Pull requests / #1126

#1126 Harden server, installer and engine against high-risk bugs

open · @aelnaby · 0 评论 · 在 GitHub 查看

Setup & installServer & APINVIDIA / CUDAModels & quantsSecurity

描述

Re-open of #992, rebased onto the new main after the history cleanup (old PR cannot be reopened).

Server: bounded request bodies (caps layered onto _body, keeping the drain machinery), vision image fetch with per-hop allowlist before connecting (no-redirect opener), connected-peer IP re-check, private/loopback/metadata refusal, size caps, Pillow bomb guards; MCP tools gated on the receiving interface (loopback keyless, LAN needs api_key or mcp_allow_remote); no shell=True in before_load; fail closed on cors ["*"] without api_key; tighter Origin trust.

Installer: safe zip extraction (traversal/symlink refusal, exec bits kept, bad-zip drop), private temp dir for the CUDA keyring, list2cmdline quoting, entrypoint allowlists, image size cap.

Engine: GGUF/PLE/index.txt overflow guards, native embed bound check.

Verified: serve.test_security 23/23 OK, test_setup_risk/pins/config OK, py_compile OK. C++ build needs the CUDA toolchain.

站内延伸阅读

链到安装、模型与版本说明,便于 SEO/GEO,非官方 issue 正文。