From 18e123bdb2e8567eadd353d27222c50b255659ab Mon Sep 17 00:00:00 2001 From: Trulla Date: Wed, 16 Sep 2026 11:34:22 +0200 Subject: [PATCH 1/2] Add FileFlows ApiKey guard against [REDACTED] key corruption Die FileFlows-API liefert ApiKey-Felder im GET als [REDACTED]. Ein Save aus der Web-UI (oder GET->PUT-Roundtrip) schreibt diesen Platzhalter in die DB, wodurch alle vier Arr-Manual-Import-Nodes still mit 401 fehlschlagen. Der n8n-Handoff bleibt auf processing, movetdarr.sh pollt weiter und der SAB-Job haengt bis zum 24h-Timeout in der Queue. Negativtest bestaetigt: ein sabotierter Key korrumpiert alle vier, weil der GET alle vier als [REDACTED] ausliefert. Guard prueft die FileFlows-SQLite auf ApiKeys != 32 Zeichen und schreibt die echten Keys via Butler-Proxy zurueck. Laeuft als systemd-Timer alle 15min auf tdarr (cron dort inaktiv). --- fileflows/guard/README.md | 87 ++++++++++++++++++++++++ fileflows/guard/ff-apikey-guard.sh | 105 +++++++++++++++++++++++++++++ 2 files changed, 192 insertions(+) create mode 100644 fileflows/guard/README.md create mode 100755 fileflows/guard/ff-apikey-guard.sh diff --git a/fileflows/guard/README.md b/fileflows/guard/README.md new file mode 100644 index 0000000..fd209bd --- /dev/null +++ b/fileflows/guard/README.md @@ -0,0 +1,87 @@ +# FileFlows ApiKey Guard + +## Problem + +Die FileFlows-API liefert `ApiKey`-Felder in Flow-Parts beim `GET` grundsätzlich +als Literal `[REDACTED]` aus. Wird ein Flow danach gespeichert — aus der Web-UI +oder über einen `GET → PUT`-Roundtrip (Scripts, Automationen) — landet dieser +Platzhalter in der Datenbank. + +Folge: die Nodes `Sonarr - Trigger Manual Import` und +`Radarr - Trigger Manual Import` authentisieren sich mit `[REDACTED]`, die Arr +antwortet **401**, der Node bricht **still** ab. + +Fehlerbild in der Kette: + +``` +SABnzbd (movetdarr.sh) → FileFlows → Arr Manual Import + ↑ 401, still +``` + +- n8n Media-Handoff bleibt auf `processing` stehen +- `movetdarr.sh` pollt den Handoff-Lease weiter → SAB-Job hängt in der Queue + bis zum 24-h-Timeout +- Symptom beim Nutzer: "hängt seit Stunden in der Queue" + +**Ein einziger UI-Save zerschießt alle vier Keys gleichzeitig**, weil der GET +alle vier als `[REDACTED]` ausliefert (verifiziert per Negativtest: 1 Key +sabotiert → 4 Keys in der DB defekt). + +## Lösung + +`ff-apikey-guard.sh` prüft alle Flows in der FileFlows-SQLite auf ApiKeys mit +Länge != 32 und schreibt die echten Keys via Butler-Proxy +(`PUT /fileflows/api/flow`) zurück. + +Keys kommen aus einer lokalen Map, nie aus Git. + +## Deployment (tdarr, 10.2.1.104) + +```bash +sudo install -m 750 fileflows/guard/ff-apikey-guard.sh \ + /app-config/ff-guard/ff-apikey-guard.sh + +# Butler-Token +printf '%s' '' | sudo tee /app-config/ff-guard/butler.token +sudo chmod 600 /app-config/ff-guard/butler.token + +# Key-Map: " " pro Zeile, Keys aus den Arr-config.xml auf 10.2.1.100 +# 8989 sonarrUHD / 8990 sonarrFHD / 7878 radarrUHD / 7879 radarrFHD +sudo chmod 600 /app-config/ff-guard/arr-keys.map +``` + +Läuft als systemd-Timer alle 15 Minuten (`cron` ist auf tdarr inaktiv): + +``` +/etc/systemd/system/ff-apikey-guard.service Type=oneshot +/etc/systemd/system/ff-apikey-guard.timer OnUnitActiveSec=15min +``` + +```bash +sudo systemctl enable --now ff-apikey-guard.timer +``` + +## Betrieb + +```bash +# Log +sudo tail /app-config/ff-guard/guard.log + +# Manuell prüfen/reparieren +sudo systemctl start ff-apikey-guard.service + +# Timer-Status +systemctl list-timers ff-apikey-guard.timer +``` + +Logzeilen (Datum TT.MM.JJJJ): + +- `OK: alle Flow-ApiKeys 32 Zeichen` — nichts zu tun +- `WARNUNG: defekte ApiKeys in Flow — repariere` +- `Flow repariert: N Key(s) zurueckgeschrieben (HTTP 200)` + +## Nach einem UI-Save immer prüfen + +Wer einen Flow in der FileFlows-UI speichert, sollte danach den Guard anstoßen +oder maximal 15 Minuten auf den Timer warten. Vorher schlagen alle +Arr-Importe still fehl. diff --git a/fileflows/guard/ff-apikey-guard.sh b/fileflows/guard/ff-apikey-guard.sh new file mode 100755 index 0000000..0b38dd6 --- /dev/null +++ b/fileflows/guard/ff-apikey-guard.sh @@ -0,0 +1,105 @@ +#!/bin/bash +# ff-apikey-guard.sh — repariert kaputte Arr-ApiKeys in FileFlows-Flows +# +# URSACHE: Die FileFlows-API liefert ApiKey-Felder im GET als "[REDACTED]". +# Wird ein Flow aus der Web-UI (oder per GET->PUT-Roundtrip) gespeichert, +# landet dieser Platzhalter in der DB. Die "Trigger Manual Import"-Nodes +# schlagen dann still fehl (Arr antwortet 401), der n8n-Handoff bleibt auf +# "processing" und der SAB-Job haengt bis zum 24h-Timeout in der Queue. +# +# Dieses Skript erkennt ApiKeys != 32 Zeichen und schreibt die echten Keys +# aus /app-config/ff-guard/arr-keys.map zurueck (Format: " "). +set -u + +BUTLER="${BUTLER:-http://10.5.85.2:8888}" +GUARD_DIR="${GUARD_DIR:-/app-config/ff-guard}" +TOKEN_FILE="$GUARD_DIR/butler.token" +KEYMAP="$GUARD_DIR/arr-keys.map" +LOG="$GUARD_DIR/guard.log" +DB="${DB:-/app-config/fileflows-data/Data/FileFlows.sqlite}" + +mkdir -p "$GUARD_DIR" +log() { echo "$(date '+%d.%m.%Y %H:%M:%S'): $1" >> "$LOG"; } + +for f in "$TOKEN_FILE" "$KEYMAP"; do + [ -r "$f" ] || { log "FEHLER: Datei fehlt oder nicht lesbar: $f"; exit 1; } +done +[ -r "$DB" ] || { log "FEHLER: DB nicht lesbar: $DB"; exit 1; } + +TOKEN="$(tr -d '\n\r' < "$TOKEN_FILE")" + +# Flows mit defekten Keys ermitteln +FLOWUIDS="$(python3 - "$DB" <<'PY' +import sqlite3, json, sys +con = sqlite3.connect("file:%s?mode=ro" % sys.argv[1], uri=True) +for uid, name, typ, d in con.execute( + "select Uid,Name,Type,Data from DbObject where Type like '%Flow%'"): + try: + o = json.loads(d) + except Exception: + continue + for p in o.get("Parts", []): + k = (p.get("Model") or {}).get("ApiKey") + if k is not None and len(str(k)) != 32: + print(uid) + break +PY +)" + +if [ -z "$FLOWUIDS" ]; then + log "OK: alle Flow-ApiKeys 32 Zeichen" + exit 0 +fi + +RC=0 +for uid in $FLOWUIDS; do + log "WARNUNG: defekte ApiKeys in Flow $uid — repariere" + OUT="$(mktemp)"; PATCHED="$(mktemp)" + + if ! curl -sf -m 60 -H "Authorization: Bearer $TOKEN" \ + "$BUTLER/fileflows/api/flow/$uid" -o "$OUT"; then + log "FEHLER: GET flow $uid fehlgeschlagen" + rm -f "$OUT" "$PATCHED"; RC=1; continue + fi + + CHANGED="$(python3 - "$OUT" "$KEYMAP" "$PATCHED" <<'PY' +import json, sys +flow = json.load(open(sys.argv[1])) +keys = {} +for line in open(sys.argv[2]): + parts = line.split() + if len(parts) == 2 and len(parts[1]) == 32: + keys[parts[0]] = parts[1] +n = 0 +for p in flow.get("Parts", []): + mod = p.get("Model") or {} + if "ApiKey" not in mod: + continue + url = str(mod.get("URL") or mod.get("ApiUrl") or "") + port = url.rstrip("/").rsplit(":", 1)[-1] + if port in keys and str(mod["ApiKey"]) != keys[port]: + mod["ApiKey"] = keys[port] + n += 1 +json.dump(flow, open(sys.argv[3], "w")) +print(n) +PY +)" + + if [ "${CHANGED:-0}" = "0" ]; then + log "WARNUNG: Flow $uid — kein Key konnte gemappt werden (Ports pruefen)" + rm -f "$OUT" "$PATCHED"; RC=1; continue + fi + + HTTP="$(curl -s -m 60 -o /dev/null -w '%{http_code}' -X PUT \ + -H "Authorization: Bearer $TOKEN" -H 'Content-Type: application/json' \ + "$BUTLER/fileflows/api/flow" --data @"$PATCHED")" + + if [ "$HTTP" = "200" ]; then + log "Flow $uid repariert: $CHANGED Key(s) zurueckgeschrieben (HTTP 200)" + else + log "FEHLER: PUT flow $uid -> HTTP $HTTP" + RC=1 + fi + rm -f "$OUT" "$PATCHED" +done +exit $RC From 650417d42b944bb88e84b36680c3768c09d25c25 Mon Sep 17 00:00:00 2001 From: Trulla Date: Wed, 16 Sep 2026 11:45:33 +0200 Subject: [PATCH 2/2] Remove empty release dirs after finalize move 05_Finalize_Move loeschte nur die Original-Videodatei, nicht das Release-Verzeichnis. Zurueck blieben leere Ordner mit .nfo-Resten unter /tdarr/complete/, die GET /media/handoff/diagnostics als target_directories auflistet und dadurch wie haengende Jobs aussehen (6 Leichen gefunden). cleanupSourceDir loescht das Verzeichnis nur wenn: - es unter SourceRoot liegt und nicht SourceRoot selbst ist - find erfolgreich war (fail safe bei Fehler) - keine Mediendatei mehr darin liegt (Season-Pack-Schutz) 6 neue Tests im bestehenden Node-VM-Harness, 22/22 gruen. --- fileflows/scripts/05_Finalize_Move.js | 51 +++++- fileflows/tests/test_finalize_move_cleanup.py | 166 ++++++++++++++++++ 2 files changed, 216 insertions(+), 1 deletion(-) create mode 100644 fileflows/tests/test_finalize_move_cleanup.py diff --git a/fileflows/scripts/05_Finalize_Move.js b/fileflows/scripts/05_Finalize_Move.js index 2b8b69e..4e209ee 100644 --- a/fileflows/scripts/05_Finalize_Move.js +++ b/fileflows/scripts/05_Finalize_Move.js @@ -4,8 +4,10 @@ * behandelt Untertitel (Text-Subs als .srt-Sidecar, Bild-Subs Disposition neutralisieren). * SICHERHEITS-FIX 17.07.2026: atomare Sidecar-Erzeugung, 0-Byte-Pruefung, * nur erfolgreich extrahierte Textspuren entfernen, Remux-Verifikation. + * CLEANUP-FIX 16.09.2026: leeres Release-Verzeichnis unter SourceRoot + * entfernen (nur wenn keine Mediendatei mehr drin liegt). * @author Sascha + Trulla - * @revision 2 + * @revision 3 * @output OK * @output Fehler */ @@ -58,6 +60,7 @@ function Script(SourceRoot, DestRoot) if (origPath !== destAbs) { Flow.Execute({ command: '/bin/rm', argumentList: ['-f', origPath] }); Logger.ILog('Deleted original: ' + origPath); + cleanupSourceDir(origPath); } // ======================================================================= @@ -87,6 +90,52 @@ function Script(SourceRoot, DestRoot) return 1; // -- Helfer -------------------------------------------------------------- + + /** + * Loescht das Release-Verzeichnis des Originals, wenn darin keine + * Mediendatei mehr liegt. Ohne das bleiben nach jedem Import leere + * Ordner mit .nfo/.sfv-Resten unter /tdarr/complete/ liegen, die den + * Handoff-Diagnostics-Endpoint als "target_directories" verschmutzen + * und faelschlich wie haengende Jobs aussehen. + * Sicherheit: nur unter SourceRoot, nur wenn keine Mediendatei mehr da. + */ + function cleanupSourceDir(originalFile) { + var dir = originalFile.substring(0, originalFile.lastIndexOf('/')); + + if (!dir || dir.indexOf(SourceRoot) !== 0 || dir === SourceRoot || + dir === SourceRoot.replace(/\/$/, '')) { + Logger.ILog('Cleanup: "' + dir + '" nicht unter ' + SourceRoot + ' - uebersprungen'); + return; + } + + var mediaExts = ['mkv', 'mp4', 'avi', 'ts', 'm2ts', 'mov', 'wmv', 'mpg', 'mpeg', 'm4v', 'iso']; + var findArgs = [dir, '-type', 'f', '(']; + mediaExts.forEach(function (ext, i) { + if (i > 0) findArgs.push('-o'); + findArgs.push('-iname', '*.' + ext); + }); + findArgs.push(')'); + + var found = Flow.Execute({ command: '/usr/bin/find', argumentList: findArgs }); + if (!found || found.exitCode !== 0) { + Logger.WLog('Cleanup: find fehlgeschlagen - Verzeichnis bleibt: ' + dir); + return; + } + + var remaining = ('' + (found.standardOutput || '')).trim(); + if (remaining.length > 0) { + Logger.ILog('Cleanup: Mediendateien noch vorhanden - Verzeichnis bleibt: ' + dir); + return; + } + + var del = Flow.Execute({ command: '/bin/rm', argumentList: ['-rf', dir] }); + if (del && del.exitCode === 0) { + Logger.ILog('Cleanup: Release-Verzeichnis entfernt: ' + dir); + } else { + Logger.WLog('Cleanup: rm fehlgeschlagen (exit=' + (del ? del.exitCode : '?') + '): ' + dir); + } + } + function handleSubtitles(file) { var ffprobe = Flow.GetToolPath('ffprobe') || Variables['ffprobe'] || 'ffprobe'; var ffmpeg = Flow.GetToolPath('ffmpeg') || Variables['ffmpeg'] || 'ffmpeg'; diff --git a/fileflows/tests/test_finalize_move_cleanup.py b/fileflows/tests/test_finalize_move_cleanup.py new file mode 100644 index 0000000..56dd29b --- /dev/null +++ b/fileflows/tests/test_finalize_move_cleanup.py @@ -0,0 +1,166 @@ +"""Tests fuer cleanupSourceDir in 05_Finalize_Move.js. + +Hintergrund (16.09.2026): Das Script loeschte nur die Original-Videodatei, nicht +das Release-Verzeichnis. Dadurch blieben unter /tdarr/complete/ leere Ordner mit +.nfo-Resten liegen. Die tauchten im Butler-Endpoint +GET /media/handoff/diagnostics als "target_directories" auf und sahen wie +haengende Jobs aus, obwohl der Import laengst durch war. + +Diese Tests fahren das echte Script in einem Node-VM-Sandkasten und pruefen, +dass rm -rf NUR bei leeren Release-Verzeichnissen unter SourceRoot laeuft. +""" + +import json +import subprocess +import unittest +from pathlib import Path + + +SCRIPT = Path(__file__).parents[1] / "scripts" / "05_Finalize_Move.js" + +NODE_HARNESS = r""" +const fs = require('fs'); +const vm = require('vm'); +const scenario = JSON.parse(process.argv[2]); +let source = fs.readFileSync(process.argv[3], 'utf8') + .replace(/^\/\*\*[\s\S]*?\*\/\s*/, ''); +source += '\n;globalThis.__exports = { Script };'; + +const executed = []; + +function fakeExecute(spec) { + const cmd = spec.command; + const args = spec.argumentList || []; + executed.push({command: cmd, args: args}); + + if (cmd === '/usr/bin/find') { + const dir = args[0]; + const hits = (scenario.mediaFiles || []).filter(f => f.startsWith(dir)); + return {exitCode: scenario.findExitCode === undefined ? 0 : scenario.findExitCode, + standardOutput: hits.join('\n')}; + } + if (cmd === '/usr/bin/test') { + return {exitCode: 1}; // Ziel existiert nicht + } + if (cmd === '/bin/mv') { + return {exitCode: scenario.mvExitCode === undefined ? 0 : scenario.mvExitCode}; + } + if (cmd === '/bin/rm') { + return {exitCode: scenario.rmExitCode === undefined ? 0 : scenario.rmExitCode}; + } + if (cmd === '/bin/mkdir') { + return {exitCode: 0}; + } + if (String(cmd).indexOf('ffprobe') !== -1) { + // keine Subtitle-Streams -> handleSubtitles steigt sofort aus + return {exitCode: 0, standardOutput: JSON.stringify({streams: []})}; + } + return {exitCode: 0, standardOutput: ''}; +} + +const context = { + Variables: { + 'file.Orig.FullName': scenario.origPath, + 'file.FullName': scenario.workingFile + }, + Flow: { + Execute: fakeExecute, + SetWorkingFile() {}, + GetToolPath: name => '/usr/bin/' + name, + TempPath: '/temp', + NewGuid: () => 'guid-0000' + }, + Logger: {ILog(){}, WLog(){}, ELog(){}, DLog(){}}, + JSON: JSON, + console +}; +vm.createContext(context); +vm.runInContext(source, context); + +const rc = context.__exports.Script( + scenario.sourceRoot || '/tdarr/complete/', + scenario.destRoot || '/tdarr/converted/' +); +console.log(JSON.stringify({rc: rc, executed: executed})); +""" + + +def run_script(scenario): + harness = Path("/tmp/ff_finalize_harness.js") + harness.write_text(NODE_HARNESS) + proc = subprocess.run( + ["node", str(harness), json.dumps(scenario), str(SCRIPT)], + capture_output=True, text=True, timeout=60, + ) + if proc.returncode != 0: + raise AssertionError(f"harness failed: {proc.stderr[-2000:]}") + return json.loads(proc.stdout.strip().splitlines()[-1]) + + +def rm_rf_targets(result): + return [e["args"][1] for e in result["executed"] + if e["command"] == "/bin/rm" and e["args"][:1] == ["-rf"]] + + +class CleanupSourceDirTests(unittest.TestCase): + + BASE = { + "origPath": "/tdarr/complete/serien4k/Slow.Horses.S06E01-W4K/slow.horses.s06e01-w4k.mkv", + "workingFile": "/temp/Runner-1/slow.horses.s06e01-w4k.mkv", + } + + def test_leeres_release_verzeichnis_wird_entfernt(self): + """Nur .nfo uebrig -> Verzeichnis muss weg.""" + result = run_script({**self.BASE, "mediaFiles": []}) + self.assertEqual(result["rc"], 1) + self.assertEqual( + rm_rf_targets(result), + ["/tdarr/complete/serien4k/Slow.Horses.S06E01-W4K"], + ) + + def test_verzeichnis_mit_restlicher_mediendatei_bleibt(self): + """Season-Pack: zweite Episode noch da -> nicht loeschen.""" + result = run_script({ + **self.BASE, + "mediaFiles": [ + "/tdarr/complete/serien4k/Slow.Horses.S06E01-W4K/slow.horses.s06e02-w4k.mkv" + ], + }) + self.assertEqual(result["rc"], 1) + self.assertEqual(rm_rf_targets(result), []) + + def test_find_fehler_laesst_verzeichnis_stehen(self): + """find schlaegt fehl -> fail safe, nichts loeschen.""" + result = run_script({**self.BASE, "mediaFiles": [], "findExitCode": 1}) + self.assertEqual(result["rc"], 1) + self.assertEqual(rm_rf_targets(result), []) + + def test_sourceroot_selbst_wird_nie_geloescht(self): + """Datei direkt in SourceRoot -> rm -rf /tdarr/complete darf NICHT passieren.""" + result = run_script({ + "origPath": "/tdarr/complete/lose.datei.mkv", + "workingFile": "/temp/Runner-1/lose.datei.mkv", + "mediaFiles": [], + }) + self.assertEqual(rm_rf_targets(result), []) + + def test_pfad_ausserhalb_sourceroot_wird_abgelehnt(self): + """Original nicht unter SourceRoot -> Script bricht mit 2 ab, kein rm -rf.""" + result = run_script({ + "origPath": "/mnt/anderswo/film/film.mkv", + "workingFile": "/temp/Runner-1/film.mkv", + "mediaFiles": [], + }) + self.assertEqual(result["rc"], 2) + self.assertEqual(rm_rf_targets(result), []) + + def test_originaldatei_wird_weiterhin_geloescht(self): + """Regression: rm -f auf das Original bleibt erhalten.""" + result = run_script({**self.BASE, "mediaFiles": []}) + rm_f = [e["args"][1] for e in result["executed"] + if e["command"] == "/bin/rm" and e["args"][:1] == ["-f"]] + self.assertIn(self.BASE["origPath"], rm_f) + + +if __name__ == "__main__": + unittest.main(verbosity=2)