fix: 渲染引擎安全加固P0+P1 补修第二轮
CI/CD Pipeline / Validate Code Quality And Tests (pull_request) Failing after 16s
CI/CD Pipeline / Unit Tests (pull_request) Failing after 1m11s
CI/CD Pipeline / Production Browser E2E (pull_request) Failing after 1535h8m25s
CI/CD Pipeline / Staging E2E Tests (pull_request) Failing after 1535h8m27s
CI/CD Pipeline / Deploy Production (pull_request) Failing after 1535h8m27s
CI/CD Pipeline / Build Production Runtime Images (pull_request) Failing after 1535h8m28s
CI/CD Pipeline / Build & Push Staging (Watchtower auto-deploy) (pull_request) Failing after 1535h8m28s
CI/CD Pipeline / Integration Tests (pull_request) Has been skipped
CI/CD Pipeline / Frontend Lint (pull_request) Has been skipped
CI/CD Pipeline / Staging API Integration Tests (pull_request) Failing after 1535h40m5s

- SSRF漏接点补全:TTS 3个下载点 + BGM 3个下载点 全部接入 url_security.py 校验
  - TTS: workflow.py (_transfer_audio_to_oss, _download_and_merge_segments) + streaming_service.py (_download_audio)
  - BGM: generation.py (外部直链, 预设库) + batch_download.py (HTTP回退)
- 重定向防护:手动跟随重定向,每次跳转前重新校验目标 URL(禁用默认自动跟随)
- 文件大小/类型限制:新增 safe_download_file/safe_download_bytes,流式下载 + 大小上限 + MIME 白名单
- 裸 subprocess 补齐:5 处全部改走统一 run_ffmpeg/run_ffprobe
  - asset_analyzer.py: 3处 (ffprobe + 2个ffmpeg)
  - ingest.py: 1处 (ffprobe)
  - voice_extraction.py: 1处 (ffmpeg)
- URL安全模块迁移到 packages/shared/ 作为单一来源,worker 端保留向后兼容 re-export
- 新增 run_ffprobe 统一工具函数到 ffmpeg_utils
- 新增 7 个下载安全单测,累计 33 个 URL 安全测试
This commit is contained in:
CI Bot
2026-07-14 15:34:29 +08:00
parent 3b80edd8c5
commit 334e2b1fc2
11 changed files with 712 additions and 279 deletions
@@ -119,6 +119,55 @@ def run_ffmpeg(
raise
def run_ffprobe(
command: list[str],
*,
capture_output: bool = True,
timeout: int = 30,
) -> tuple[str, str]:
"""执行 FFprobe 命令。
Args:
command: 完整的 ffprobe 命令列表(含 "ffprobe" 本身)
capture_output: 是否捕获 stdout/stderr
timeout: 超时时间(秒),默认 30s;None 表示不设超时
Returns:
(stdout, stderr) 元组
Raises:
subprocess.CalledProcessError: 命令执行失败时抛出
subprocess.TimeoutExpired: 超时未完成时抛出
"""
try:
result = subprocess.run( # nosec B603
command,
check=True,
stdout=subprocess.PIPE if capture_output else None,
stderr=subprocess.PIPE if capture_output else None,
text=True,
timeout=timeout,
)
return (result.stdout or "", result.stderr or "")
except subprocess.TimeoutExpired:
logger.error(
"FFprobe 命令超时 (%ds): command=%s",
timeout or -1,
" ".join(str(c) for c in command[:20]),
)
raise
except subprocess.CalledProcessError as e:
stderr_text = (e.stderr or "").strip()
logger.error(
"FFprobe 命令失败: exit_code=%d command=%s\nstderr:\n%s",
e.returncode,
" ".join(str(c) for c in command[:20]),
stderr_text[:5000],
)
raise
def probe_has_audio(local_path: str | Path) -> bool:
"""探测文件是否包含音频流。