fix: sandbox_file reads a QR-code image instead of uploading its path - #328
Conversation
The QR branch handed the path string to from_content, so the upload body was the text of the path and the server failed the task as an unrecognised image. Read it with from_path, as submit does. Also point refang.py's docstring at its spec section instead of repeating it, and say the case-table pin guards only its own copy.
|
The fix is correct. The
|
A respx test on both clients asserts the S3 PUT body is the image and the create body names its unrefanged basename; the spy-based tests could not see the uploaded body. Also fix the two spec sentences that still described the path being passed on as content.
|
Both addressed in 35844b1 (and 6c50e82, import order):
|
|
LGTM. Checked against AGENTS.md and specs/02–05: |
|
No issues found against AGENTS.md or specs/. The |
SummaryLets an analyst paste an indicator from a threat-intel report ( Severity: 0 HIGH · 2 MODERATE · 1 LOW — none of them in this repo. Prior feedback: all 29 points checked and addressed.
Fixes are proposed, not applied; nothing was run. Cross-repo coordinationSet: polyswarm-api#327 merged · SDK (reference) — polyswarm-cli#274 merged · CLI — polyswarm-api#328 open · SDK review fixes ← you are here — the web UI's PR (private repo) open · UI Merge order: Coherence: the fixes are independent, and none touches this repo. Findings (round 1)No defects found in this repo's diff. It resolves everything the SDK's earlier rounds left open on #327: the QR-code elsewhere: F1, F2, F3 → the web UI's PR (private repo) Standards conformityChange-level: no violations introduced by this diff. |
|
Thanks, Sam. Nothing is open for this repo, per your round-1 verdict. For the set: F1, F2 and F3, which you routed to the web UI's PR, are fixed there with tests that were red before the fix:
This PR is unchanged at 6c50e82, and CI is green. |
What
Follow-up to #327 (IoC refanging), addressing its review before 4.6.0 is released.
sandbox_filenow reads a QR-code image instead of uploading its path. Withartifact_type=URLandpreprocessing={'type': 'qrcode'}, the URL branch handed the path string toLocalArtifact.from_content. That made the upload body the UTF-8 text of the path, so the server created the sandbox task and then failed it as "Image format not recognized", even for a valid image. The branch now reads the file withLocalArtifact.from_path, assubmit's QR branch already does, and still never refangs it.from_contentcall predates refanging (3.9.0). feat: refang defanged IoC inputs before building requests #327 only added the guard around it, and its tests pinned the path-as-body behaviour. Those tests now spy onfrom_pathand also assert that nothing is uploaded as text.submit, and a missing path fails before any task is created.from_handlebranch and is unaffected.refang_iocsmakes no difference either way.refang.py's module docstring now points to its spec instead of repeating it. It keeps only the portability paragraph, which describes how the patterns are written, and namesspecs/05-downstream-contract.md§"IoC refanging" for what the contract is, why clients refang, where it is applied and what is out of scope.Compatibility
No public surface changes and no version bump.
developalready declares the unreleased4.6.0, and this lands before that release. The CLI is unaffected: it never callssandbox_filefor QR codes (sandbox url --qrcode-filegoes throughsandbox_url).Tests
test/sandbox_file_qrcode_respx_test.py: a dual-transport respx test that writes real bytes to a file namedqr[.]png, submits it with refanging on, and asserts the S3 PUT body is exactly those bytes and the create body'sartifact_nameis the unrefanged basename. Against the previous code it fails with the upload body being the text of the path. It uses the respx tier because the e2e stack's sandbox providers can't reasonably process a QR image.sandbox_filetests now expectfrom_path. On their own they cannot see the uploaded body; the respx test covers that.test/_client_harness.pygains a publicrequestsaccessor (every request, in order) for multi-request flows.03-endpointssays the image is read withfrom_path(body = image bytes, default name = basename), and02-resourcesnotes the QR exception onfrom_content.