mirror of
https://gitcode.com/JianFeeeee/HomeAgent.git
synced 2026-10-04 00:03:59 +00:00
fix(plugins): bili output_dir 系统目录黑名单 + recoverydiag db_path 沙箱限制
P3 bili: output_dir 配置项此前未校验,yt-dlp 可被配置写到任意系统目录。 加系统目录黑名单(/、/etc、/usr、/var 等),命中直接拒绝执行。 P4 recoverydiag: db_path 参数 LLM 可控,可探测读取任意 sqlite 文件。 现强制限制在 data 目录内(前缀校验),越界返回提示。 两插件重打包升版(bili 1.2.0 / recoverydiag 0.2.0)安装验证 config_kept=true,内核重启加载正常。
This commit is contained in:
21
third_party/homeagent-sdk/example/recoverydiag/plg.json
vendored
Normal file
21
third_party/homeagent-sdk/example/recoverydiag/plg.json
vendored
Normal file
@ -0,0 +1,21 @@
|
||||
{
|
||||
"name": "recoverydiag",
|
||||
"name_zh": "恢复诊断",
|
||||
"name_en": "Recovery Diagnostics",
|
||||
"version": "0.2.0",
|
||||
"description": "快速检查/崩溃取证工具集:diag_triage(退出码/信号/存活粗分)、diag_db(config.db 完整性 + LLM 源解析校验)、diag_log_scan(日志签名命中)、diag_delta(last-good 快照 vs 现状 diff)、diag_loc(正交综合定位)。全部返回结论而非原文,确定性、不消耗 LLM token,供 guard / failback 恢复决策使用。",
|
||||
"author": "HomeAgent",
|
||||
"entry": "plugin.so",
|
||||
"tags": [
|
||||
"diag",
|
||||
"recovery",
|
||||
"diagnostics",
|
||||
"triage",
|
||||
"failback"
|
||||
],
|
||||
"targets": "linux/amd64",
|
||||
"outdir": "dist",
|
||||
"bundle": true,
|
||||
"replaces": {},
|
||||
"source_dirs": []
|
||||
}
|
||||
1023
third_party/homeagent-sdk/example/recoverydiag/plugin.go
vendored
Normal file
1023
third_party/homeagent-sdk/example/recoverydiag/plugin.go
vendored
Normal file
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user