You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ghostscript 10.xxx无法使用toolbin辅助/序言文件问题

Ghostscript执行PostScript脚本时权限拒绝问题解决

执行./gs/lib或./gs/toolbin下的pdf_info.ps、extractICCProfiles.ps等辅助脚本时,反复出现权限拒绝错误,即使添加-dNOSAVER参数也无法解决,错误提示包含/invalidfileaccess和Last OS error: Permission denied。

操作示例

示例1:

gs -q -dNODISPLAY extractICCprofiles.ps -c "(ICC_) (test.pdf) extractICCprofiles quit"

错误输出:

Error: /invalidfileaccess in --file--
Operand stack:
   (test.pdf)   (r)
Execution stack:
   %interp_exit   .runexec2   --nostringval--   --nostringval--   --nostringval--   2   %stopped_push   --nostringval--   --nostringval--   --nostringval--   false   1   %stopped_push   .runexec2   --nostringval--   --nostringval--   --nostringval--   2   %stopped_push   --nostringval--   --nostringval--
Dictionary stack:
   --dict:770/1123(ro)(G)--   --dict:0/20(G)--   --dict:81/200(L)--
Current allocation mode is local
Last OS error: Permission denied

示例2:

gs -q -dNOSAVER -dNODISPLAY extractICCprofiles.ps -c "(ICC_) (test.pdf) extractICCprofiles quit"

错误输出:

Error: /invalidfileaccess in --file--
Operand stack:
   (test.pdf)   (r)
Execution stack:
   %interp_exit   .runexec2   --nostringval--   --nostringval--   --nostringval--   2   %stopped_push   --nostringval--   --nostringval--   --nostringval--   false   1   %stopped_push   .runexec2   --nostringval--   --nostringval--   --nostringval--   2   %stopped_push   --nostringval--   --nostringval--
Dictionary stack:
   --dict:771/1123(ro)(G)--   --dict:0/20(G)--   --dict:81/200(L)--
Current allocation mode is local
Last OS error: Permission denied
GPL Ghostscript 10.01.2: Unrecoverable error, exit code 1

问题原因

从Ghostscript 9.50版本开始,默认启用了严格的安全沙箱机制(-dSAFER),阻止PostScript脚本访问文件系统,这是导致/invalidfileaccess错误的核心原因。你使用的-dNOSAVER是无效参数,正确的禁用安全沙箱参数是-dNOSAFER。

解决方法

  1. 禁用安全沙箱(快速解决)
    使用-dNOSAFER参数替代-dNOSAVER,修改命令如下:

    gs -q -dNOSAFER -dNODISPLAY extractICCprofiles.ps -c "(ICC_) (test.pdf) extractICCprofiles quit"
    

    注:该参数会完全关闭Ghostscript的安全限制,仅在可信脚本和文件环境下使用。

  2. 精细控制文件访问(更安全)
    如果不想完全关闭安全机制,可以通过-dISEDITPATH指定允许访问的目录,结合-dSAFER使用:

    gs -q -dSAFER -dISEDITPATH=$(pwd) -dNODISPLAY extractICCprofiles.ps -c "(ICC_) (test.pdf) extractICCprofiles quit"
    

    这里$(pwd)表示允许访问当前工作目录,你可以替换为test.pdf所在的具体路径。

  3. 检查文件系统权限
    确保运行Ghostscript的用户对test.pdf、extractICCprofiles.ps以及相关目录拥有读取权限,可通过ls -l查看权限,使用chmod调整权限(如chmod +r test.pdf)。

内容的提问来源于stack exchange,提问作者Alex

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 03:11:15