Restore native LTX media mounts with a restricted shared-directory policy

This commit is contained in:
Mikei386
2026-09-30 15:47:24 +02:00
parent ea33527233
commit 21f11eac57
3 changed files with 13 additions and 3 deletions
+7 -2
View File
@@ -89,7 +89,9 @@ def validate(c):
targets.add(target)
if m.get('index')!=i or type(m.get('read_only')) is not bool or type(m.get('was_file')) is not bool:raise ValueError('Ungültige Volume-Einstellung.')
rel=m.get('deck_path')
if rel is not None and (rel not in ('models','video/comfy-work/models','video/comfy-client-token') or not m['read_only']):raise ValueError('Deck-Dateien dürfen nur als bekannte, lesende Modell-/Token-Volumes eingebunden werden.')
media={'video/original-work/remote-inputs/deskweb':('/data/inputs',False),'video/original-work/outputs':('/data/outputs',True)}
native_media=rel in media and c['name']=='ltx-deskweb' and (target,m['read_only'])==media[rel] and not m['was_file']
if rel is not None and not native_media and (rel not in ('models','video/comfy-work/models','video/comfy-client-token') or not m['read_only']):raise ValueError('Deck-Volume nicht freigegeben; nur bekannte Modell-/Tokenpfade und LTX-Medienordner erlaubt.')
for name,data in m.get('files',{}).items():
if name not in ('file','Settings.fds','Backends.fds'):raise ValueError('Unbekannte Konfigurationsdatei.')
if not isinstance(data,str) or len(base64.b64decode(data,validate=True))>MAX_FILE:raise ValueError('Ungültige Konfigurationsdatei.')
@@ -150,7 +152,10 @@ def restore(manager,c):
if m['deck_path']=='video/comfy-client-token' and not source.exists():
import secrets
source.parent.mkdir(parents=True,exist_ok=True);source.write_text(secrets.token_urlsafe(48)+'\n');source.chmod(0o600);os.chown(source,65534,65534)
elif m['deck_path']!='video/comfy-client-token':source.mkdir(parents=True,exist_ok=True)
elif m['deck_path']!='video/comfy-client-token':
source.mkdir(parents=True,exist_ok=True)
if m['deck_path'].startswith('video/original-work/'):
is_input=m['deck_path'].endswith('/deskweb');os.chown(source,1000 if is_input else 65534,65534);source.chmod(0o2770 if is_input else 0o2750)
elif m['was_file']:
if 'file' not in m['files']:raise ValueError('Benötigte Volume-Datei fehlt im Backup.')
source.write_bytes(base64.b64decode(m['files']['file']));source.chmod(0o600)