Lilypond security

From: John Williams
Subject: Lilypond security
Date: Tue, 2 Dec 2003 11:44:21 -0700 (MST)

I was wondering if anyone knows how secure lilypond is?

For example, if I download a .ly file from somewhere,
has any effort been made to prevent that file from
doing something bad to my system?  For example,
executing arbitrary scheme code which will erase my

Lilypond has ways to reach down into the scheme, TeX,
or postscript levels.  Ghostscript has the -dSAFER option
to prevent most exploits.  I doubt TeX can do anything bad.
But the scheme level makes me very uneasy.

~ John Williams

