Inspect Windows .ico Files on Linux with the winicon Manual
You will finish with a reliable way to identify a Windows icon file on Linux and a clear understanding of what its sizes, colour depths and transparency data mean. The local winicon(1) page is a format reference, not a command you run to convert an image.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about ten minutes. You need a shell, the netpbm package for the manual page, and an .ico file that you can read. The examples inspect files only. They do not alter an icon, install anything or require sudo.
1. Check what winicon is on this system
Start by reading the installed manual page and checking the package version. These are ordinary, read-only commands:
$ man winicon
$ dpkg-query -W -f='${Package} ${Version}\n' netpbm
netpbm 2:11.05.02-1.1build1
The first command opens documentation headed Windows Icons. This package does not provide a separate winicon executable on the inspected system: man -w winicon resolves to /usr/share/man/man1/winicon.1.gz, while command -v winicon produces no path. That distinction prevents a common error: trying to pass an icon to a documentation page as though it were a converter.
Checkpoint
If man winicon reports that no manual entry exists, check that netpbm is installed. If the package version differs, treat the behaviour described here as the contract of the manual page you actually read, not as a guarantee about every release.
2. Confirm the file name and basic type
Windows icon files normally use the .ico extension. The manual records the registered MIME type as image/vnd.microsoft.icon, notes the still-common unofficial name image/x-icon, and identifies .ico as the Microsoft file extension. The extension is useful, but it is not proof that the bytes are an icon.
Inspect the candidate without opening or modifying it:
$ ICON='/path/to/application.ico'
$ test -r "$ICON" && file -- "$ICON"
/path/to/application.ico: MS Windows icon resource - 2 icons, 32x32, 4 bits/pixel
The exact file wording depends on its version and on the contents of your icon. Look for an identification as a Microsoft Windows icon resource. If it instead reports generic data, a different image type or an error, stop and check the path before treating the file as an .ico.
If file is unavailable, the manual still gives you the format facts, but it does not supply a validation utility. Do not invent a magic-number test from this page: the documented format can contain several images and different encodings.
3. Read an icon as a collection of images
A Windows icon file can contain one or more images. Each image can have its own resolution and bits-per-pixel value, up to 256 by 256 pixels according to the local documentation. This is why an icon is not simply one bitmap with a fixed size.
Typical shell entries include 16x16, 32x32 and 48x48 images at 4, 8 or 32 bits per pixel. Newer icon sets can also contain 24x24, 96x96 and 256x256 entries. A 256x256 image is commonly PNG encoded. These are representative values, not a promise that every icon contains all of them.
The bpp label is easy to misread. For ordinary BMP-encoded images, the colour channels are generally RGB with 8 bits per channel. Below 16 bpp, a palette is used. In that context, the bpp value describes the number of available colours rather than the number of bits in each colour channel.
Checkpoint
When an inspection tool lists several entries, record the size and bpp for each one. Do not discard a smaller entry just because a larger one exists: software may select an image that matches the display size.
4. Interpret transparency without guessing
BMP-encoded icon images use two masks. The XOR mask carries the colour information. The AND mask carries one-bit transparency information. On a monochrome display, the masks are combined with the background: the AND operation is applied first and the XOR operation second.
That model explains why an old icon can look odd on a modern background. A set bit in the AND mask with a reset bit in the XOR mask represents transparency in the documented monochrome example. A set bit in both masks requests an inverted background. In colour environments, pixels outside the opaque area are usually black and sometimes white; other colours are not predictable.
Since Windows XP, a 32-bit BMP-encoded icon may also carry an 8-bit transparency channel. The AND mask is still required, including for uses such as generating shadows. PNG-encoded images do not contain an AND mask. Windows constructs one from the PNG transparency channel when rendering, if that channel is present.
This is a reason to avoid 'fixing' an icon by converting it immediately. A conversion tool may preserve the visible result while changing which transparency representation is stored. First establish whether the source entry is BMP or PNG encoded and whether the edge behaviour is actually a format issue.
5. Make a non-destructive visual check
If ImageMagick is already installed, identify can provide a second opinion and often reports multiple frames or entries:
$ identify -- "$ICON"
/path/to/application.ico[0] ICO 32x32 32x32+0+0 8-bit sRGB 1.2KiB 0.000u 0:00.000
$ identify -format '%m %wx%h\n' -- "$ICON"
ICO 32x32
Output varies with the ImageMagick build and the icon. The useful checks are that the command exits successfully, reports an ICO image, and shows dimensions that make sense for the entry you intended to inspect. If it reports a delegate or decoding error, retain the original file and investigate that error rather than overwriting the source.
Neither file nor identify proves that every consumer will render every entry identically. Windows can construct an AND mask for a PNG entry, while older software may expect BMP masks. Test the icon in the application that will use it if compatibility matters.
6. Keep the original safe
Reading an icon is reversible because it changes nothing. Conversion is different: shell redirection with > truncates its destination before a program writes output. Do not direct experimental output at the source file:
$ cp --preserve=all -- "$ICON" "${ICON}.backup"
$ identify -- "$ICON"
$ ls -l -- "$ICON" "${ICON}.backup"
This backup command is optional and needs write permission in the directory. To undo the backup operation, remove only the explicitly named backup after you have finished checking the original:
$ rm -- "${ICON}.backup"
That removal is destructive, so confirm the path with printf '%s\n' "${ICON}.backup" first. There is no reason to use elevated privileges for files in your own working directory. If an icon belongs to a system package, copy it to a temporary working directory for inspection instead of changing the installed file.
Done means
man winiconworks and you know which Netpbm version supplied it.- You have confirmed the candidate is readable and identified it as an ICO resource.
- You understand that one file can contain several sizes, colour depths and encodings.
- You have considered both the XOR/AND masks and PNG transparency before converting anything.
- The original icon remains unchanged and any optional backup has a deliberate, known path.