feat: normalize temperature sources and add Linux disk support - #4
Conversation
Introduce a shared validate, collect, and adjust contract for every temperature provider. Add smartctl-based Linux disk readings and SSH-based remote NVIDIA GPU readings so heterogeneous sensors can feed one decision chain. Update container dependencies, Compose guidance, TUI settings, tests, and bilingual operations documentation, including the TrueNAS CD6 deployment path.
|
@Catalina-df |
Review: changes requested[P1] Reject path traversal in
source src/FanControlWithEsxiSmart.sh
OPERATION_MODE=auto TEMPERATURE_SOURCES=linux_disk DRY_RUN=true \
IDRAC_IP=10.0.0.10 IDRAC_ID=root IDRAC_PASSWORD=x \
LINUX_DISK_DEVICES=/dev/../etc/passwd \
validate_config auto
# exits 0Please reject any path containing The PR test suite passes in a clean checkout ( |
|
In reply to #4 (comment): Catalina 將先核對 PR 的實際 diff、測試結果與觸發留言脈絡,再按 review 規則只回報可重現的缺陷、風險與測試缺口;確認完成後會把結論直接回覆到該 PR thread。 目前已確認 PR 只有一個提交,核心變更集中在控制器、TUI、測試與容器設定。接下來會逐段核對 shell 的實際執行路徑,尤其是 smartctl/jq 的錯誤碼處理、SSH 參數與相容性分支;PR 描述本身不能替代程式行為驗證。 測試在乾淨的 PR clone 中通過 53 個核心與 14 個 TUI assertion;本機沒有安裝 ShellCheck,因此 CI 的 ShellCheck 結果只能作為外部已報告狀態,不能冒充本次本機執行。現階段未見介面分派或多目標保留有效讀值的明顯回歸,正在補查邊界條件與既有來源的相容性。 已找到一項可重現的安全性缺陷: 交叉 review agent因其環境無法取得 PR 原始碼,沒有新增可用證據;實際 clone 與重現結果仍以本次檢查為準。結論是保留一項需修正的 finding,並附上精確行號與重現命令,再直接貼回 PR 的 issue-comment thread。 Catalina 已完成 PR #4 的 review,並將結論回覆至原 PR thread。 發現一項需修正的安全性問題: P1: src/FanControlWithEsxiSmart.sh:787 的正則只檢查 LINUX_DISK_DEVICES=/dev/../etc/passwd validate_config auto
# exit 0這違反 PR 描述中「拒絕 unsafe 或 relative device paths」的行為承諾,並可能讓 驗證結果:乾淨 checkout 中核心測試 |
Reject dot and empty path components before invoking smartctl while preserving nested /dev paths such as disk/by-id. Add regression coverage and document the accepted path shape.
|
@Catalina-df 已修正,謝謝指出這個 traversal 問題。 修正內容:
修正 commit: 驗證:
|
|
@Catalina-df |
|
已重新核對修正提交 驗證結果:
Final review:APPROVED。未發現其他 blocking finding。 |
|
In reply to #4 (comment): Catalina 低頭核對修正提交與 PR thread 的實際內容,會以目前分支上的程式與可重現驗證為準,確認 traversal 修補是否完整後,再把最終 review 結論直接回覆到該留言串。 修正提交已確認已進入 PR head,且原先的 finding 確實有對應 regression test。Catalina 正在檢查驗證函式的實際語意與所有呼叫點,特別是空元件、尾端斜線、巢狀 實際 checkout 的測試通過 55 個 core assertions,較留言所載的 54 多一項;修正後的 helper 會拒絕 parent/current/空 path component、尾端斜線與雙斜線,同時保留 所有本機可執行驗證均已通過:Bash syntax、core 55 assertions、TUI 14 assertions 與 GitHub API 建立留言回傳 404,現有讀取權限正常,較像目前 CLI token 對該 endpoint 的寫入路由限制;我會改用 Catalina 已完成修正後的核對,並將最終結論回覆至 PR #4: Final review:APPROVED 原先的 P1 path traversal finding 已由 驗證結果:
留言已發布:Final review comment |
|
In reply to #4 (comment): Error: Type validation failed: Value: {"query":"skills.list skills.brief coding-agent df-meta-mcp","queryType":"ranked","matches":[{"name":"mcp_df_meta_mcp_context7_query_docs","stableId":"["lilac.catalog-tool",1,"mcp","df-meta-mcp","context7__query-docs"]","source":"mcp","sourceId":"df-meta-mcp","rawName":"context7__query-docs"},{"name":"mcp_df_meta_mcp_context7_resolve_library_id","stableId":"["lilac.catalog-tool",1,"mcp","df-meta-mcp","context7__resolve-library-id"]","source":"mcp","sourceId":"df-meta-mcp","rawName":"context7__resolve-library-id"},{"name":"mcp_df_meta_mcp_deepwiki_ask_question","stableId":"["lilac.catalog-tool",1,"mcp","df-meta-mcp","deepwiki__ask_question"]","source":"mcp","sourceId":"df-meta-mcp","rawName":"deepwiki__ask_question"},{"name":"mcp_df_meta_mcp_deepwiki_read_wiki_contents","stableId":"["lilac.catalog-tool",1,"mcp","df-meta-mcp","deepwiki__read_wiki_contents"]","source":"mcp","sourceId":"df-meta-mcp","rawName":"deepwiki__read_wiki_contents"},{"name":"mcp_df_meta_mcp_deepwiki_read_wiki_structure","stableId":"["lilac.catalog-tool",1,"mcp","df-meta-mcp","deepwiki__read_wiki_structure"]","source":"mcp","sourceId":"df-meta-mcp","rawName":"deepwiki__read_wiki_structure"}]}. |
Summary
This PR makes temperature providers use one extensible interface and adds the sources needed for the planned TrueNAS deployment:
validate,collect, andadjustmethods;Motivation
The controller previously handled
esxi,idrac, andgputhrough source-specific branches, including a GPU-only adjustment inside the decision code. Adding another provider required editing validation, collection, diagnostics, and temperature adjustment separately.The target deployment runs on TrueNAS and needs to combine a Kioxia CD6 temperature with GPU temperatures from other VMs. The new source contract keeps that decision chain generic: each provider returns labeled readings, owns its adjustment, and feeds the existing highest-temperature and hysteresis logic.
Source interface
Registered providers implement:
Collection records use a common tab-separated schema:
The registry is an allowlist, and validation rejects incomplete providers.
collect_temperature_readingsanddiagnose_modenow dispatch through the interface instead of branching on source IDs. The decision function also delegates offsets throughadjust, so it no longer contains a GPU special case.Existing
esxi,idrac, and localgpubehavior remains available.WITH_GPU_TEMPand the defaultTEMPERATURE_SOURCES=esxiare preserved for compatibility.New
linux_disksourceConfiguration:
Behavior:
smartctl -n <mode> -A -j;jq;LINUX_DISK_NOCHECK=standbyto avoid waking sleeping SATA/SAS disks;The image now includes
smartmontoolsandjq. Compose documentation maps only explicitly selected devices rather than granting broad privileged access.New
remote_gpusourceConfiguration:
The source executes one fixed read-only command on each host:
It labels readings as
<host>/gpu<index>, supports SSH key or password authentication, and shares the credential-safe SSH transport used by ESXi. Passwords stay inSSHPASSinstead of process arguments.TrueNAS deployment validation
The investigation was read-only.
/dev/nvme1linux_disk nvme1 6969 linux_disk:nvme1=69CTrueNAS currently exposes no local NVIDIA GPU and no TrueNAS-managed VM, so
remote_gpuwas verified with multi-host test fixtures but not against the eventual GPU VMs. Those hosts and their monitoring SSH key must be supplied before deployment.Recommended deployment shape:
Safety and failure behavior
diagnoseremains read-only and does not send fan commands.Tests and checks
git diff --checkA Docker image build was not run because the development machine has no Docker engine, and the TrueNAS investigation was intentionally read-only.
Documentation
Updated:
.env.exampleREADME.mdREADME.zh-TW.mdUSAGE_GUIDE.mddocs/TEMPERATURE_SOURCES.mddocs/TROUBLESHOOTING.md