixes. DICOM: Pre/post rescale functions are temporarily disabled (until the implementation is fixed). JPEG: Fix regression in last release in which reading some JPEG files produces the error "Improper call to JPEG library in state 201". ICON: Some DIB-based Windows ICON files were reported as corrupt to an unexpectedly missing opacity mask image. In-memory Blob I/O: Don't implicitly increase the allocation size due to seek offsets. MNG: Detect and handle failure to allocate global PLTE. Fix divide by zero. DrawGetStrokeDashArray(): Check for failure to allocate memory. BlobToImage(): Now produces useful exception reports to cover the cases where 'magick' was not set and the file format could not be deduced from its header. API Updates: Wand API: Added MagickIsPaletteImage(), MagickIsOpaqueImage(), MagickIsMonochromeImage(), MagickIsGrayImage(), MagickHasColormap() based on contributions by Troy Patteson. New structure ImageExtra added and Image 'clip_mask' member is replaced by 'extra' which points to private ImageExtra allocation. The ImageGetClipMask() function now provides access to the clip mask image. New structure DrawInfoExtra and DrawInfo 'clip_path' is replaced by 'extra' which points to private DrawInfoExtra allocation. The DrawInfoGetClipPath() function now provides access to the clip path. New core library functions: GetImageCompositeMask(), CompositeMaskImage(), CompositePathImage(), SetImageCompositeMask(), ImageGetClipMask(), ImageGetCompositeMask(), DrawInfoGetClipPath(), DrawInfoGetCompositePath() Deprecated core library functions: RegisterStaticModules(), UnregisterStaticModules(). Feature improvements: Static modules (in static library or shared library without dynamically loadable modules) are now lazy-loaded using the same external interface as the lazy-loader for dynamic modules. This results in more similarity between the builds and reduces the fixed initialization overhead by only initializing the modules which are used. SVG: The quality of SVG support has been significantly improved due to the efforts of Greg Wolfe. FreeType/TTF rendering: Rendering fixes for opacity.
2018-04-17Add p11-kit to gnutls/bl3.mk and bump dependencies.wiz1-2/+2
2018-04-16Recursive bump for new fribidi dependency in pango.wiz1-2/+2
2018-03-12Recursive bumps for fontconfig and libzip dependency changes.wiz1-2/+2
2018-01-28Bump PKGREVISION for gdbm shlib major bumpwiz1-1/+2
2017-12-19GraphicsMagick: updated to 1.3.27aadam1-3/+2
1.3.27: Security Fixes: * CMYK: Fix heap overwrites in raw CMYK writer. Fix heap overwrites in raw CMYK reader (noticed when doing montage). * GIF: Assure that global colormap is initialized. * DescribeImage(): Fix possible heap write overflow when describing visual image directory. Fix possible heap read overflow while accessing heap data, and possible information disclosure while describing the IPTC profile. * DICOM: Fix huge memory allocation based on bogus length value (DOS opportunity). * DrawDashPolygon(): Fix heap out of bounds read in render code. * GRAY: Fix heap overwrites in raw GRAY reader (noticed when doing montage). * JNG: Fix heap overruns. Fix assertions. * JNG: Prevent a crash due to zero-length color_image while reading a JNG image. (CVE-2017-11102). Reject JNG files with unreasonable dimensions given the file size (avoid DOS). * JNX: Fix DOS due to excessive memory allocations with corrupt file. * JPEG: Do not allocate backing image pixels until a scanline has been successfully read. Avoids DOS opportunity with suitably manufactured file. * MAP: Fix null pointer dereference or segmentation violation. * MAT: Fix heap write overflow. * MNG: Reject over-large (65k by 65k) image. Fix heap overwrites. * PAM: Fix heap buffer overflow in PAM writer for 1 bit/sample + alpha. * PICT: Fix excessive memory allocation due to malformed image file. * PNG: Fix heap buffer overflow in PNG writer when promoting from indexed PNG to RGBA. * PNM: Fix DOS due to excessive memory allocations with corrupt file. * RGB: Fix heap overwrite in raw RGB writer. Fix heap overwrites in raw RGB reader (noticed when doing montage). * RLE: Fix DOS opportunities due to false claims in image header. Fix heap out of bounds read. * SFW: Avoid possible heap write overflow. * SUN: Fix heap read overflow. Fix DOS due to excessive memory allocations with corrupt file. * SVG: Fix heap write overflow. * TIFF: Use heuristics to avoid DOS (excessive memory use) due to false claims by input file. It is possible that this may reject some valid files. Fix possible small heap overwrite beyond the allocated scanline buffer due to the NumberOfObjectsInArray() macro rounding up rather than down. * UIL: Fix heap overwrite in writer. * WPG: Fix DOS issues (memory, disk space, CPU time) due to insufficient validations. Fix heap overwrites. * XBM: Fix DOS issue where code remains stuck in loop and does not return. * XV 332 (PNM): Fix null pointer dereference due to malformed file. * TracePSClippingPath()/TraceSVGClippingPath(): Fix heap out of bounds read. * Validate path entries in the MAGICK_CODER_MODULE_PATH and MAGICK_FILTER_MODULE_PATH environment variables and convert all paths to real paths if possible. This avoids possible use of relative paths to load modules (a possible security issue), or the possibility of adding a directory which was in the path, but missing, and may improve efficiency by removing non-existent paths. Bug fixes: * AVS: Memory leaks eliminated. * CINEON: Fix possible use of NULL pointer. * CMYK: Memory leaks eliminated. * CUT: Memory leaks eliminated. Fix possible use of NULL pointer. * DCM: Fix possible use of NULL pointer. * DrawImage(): Avoid "negative" strncpy(). This seems to be benign with glibc but perhaps not with other implementations. * DPX: Memory leaks eliminated. * EMF: Fix possible use of NULL pointer. * FindMagickModule(): Fix possible use of NULL pointer. * FITS: Fix memory leak. * GIF: Fix memory leak. * HDF: Memory leaks eliminated. * HISTOGRAM: Fix memory leak. * JNG: Memory leaks eliminated. Memory use after free and double-free issues eliminated. Error reporting fixes. * Magick::Options::strokeDashArray(): Fix possible use of NULL pointer. * MagickXFileBrowserWidget(): Fix possible use of NULL pointer. * MAT: Memory leaks eliminated. * MagickMapCloneMap(): Fix possible assertion failure. * MNG: Memory use after free issues eliminated. Fix possible use of NULL pointer. Fix memory leaks. * MontageImageCommand(): Fix memory leaks. * MPC: Fix memory leak in writer. * MPEG: Fix memory leaks in writer. * MTV: Memory leaks eliminated. * NTRegistryKeyLookup(): Fix possible use of NULL pointer. * NTGetTypeList(): Fix possible use of NULL pointer. * PCD: Memory leaks eliminated. * PCL: Fix null pointer dereference in PCL writer. * PCX: Memory leaks eliminated. * PALM: Fix possible use of NULL pointer. Fix memory leak. * PICT: Memory leaks eliminated. * PNG: Fix small (one-off) heap read overflow. * PNM: Fix memory leaks. * PS: Fix use of null pointer in error path. * PWP: Fix possible use of null pointer. * ReplaceImageColormap(): Throw an exception rather than assertion if the input image is not colormapped. * RGB: Fix memory leak. * SegmentImage(): Fix possible use of NULL pointer. * SetImageProfile(): Fix possible assertion failure. * SGI: Check for EOF while reading SGI file header. * SUN: Fix memory leak. * TIFF: Fix possible use of NULL pointer. Fix memory leaks in writer. * TIM: Fix memory leak. * TOPOL: Fix possible use of NULL pointer. Fix memory leaks. * VIFF: Fix memory leak. * WEBP: Detect partial write to output file. * WPG: Fix possible use of null pointer. Fix excessive use of disk resources due to insufficient validations. * WriteImage(): Restore use of GetBlobStatus() to test if an I/O error was encountered while writing output file. This assures that I/O failure in writers which do not themselves verify writes is assured to be reported. * WMF: Memory use after free issues eliminated. * YUV: Fix memory leaks. New Features: * PNG: Implemented eXIf chunk support. * WEBP: Add support for EXIF and ICC metadata provided that at least libwebp 0.5.0 is used. * Magick++ Image autoOrient(): New Image method to auto-orient an image so it looks right-side up by default. Windows Delegate Updates/Additions: * Libtiff is updated to libtiff 4.0.9. Build Changes: * JPEG/PNG: The SETJMP_IS_THREAD_SAFE definition is used to determine if setjmp/longjmp are thread safe. If these interfaces are thread safe, then concurrent reads/writes are possible. This definition is false for Solaris but true for Linux. JPEG and PNG will be fully concurrent if this definition is enabled. Behavior Changes: * PALM: PALM writer is disabled. * ThrowLoggedException(): Capture the first exception at ErrorException level or greater, or only capture exception if it is more severe than an already reported exception. * DestroyJNG(): This internal function is now declared static and is removed from shared library or DLL namespace.
2017-11-23recursive bump for libxkbcommon removal from at-spi2-corewiz1-1/+2
2017-07-091.3.26:adam1-2/+1
Security Fixes: --------------- DPX: Fix excessive use of memory (DOS issue) due to file header claiming large image dimensions but insufficient backing data. (CVE-2017-10799). JNG: Fix memory leak when reading invalid JNG image (CVE-2017-8350). MAT: Fix excessive use of memory (DOS issue) due to continuing processing with insufficient data and claimed large image size. Verify each file extent to make sure that it is within range of file size. (CVE-2017-10800). META: Fix heap overflow while parsing 8BIM chunk (CVE-2016-7800). PCX: Fix denial of service issue. RLE: Fix abnomally slow operation (denial of service issue) with intentionally corrupt colormapped file. PICT: Fix possible buffer overflow vulnerability given suitably truncated input file. PNG: Enforce spec requirement that the dimensions of the JPEG embedded in a JDAT chunk must match the JHDR dimensions (CVE-2016-9830). PNG: Avoid NULL dereference when MAGN chunk processing fails. SCT: Fix stack-buffer read overflow (underflow?) while reading SCT header. SGI: Fix denial of service issues. Delay large memory allocations until file header has fully passed sanity checks. TIFF: Fix out of bounds read when reading CMYKA TIFF which claims to have only 2 samples per pixel (CVE-2017-6335). TIFF: Fix out of bounds read when reading RGB TIFF which claims to have only 1 sample per pixel (CVE-2017-10794). WPG: Fix heap overflow (CVE-2016-7996). Fix assertion crash (CVE-2016-7997). Bug fixes: ---------- DifferenceImage(): Fix Fix all-black difference image if an input file is colormapped. EXIF orientation was not being properly detected for some files. -frame: The import command -frame handling was improperly implemented and was using already freed data. GIF: Fixes for "Excessive LZW string data" problem. Magick++: Bug fixes to PathSmoothCurvetoRel::operator() and PathSmoothCurvetoRel::operator(). PAM: Support writing GRAYSCALE PAM format. PNG: Fix memory leaks. SVG: Fixed a memory leak. Fixed a possible null pointer dereference. TclMagick: Problem that TkMagick could not resolve functions from TclMagick under Linux is fixed. TclMagick: Fix parser validatation in magickCmd() to avoid crash given a syntax error. TIFF: Fix for reading old JPEG files (avoids "Improper call to JPEG library in state 0. (LibJpeg)."). TXT: Fixed memory leak. XCF: Error checking is improved. New Features: ------------- EXIF rotation: Support is added such that the EXIF orientation tag is updated when the image is rotated. MAT: Now support reading multiple images from Matlab V4 format. Magick++: Orientation method now updates orientation in EXIF profile, if it exists. Magick++: Added Image attribute method which accepts a 'char *' argument, and will remove the attribute if the value argument is NULL. -orient: The -orient command line option now also updates the orientation in the EXIF profile, if it exists. PGX: Support PGX JPEG 2000 format for reading and writing (within the bounds of what JasPer supports). Wand API: Added MagickAutoOrientImage(), MagickGetImageOrientation(), MagickSetImageOrientation(), MagickRemoveImageOption(), and MagickClearException().
2017-03-09Make pkg-config a runtime dependency so GraphicsMagick*config work.jperkin1-3/+3
Bump PKGREVISION.
2017-02-28Recursive revbump from graphics/libwebpryoon1-1/+2
2016-09-07Updated GraphicsMagick to 1.3.25.wiz1-2/+1
1.3.25 (September 5, 2016) ========================== Special Issues: * None Security Fixes: * EscapeParenthesis(): I was notified by Gustavo Grieco of a heap overflow in EscapeParenthesis() used in the text annotation code. While not being able to reproduce the issue, the implementation of this function is completely redone. * Utah RLE: Reject truncated/absurd files which caused huge memory allocations and/or consumed huge CPU. Problem was reported by Agostino Sarubbo based on testing with AFL. * SVG/MVG: Fix another case of CVE-2016-2317 (heap buffer overflow) in the MVG rendering code (also impacts SVG). * TIFF: Fix heap buffer read overflow while copying sized TIFF attributes. Problem was reported by Agostino Sarubbo based on testing with AFL. Bug fixes: * GetToken(): Fix obscure bug (read beyond end of string buffer) noticed while parsing a MVG file. This problem was reported by Gustavo Grieco. * MVG rendering: Fix undesired hard errors when some objects were drawn outside of the image bounds. Requests to draw objects entirely outside of the image should be silently ignored. * MVG/SVG rendering: Fix gradient size sanity checks which were causing gradient requests to fail. Due to a design weakness in that gradient images allocate resources rather than being computations at point of use, the maximum gradient image size is now hard-limited to 5000x5000 pixels until the design problem is fixed. Some SVG icons (as small as 8x8 pixels) authored using Inkscape request absurdly huge gradients. Gradient sizes as large as 20,000x20,000 have been observed in SVG icon files delivered by packages on an Ubuntu Linux system. * SVG: Fix some memory leaks which occur on parsing error. New Features: * None Feature improvements: * ElapsedTime(): Use clock_gettime() (when available with default linkage) to obtain elapsed time. * DescribeImage(): Provide 6 digits of seconds precision in in elapsed time output. Previously the resolution was rounded up to a full second. Windows Delegate Updates/Additions: * webp: Updated bundled libwebp to release 0.5.1. * libxml: Updated bundled libxml2 to release 2.9.4. * lcms: Updated bundled lcms2 to release 2.8. * png: Update bundled libpng to release 1.6.24. Build Changes: * OpenMP is properly configured for clang 3.8 using its own '-lomp' rather than '-lgomp'. Behavior Changes: * SVG: Some SVG files may be rejected due to absurdly large gradient requests. * The 'identify' and 'info' functionality only shows the pixel read rate if image was not read in 'ping' mode. Provide 6 digits of seconds precision in in elapsed time output.
2016-07-09Bump PKGREVISION for perl-5.24.0 for everything mentioning perl.wiz1-1/+2
2016-06-06Updated GraphicsMagick to 1.3.24.wiz1-2/+1
1.3.24 (May 30, 2016) ========================== .. _`GCC bug 53967` : http://gcc.gnu.org/bugzilla/show_bug.cgi?id=53967 Special Issues: * A shell exploit (CVE-2016-5118) was discovered associated with a filename syntax where file names starting with '|' are intepreted as shell commands executed via popen(). Insufficient sanitization in the SVG and MVG renderers allows such filenames to be passed through from potentially untrusted files. There might be other ways for untrusted inputs to produce such filenames. Due to this issue, support for the feature is removed entirely. * A shell exploit was discovered associated with the gnuplot delegate and which is triggered by the 'gplt' entry in delegates.mgk. A remote exploit is possible if the attacker can cause a provided SVG or MVG file to be rendered (or the user opens a provided file). The gnuplot program must be installed in order for the exploit to be successful. It is strongly recommended to remove this entry in all delegates.mgk files. * Due to `GCC bug 53967`_, several key agorithms (e.g. convolution) may execute much faster (e.g. 2-3X) for x86-64 and/or when SSE is enabled for floating point math (`-mfpmath=sse`) if the GCC option `-frename-registers` is used. Default 32-bit builds do not experience the problem since they use '387 math. It is not clear in what version of GCC this problem started but it was not noticed by the developers until the GCC 4.6 timeframe. Other compilers do not suffer from this bug. Please lobby the GCC project to fix this embarrassing performance bug. Security Fixes: * BLOB: Remove support for reading input from a shell command, or writing output to a shell command, by prefixing the specified filename (containing the command) with a '|'. This feature provided a remote shell execution opportunity. * DIB: Fixed out of bounds reads. Added more header validations. * JNG: File size limits are enforced. * MAT: Fixed denial of service opportunity. Fix hang on corrupt deflate stream. * META: Fixed out of bounds reads and writes. * MIFF: Fixed thrown assertion. * MSL: Ignore the file extension on MSL files. It is necessary to add a "msl:" prefix to MSL files to read the as an image. * MVG: No longer assume that files ending with extension ".mvg" are MVG files. MVG parsing does more validity checking on its input. Assure that enough PrimitiveInfo structures are allocated in advance to support a given vector path (heap overflow problem). * PCX: Fixed unreasonable memory allocation due to intentionally corrupt file. * PDB: Fixed a heap buffer overflow and out of bounds read. * PICT: Fixed an out of bounds write. * PS: Ghostscript is now always run with -dSAFER for safer execution. * PSD: Fixed segmentation violations, heap buffer overflows, and out of bounds writes. * RLE: Fixed out of bounds reads and writes. * ReadImages(): Fixed a possible infinite recursion due to a crafted input file. * RotateImage(): Fixed thrown assertion. * SGI: Fixed out of bounds writes. * SUN: Fixed out of bounds reads and writes. * SVG: Fixed heap and stack buffer overflows, as well as segmentation violations (CVE-2016-2317 and CVE-2016-2318). Also fixed endless loop, unexpectedly large memory allocation, divide by zero, and recursion issues. * TIFF: Fixed an assertion while reading. Fixed benign heap overflow. * TMP: Adding a "tmp:" prefix to a filename no longer removes the file since this seems dangerous. * VIFF: Fix excessive memory allocation with intentionally corrupted input file. * XCF: Fixed a heap buffer overflow. * XPM: Fixed several heap buffer overflows, and out of bound reads/writes. Also fixed a case of excessive memory allocation. * delegate.mgk: The default delegate.mgk file has been pared down in order to reduce security exposure. * gnuplot ('gplt' delegate in delegates.mgk): Support for rendering gnuplot files is removed since the format is inherently insecure. * File names: File names starting with a '|' character are no longer interpreted as shell commands to be executed as input or output. Bug fixes: * BMP: Fix reading 24-bit Microsoft BMP which claims to have a colormap. * FILE: `file://` URLs are properly supported now (they never worked before). * JP2: It is now possible to write lossless JPEG 2000 "JP2" format. * SVG: Support font-size "medium". New Features: * Blob I/O C APIs: Added signed versions of short and long Read/Write functions. * FILE: `file://` URLs are properly supported now (they never worked before). * MAT: Matlab V4 is now partially supported. * Magick++: Added double-precision xResolution() and yResolution() methods to support setting the horizontal and vertical resolution with double floating point precision. * Mogrify now supports a -preserve-timestamp option to preserve file access and modification timestamps. Feature improvements: Windows Delegate Updates/Additions: * Updated bundled libpng to release 1.6.19. * Updated bundled libwebp to release 0.4.4. * Update bundled libxml2 to release 2.9.3. * Update bundled freetype to release 2.6.2. Build Changes: * Added ``--enable-broken-coders`` configure option to enable file format support which may be broken or cause security issues. The PSD format is now classified as "broken" (until it is fixed). Behavior Changes: * PSD format is not included in the build by default. * Files ending with ".mvg" and ".msl" are not assumed to be image files by default. * File names starting with '|' are no longer treated as shell commands. * Gnuplot and POV delegate support is removed from the default delegate.mgk file.