Adversarial runner needs media sandbox for thumbnail checks #211

Closed
opened 2026-09-26 20:23:52 +00:00 by kayg · 1 comment
Owner

Found during the post-merge real-server adversarial round for #114 on commit ec16c9cd9a60a472dc405638433b99ee6b3bd52b (2026-09-26).

tests/adversarial/run.sh builds and starts calternal-server on the host. It does not install calternal-media-sandbox or calternal-media-sandbox-dropcaps; command -v found neither. The runtime image copies deploy/media-sandbox and the /opt/calternal codec tools. MediaThumbnailer starts calternal-media-sandbox image .... If that command is missing, run_media_output returns no output and the thumbnail job does not publish derived data. The public thumbnail route returns 404 when the derived file is absent.

Observed in the real-server share-options probe: it uploaded Audit/Secret photo name.jpg, waited 30 seconds, and found no thumbnail. View-only thumbnail requests at sizes 256 and 1024 returned 404. Password gallery thumbnail requests and the later download-limit thumbnail checks also returned 404. The server remained alive. The route behavior is consistent with a missing derived thumbnail; share authorization still needs a media-enabled run.

Update the local runner to provide the same sandbox and codec tools as the runtime image, or add a clear media-capability check and run thumbnail-success assertions only in a media-enabled environment. Keep native decoders inside the sandbox.

Found during the post-merge real-server adversarial round for #114 on commit `ec16c9cd9a60a472dc405638433b99ee6b3bd52b` (2026-09-26). `tests/adversarial/run.sh` builds and starts `calternal-server` on the host. It does not install `calternal-media-sandbox` or `calternal-media-sandbox-dropcaps`; `command -v` found neither. The runtime image copies `deploy/media-sandbox` and the `/opt/calternal` codec tools. `MediaThumbnailer` starts `calternal-media-sandbox image ...`. If that command is missing, `run_media_output` returns no output and the thumbnail job does not publish derived data. The public thumbnail route returns 404 when the derived file is absent. Observed in the real-server `share-options` probe: it uploaded `Audit/Secret photo name.jpg`, waited 30 seconds, and found no thumbnail. View-only thumbnail requests at sizes 256 and 1024 returned 404. Password gallery thumbnail requests and the later download-limit thumbnail checks also returned 404. The server remained alive. The route behavior is consistent with a missing derived thumbnail; share authorization still needs a media-enabled run. Update the local runner to provide the same sandbox and codec tools as the runtime image, or add a clear media-capability check and run thumbnail-success assertions only in a media-enabled environment. Keep native decoders inside the sandbox.
Author
Owner

Duplicate of #209 (media sandbox on the local runner); the e2e-fix job owns it.

Duplicate of #209 (media sandbox on the local runner); the e2e-fix job owns it.
kayg closed this issue 2026-09-26 21:02:32 +00:00
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#211
No description provided.