Open Files Safely by MIME Type with mimeopen

mimeopen launches a file through its desktop MIME association, or lets you pick a different app for one run only. This guide covers both, plus diagnosing a missing association without guessing. The examples match mimeopen 0.34 from Debian package libfile-mimeinfo-perl 0.34-1, the version installed on this machine.

1. Confirm the installed command

Check the version before relying on a flag in a script:

$ mimeopen --version
mimeopen 0.34

The command comes from libfile-mimeinfo-perl. If mimeopen is not found, install the package through your normal distribution process; do not use sudo merely to run it.

2. Open a file with its default application

Pass the path as an ordinary argument:

$ mimeopen /path/to/report.pdf

mimeopen works out the file's MIME type and asks the desktop application database for the default handler. If one is configured, that application runs. If none is configured, the command shows an open-with menu in the terminal.

There is no useful universal output to copy here: the visible result is the application window, which may detach immediately. Check the application itself rather than treating a quiet terminal as proof the file opened.

Checkpoint: start with a harmless document you already trust, such as /path/to/report.pdf, and keep the original file in place. mimeopen opens it; it does not convert or edit it.

3. Choose an application for one launch

Use --ask when you want a menu without changing the default association:

$ mimeopen --ask /path/to/report.pdf

Select an application when prompted. The manual is explicit that --ask does not change the default, which makes it the safer choice when testing a viewer or working on a shared desktop profile.

Use --ask-default only when you intend to set a new default:

$ mimeopen --ask-default /path/to/report.pdf

Warning: this changes desktop association state for the relevant MIME type, not just this one file. Record the current association first if you may need to restore it, and make the change through the desktop settings or association tool you normally use if you need a documented undo path. The manpage promises no portable command for reversing it.

4. Make a non-interactive choice

Use --no-ask in a script or remote session, where a terminal prompt would just hang:

$ mimeopen --no-ask /path/to/report.pdf

The command picks the configured default, or the first program known to handle the MIME type if there is no default. Either way it does not set that program as the new default. In automation, a successful launch does not mean the user's association has changed.

Do not treat --no-ask as proof a particular application was chosen. If the exact application matters, check the desktop association separately, or invoke that application directly through its own command-line interface.

5. Trust the content instead of the filename

Normally MIME detection can use the filename extension, glob rules and inode type as well as content. Use --magic-only when the name or extension is untrusted:

$ mimeopen --magic-only /path/to/downloaded-file

This tells the command to inspect only the content, which is useful for a file whose suffix has been changed. It is not a security scanner: a MIME type is an input to application selection, not proof the file is safe. Treat a file from an untrusted source as untrusted even when the detected type looks familiar, and avoid an application that parses active content unless that risk is acceptable.

6. Diagnose a missing association

Add --debug to see how the MIME type was worked out:

$ mimeopen --debug --no-ask /path/to/report.pdf

Debug output can show the data directories searched and the matching MIME rules, but it does not guarantee a handler exists. On this machine, a debug run against /etc/hosts reports:

WARNING: You don't seem to have any mimeinfo.cache files.
No applications found for mimetype: text/plain

The exact diagnostic varies with the file and desktop install. The warning points at the desktop application cache; the final line means no registered application was found for the detected type.

7. Keep scripts predictable

Ask for help or version information without opening anything:

$ mimeopen --help
$ mimeopen --version

This installed version supports --ask, --ask-default, --no-ask, --magic-only, --database, --debug, --help, --usage and --version. The old --dereference option is deprecated and ignored, because following symbolic links is already the default.

Quote paths supplied by users or discovered by a script:

file_path="/path/to/report with spaces.pdf"
mimeopen --no-ask -- "$file_path"

The -- separator stops a path beginning with a hyphen being read as an option. Keep the command unprivileged unless the file itself is inaccessible, and do not give a desktop application more access than it needs just to open a document.

Done means