fix(blur): fold the heid bug-hunt: two file names, a reader-judged writer, one predicate
The heid bug-hunt panel on 4cfbce5 (hulda, regin, kimi; groa timed out) found
four real defects in the round-trip fix, and three of its arms converged on the
worst: it re-created the bug it existed to fix.
- Two names, never a sniffed file (3/3). JSON went into the OLD `.blurred`, and
the reader guessed the format from the bytes, so a legacy file whose one line
is an item named `["a.png"]` read as {"a.png"} and blurred the neighbour. The
set now lives in `.blurred.json`, JSON only. The legacy `.blurred` is read as
lines only, and only while `.blurred.json` is absent; the first write retires
it, after the new file is in place.
- A planted directory is a 409, not a 500 (2/3 plus a third angle, executed by
the seat). The reader was hardened against it and the writer was not:
os.replace and unlink raised IsADirectoryError through the route. Now the
writer is judged by its reader: set_blurred re-reads after writing and raises
BlurUnwritable unless the set on disk is the set asked for. That one check
covers a directory at either name, a permission and a race.
- A lone surrogate is dropped on read (hulda, executed). `"\ud800"` is a valid
JSON string that no filename can produce, and the UTF-8 encode raised on it
at every later write.
- The writer respects the reader's size cap (2/3). Nothing capped the write,
and the reader reads an oversized file as EMPTY, which reveals everything.
- One predicate, check_rel, for the route and the CLI (2/3). The CLI's `*..*`
substring guard refused `a..b.png`, which the route accepts. It also refuses
an empty path now (regin, kimi), and every item is checked before any is
written.
- `booth blur` fails closed, with a message and exit 3, when its package is
missing (kimi), as `link` already does.
Declined, with reasons: the Item positional-constructor break (booth_items is
the only constructor, INV-1), the fdopen fd leak and the short read (not
constructible on a local filesystem, and the `.seen` shape), and
unreadable-reads-as-revealed (blur is cosmetic; the `.seen` posture).
blur_storage.toml: 20/20 proved. One row came back VACUOUS on its first run,
because `set() or X` is X, and was rewritten before counting.
This commit is contained in:
+14
-8
@@ -104,7 +104,7 @@ from booth.items import ( # noqa: E402,F401
|
||||
)
|
||||
# The per-item blur writer lives with its reader in booth/blur.py, stdlib-only so
|
||||
# `scripts/booth blur` shares both. Re-exported: tests import it from here.
|
||||
from booth.blur import set_blurred # noqa: E402,F401
|
||||
from booth.blur import BlurUnwritable, check_rel, set_blurred # noqa: E402,F401
|
||||
|
||||
# Sentinel dotfile that exempts a booth from the TTL sweep. A dotfile because
|
||||
# the existing listing code already skips dotfiles, so it costs nothing in item
|
||||
@@ -2216,14 +2216,20 @@ def create_app(
|
||||
"""Toggle one item's blur. Reversible and cosmetic, so no confirmation.
|
||||
See BLUR_FILE: this hides an item from a glance, it does not protect it."""
|
||||
booth = resolve_booth(name)
|
||||
# Guard the path the same way the file route must: a blur entry is only
|
||||
# ever a booth-relative path, never an escape. NEVER STRIPPED: " a.png"
|
||||
# and "a.png" are two items, and a stripped `f` blurred the neighbour
|
||||
# (heid bug-hunt on r2b merge 1). A leading "/" is never part of a rel.
|
||||
# NEVER STRIPPED: " a.png" and "a.png" are two items, and a stripped
|
||||
# `f` blurred the neighbour (heid bug-hunt on r2b merge 1). A leading
|
||||
# "/" is never part of a rel. What else a blur entry may be is
|
||||
# `check_rel`'s one predicate, shared with `booth blur`, so the route
|
||||
# and the CLI cannot disagree about which items are addressable.
|
||||
rel = f.lstrip("/")
|
||||
if ".." in Path(rel).parts:
|
||||
raise HTTPException(status_code=400, detail="bad item path")
|
||||
set_blurred(booth, rel, on not in ("0", "false", ""))
|
||||
try:
|
||||
set_blurred(booth, rel, on not in ("0", "false", ""))
|
||||
except ValueError as exc:
|
||||
raise HTTPException(status_code=400, detail=str(exc))
|
||||
except BlurUnwritable as exc:
|
||||
# The state on disk is wrong (a planted directory, a permission),
|
||||
# not the request: a refusal, never a 500.
|
||||
raise HTTPException(status_code=409, detail=str(exc))
|
||||
return RedirectResponse(url=f"/b/{quote(name, safe='')}/", status_code=303)
|
||||
|
||||
@app.post("/b/{name}/delete")
|
||||
|
||||
Reference in New Issue
Block a user