# Perhaps your startup script should ban connections from 19.5.2 clients

**URL:** <https://the.fmsoup.org/t/perhaps-your-startup-script-should-ban-connections-from-19-5-2-clients/3088>\
**Category:** Heads-Up!\
**Tags:** bug\
**Created:** [September 13, 2022, 7:21pm UTC](https://the.fmsoup.org/t/perhaps-your-startup-script-should-ban-connections-from-19-5-2-clients/3088 "2022-09-13T19:21:41Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bobino](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/bobino/32/194_2.png) [@Bobino](https://the.fmsoup.org/u/Bobino)\
**Post date:** [September 13, 2022, 7:21pm UTC](https://the.fmsoup.org/t/perhaps-your-startup-script-should-ban-connections-from-19-5-2-clients/3088/1 "2022-09-13T19:21:41Z")

</div>

This is something to be aware of. Yes, making sure workstations upgrade to 19.5.3 is part of the fix, but perhaps connections with 19.5.2 should be terminated upon login.

> **[Fixing the "Convert this Database" Bug](https://www.soliantconsulting.com/blog/filemaker-convert-this-database-bug/)**
>
> FileMaker 19.5.2 introduced a bug that can prevent you from opening your FileMaker solution. Learn more about the bug and how to fix it.

---

<div class="post-metadata">

**Author:** ![FileKraft](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/filekraft/32/1183_2.png) [@FileKraft](https://the.fmsoup.org/u/FileKraft)\
**Post date:** [September 14, 2022, 3:15pm UTC](https://the.fmsoup.org/t/perhaps-your-startup-script-should-ban-connections-from-19-5-2-clients/3088/2 "2022-09-14T15:15:52Z")

</div>

that's not a fix it is a disaster telling to use a hex editor on a file!

---

<div class="post-metadata">

**Author:** ![Bobino](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/bobino/32/194_2.png) [@Bobino](https://the.fmsoup.org/u/Bobino)\
**Post date:** [September 14, 2022, 3:21pm UTC](https://the.fmsoup.org/t/perhaps-your-startup-script-should-ban-connections-from-19-5-2-clients/3088/3 "2022-09-14T15:21:35Z")

</div>

I think someone who ends up being unable to open the file will implement just about anything to gain back access to a file. There is a likeliness that sending the file to Claris for repair results in something similar.

All in all, this bug is a bad one, and avoiding it in the first place sounds like the best "remedy" to me (I know typically a remedy is something you take after the fact, but I am simply saying that no remedy beats prevention). This is why I suggest testing for that version in a file startup script and close the file down when the version being used is the one that is prone to this bug.

---

<div class="post-metadata">

**Author:** ![FileKraft](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/filekraft/32/1183_2.png) [@FileKraft](https://the.fmsoup.org/u/FileKraft)\
**Post date:** [September 14, 2022, 3:30pm UTC](https://the.fmsoup.org/t/perhaps-your-startup-script-should-ban-connections-from-19-5-2-clients/3088/4 "2022-09-14T15:30:40Z")

</div>

[https://community.claris.com/en/s/question/0D53w00005oUqh3CAC/filemaker-server-started-corrupting-nightly-backups-about-a-week-ago-when-server-restarted-it-corrupted-main-working-file-this-is-critical-for-the-busy-help-please?t=1663169070229](https://community.claris.com/en/s/question/0D53w00005oUqh3CAC/filemaker-server-started-corrupting-nightly-backups-about-a-week-ago-when-server-restarted-it-corrupted-main-working-file-this-is-critical-for-the-busy-help-please?t=1663169070229)

---

<div class="post-metadata">

**Author:** ![Bobino](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/bobino/32/194_2.png) [@Bobino](https://the.fmsoup.org/u/Bobino)\
**Post date:** [September 14, 2022, 3:36pm UTC](https://the.fmsoup.org/t/perhaps-your-startup-script-should-ban-connections-from-19-5-2-clients/3088/5 "2022-09-14T15:36:18Z")

</div>

Also related is this other community post: [Claris Community (English)](https://community.claris.com/en/s/question/0D53w00005oT2yiCAC/i-updated-to-1952201-and-now-when-i-try-to-open-files-i-keep-getting-request-to-convert-the-file-to-fmp12-and-they-are-all-fmp12-only-happened-since-upgrading)

---

<div class="post-metadata">

**Author:** ![Malcolm](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/malcolm/32/196_2.png) [@Malcolm](https://the.fmsoup.org/u/Malcolm)\
**Post date:** [September 14, 2022, 6:57pm UTC](https://the.fmsoup.org/t/perhaps-your-startup-script-should-ban-connections-from-19-5-2-clients/3088/6 "2022-09-14T18:57:17Z")

</div>

I know what you mean - but the fix is available and it works.

---

<div class="post-metadata">

**Author:** ![Bobino](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/bobino/32/194_2.png) [@Bobino](https://the.fmsoup.org/u/Bobino)\
**Post date:** [September 14, 2022, 7:03pm UTC](https://the.fmsoup.org/t/perhaps-your-startup-script-should-ban-connections-from-19-5-2-clients/3088/7 "2022-09-14T19:03:46Z")

</div>

It works if your file does not have Encryption at Rest enabled. This is really the kind of glitch we should make some effort to avoid. Cost of prevention is negligible, the cost if the file cannot be open is on a totally different scale.

---

<div class="post-metadata">

**Author:** ![tonywhitelive](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/tonywhitelive/32/208_2.png) [@tonywhitelive](https://the.fmsoup.org/u/tonywhitelive)\
**Post date:** [September 16, 2022, 4:04pm UTC](https://the.fmsoup.org/t/perhaps-your-startup-script-should-ban-connections-from-19-5-2-clients/3088/8 "2022-09-16T16:04:07Z")

</div>

Yes, it is best practice to validate the client configuration that is trying to open a FileMaker system and either:

- quit the system (and create a help request) or
- create a help request to upgrade the installation on a non-emergency basis.

The functions that might be used include...

1. Get ( Device )
2. Get ( SystemPlatform )
3. Get ( SystemVersion )
4. Get ( ApplicationVersion )
5. Get ( ApplicationArchitecture )

...with Get ( SystemPlatform ) and Get ( ApplicationVersion ) likely to be the most useful.

![image](https://canada1.discourse-cdn.com/flex030/uploads/fmsoup/original/2X/c/c0c53067135bfdd650fbb4b15ad9e45cb3ba17c5.png)

Get ( EncryptionState ) could also added to note the level of risk.

A script that...

1. is called on system/file opening
2. branches using the functions above
3. filters against white lists of tested configurations

...would add an additional measure of protection and also buy time to address in other ways.

There are lots of types of customers and lots of FM system architectures. And there are other things that can be done to protect against this issue.

Happy to hear other thoughts on how to address this challenge.

---

<div class="post-metadata">

**Author:** ![JasonMark](https://avatars.discourse-cdn.com/v4/letter/j/a9adbd/32.png) [@JasonMark](https://the.fmsoup.org/u/JasonMark)\
**Post date:** [September 19, 2022, 8:13pm UTC](https://the.fmsoup.org/t/perhaps-your-startup-script-should-ban-connections-from-19-5-2-clients/3088/9 "2022-09-19T20:13:54Z")

</div>

Thank you for sharing this. I just implemented in all my solutions a test on startup so anyone using 19.5.2 loses access to the "File" menu and gets an alert to update. That should be safe, right? I just want to make sure I'm not missing any other minor details of this

---

<div class="post-metadata">

**Author:** ![Bobino](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/bobino/32/194_2.png) [@Bobino](https://the.fmsoup.org/u/Bobino)\
**Post date:** [September 19, 2022, 8:23pm UTC](https://the.fmsoup.org/t/perhaps-your-startup-script-should-ban-connections-from-19-5-2-clients/3088/10 "2022-09-19T20:23:04Z")

</div>

I would favor changing the file options to make the minimum version 19.5.3. If I cannot do that because version of 19.5.1 or prior need to connect, I would test for the version 19.5.2 specifically and close the file down (after showing a custom dialog), without attempting to leave the user in, but having to manage access to menu or script commands that prompt open the same dialog. It may be draconian, but I prefer to be on the safe side. I could explain myself easily with anyone who would feel like this measure generates too much discomfort.

If anyone wants to keep using 19.5.2 after being advised of the possible repercussions, I would ask the customer to sign a release form to the effect they were informed about the problem this could lead to, but chose to disregard their vendor's recommendation in this matter.

19.5.2 is simply not a configuration I want to support. I do not feel like the risk is worth it.

---

<div class="post-metadata">

**Author:** ![tonywhitelive](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/tonywhitelive/32/208_2.png) [@tonywhitelive](https://the.fmsoup.org/u/tonywhitelive)\
**Post date:** [September 19, 2022, 10:31pm UTC](https://the.fmsoup.org/t/perhaps-your-startup-script-should-ban-connections-from-19-5-2-clients/3088/11 "2022-09-19T22:31:06Z")

</div>

- validate the client configuration on FM System Open
- proof of concept...validate versions that might be [A] higher and have issues or [B] older and not have features that are used, etc.
- \*\*\* more that one way to write the code to achieve the goals. See below (simple version using illogical appVersion sample data and template code).

 ![image](https://canada1.discourse-cdn.com/flex030/uploads/fmsoup/original/2X/7/76da6e18f4b3f06e44d7fe78bee3e398de229588.png)

---

<div class="post-metadata">

**Author:** ![Bobino](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/bobino/32/194_2.png) [@Bobino](https://the.fmsoup.org/u/Bobino)\
**Post date:** [September 20, 2022, 9:24pm UTC](https://the.fmsoup.org/t/perhaps-your-startup-script-should-ban-connections-from-19-5-2-clients/3088/12 "2022-09-20T21:24:06Z")

</div>

It is worth noting from the [release notes of 19.5.4](https://community.claris.com/en/s/article/Claris-FileMaker-Pro-19-5-4-Release-Notes) that the newer software will now open the problematic files. There is no mention about Encryption At Rest, and the release notes also do not mention what new value gets inserted as the minimum version required to open the file.

I also do not know if the fix is silent or the user gets notified of a change to that section, but in order for a fix to be implemented, that minimum version needs to be re-written and there is no way for the software to guess the value you need to see there, so you should pay attention to that after the file gets "fixed".

---

<div class="post-metadata">

**Author:** ![soliantkarl](https://avatars.discourse-cdn.com/v4/letter/s/e47c2d/32.png) [@soliantkarl](https://the.fmsoup.org/u/soliantkarl)\
**Post date:** [September 21, 2022, 1:07am UTC](https://the.fmsoup.org/t/perhaps-your-startup-script-should-ban-connections-from-19-5-2-clients/3088/13 "2022-09-21T01:07:49Z")

</div>

FMP 19.5.4 resets the minimum version to 12.0 if it was "damaged" by this bug. The fix is applied silently and no logging is done for it (like with import.log, recovery.log, conversion.log...). The same should happen on FMS but I haven't tested it there yet.

---

<div class="post-metadata">

**Author:** ![steve\_ssh](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/steve_ssh/32/160_2.png) [@steve\_ssh](https://the.fmsoup.org/u/steve_ssh)\
**Post date:** [September 21, 2022, 1:59am UTC](https://the.fmsoup.org/t/perhaps-your-startup-script-should-ban-connections-from-19-5-2-clients/3088/14 "2022-09-21T01:59:38Z")

</div>

Thank you for the additional detail @soliantkarl

---

<div class="post-metadata">

**Author:** ![flybynight](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/flybynight/32/1023_2.png) [@flybynight](https://the.fmsoup.org/u/flybynight)\
**Post date:** [September 21, 2022, 5:04pm UTC](https://the.fmsoup.org/t/perhaps-your-startup-script-should-ban-connections-from-19-5-2-clients/3088/15 "2022-09-21T17:04:56Z")

</div>

@soliantkarl does this work for files with EAR applied? I'm assuming so… but I don't like to assume anything in the world of agile development. 😉

---

<div class="post-metadata">

**Author:** ![soliantkarl](https://avatars.discourse-cdn.com/v4/letter/s/e47c2d/32.png) [@soliantkarl](https://the.fmsoup.org/u/soliantkarl)\
**Post date:** [September 21, 2022, 7:21pm UTC](https://the.fmsoup.org/t/perhaps-your-startup-script-should-ban-connections-from-19-5-2-clients/3088/16 "2022-09-21T19:21:47Z")

</div>

@flybynight My fix doesn't work with EAR files but FMP 19.5.4 (released yesterday on Sep 20, 2022) does fix this bug.

---

<div class="post-metadata">

**Author:** ![soliantkarl](https://avatars.discourse-cdn.com/v4/letter/s/e47c2d/32.png) [@soliantkarl](https://the.fmsoup.org/u/soliantkarl)\
**Post date:** [September 21, 2022, 7:27pm UTC](https://the.fmsoup.org/t/perhaps-your-startup-script-should-ban-connections-from-19-5-2-clients/3088/17 "2022-09-21T19:27:38Z")

</div>

To clarify, here's the timeline of this bug:

- July 18, 2022: Earliest report of this bug that I can see.
- Aug 27, 2022: I heard about the bug for the first time and published the fix on the same day.
- Aug 31, 2022: FileMaker Pro 19.5.3 was released. This release prevents this bug from happening but doesn't resolve it for files already affected by this bug.
- Sep 13, 2022: The Soliant blog post about this bug was published. [Fixing the "Convert this Database" Bug](https://www.soliantconsulting.com/blog/filemaker-convert-this-database-bug/)
- Sep 20, 2022: FileMaker Pro 19.5.4 was released, and it can fix files affected by this bug.

@FileKraft, I agree that we should avoid tampering with client applications using hex editors.  
In the [post](https://community.claris.com/en/s/question/0D53w00005oT2yiCAC/i-updated-to-1952201-and-now-when-i-try-to-open-files-i-keep-getting-request-to-convert-the-file-to-fmp12-and-they-are-all-fmp12-only-happened-since-upgrading) where I provided instructions about the fix, I wrote that the "fixed" file should not be used even though it's functional, but some didn't have unaffected backups of their files. It was a useful temporary fix until Claris released an official one. The hex editor was unavoidable to multiple FM devs, especially those whose clients urgently needed access to their systems (such as medical clinics).

---

<div class="post-metadata">

**Author:** ![flybynight](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/flybynight/32/1023_2.png) [@flybynight](https://the.fmsoup.org/u/flybynight)\
**Post date:** [September 21, 2022, 7:42pm UTC](https://the.fmsoup.org/t/perhaps-your-startup-script-should-ban-connections-from-19-5-2-clients/3088/18 "2022-09-21T19:42:50Z")

</div>

@soliantkarl thanks for confirming… yes, I was asking about 19.5.4, since they didn't explicitly say it worked on EAR files.

It might be nice if you added an update/addendum to your blog post about 19.5.4, mentioning encrypted files, and also the v12.0 that is silently applies as the minimum.

---

<div class="post-metadata">

**Author:** ![FileKraft](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/filekraft/32/1183_2.png) [@FileKraft](https://the.fmsoup.org/u/FileKraft)\
**Post date:** [September 21, 2022, 8:03pm UTC](https://the.fmsoup.org/t/perhaps-your-startup-script-should-ban-connections-from-19-5-2-clients/3088/19 "2022-09-21T20:03:15Z")

</div>

when there is a bug of this severity (complete data loss) communicate everything and don't outsource to third parties if responsible...

yes great that @soliantkarl offered quick rescue!

---

<div class="post-metadata">

**Author:** ![soliantkarl](https://avatars.discourse-cdn.com/v4/letter/s/e47c2d/32.png) [@soliantkarl](https://the.fmsoup.org/u/soliantkarl)\
**Post date:** [September 21, 2022, 9:22pm UTC](https://the.fmsoup.org/t/perhaps-your-startup-script-should-ban-connections-from-19-5-2-clients/3088/20 "2022-09-21T21:22:18Z")

</div>

I was going to wait seven days before posting an update about 19.5.4 in case a worse problem arose, but I don't think it's necessary in this case. I just submitted the update, and it is now in the process of being published.  
Thank you for your advice.

[Next page](https://the.fmsoup.org/t/perhaps-your-startup-script-should-ban-connections-from-19-5-2-clients/3088.md?page=2)
