對話摘要 2026-08-18


description: 4 note(s) today. name: ‘2026-08-18’

2026-08-18 每日安全審查

結果:基本正常,4 個低風險注意項(已推 Telegram 619760664)

✅ 正常

  • QwenPaw 2.1.0(最新 stable;RCE issue #4470 已 closed,唔受影響)
  • Patches 完整:secret_redaction.py、task_tracker.py last_event_at、mcp.py whitelist、progressive_disclosure.py 全部存在
  • audit.db 24H:0 deny(4 條 sandbox_fallback 係 config 正常行為)
  • cryptography 48.0.1(GHSA-537c 已 patch;CVE-2026-69248/69249/69247 ≤48.0.0 唔受影響)
  • fail2ban active、dnf-automatic enabled
  • 容器:68 running 無 restarting/unhealthy;無 privileged container;無新 Web port 映射(3x-ui 443 已知)
  • CF Tunnel healthy(4 conn,client 2026.8.1 pin 啱);Access 全 Authentik IdP(0abce3f9);DNS 無可疑新 record(benhoweb.com 全已知;shinggo.xyz 403 權限唔夠)
  • 依賴:fastmcp 3.4.7(升咗)、olw/synto 0.7.0、alist lrcfix-20260805、crawl4ai 0.9.2

⚠️ 注意項(已知/低風險)

  1. Sandbox 關閉:agent.json sandbox_enabled=false + /sys/kernel/security/lsm 唔存在(容器限制)。tool_guard/file_guard 仍生效,qwenpaw 無對外暴露。如日後要嚴格隔離可喺 host 開 Landlock。
  2. 3x-ui 443 映射 host:3x-ui 運行中(用戶可能重啟),違反「禁 Web Port 映射 Host」政策——已知,記低。
  3. Syncthing 22000/tcp+udp、21027/udp 暴露 host(用戶部署 08-16)——非 web port,低風險。
  4. 受限檢查:firewall-cmd(polkit 需 root)同 /etc/ssh/sshd_config(600 root)讀唔到,未能直接確認 PasswordAuthentication=no;建議用戶間中手動確認。

建議總結

  • 整體安全、端到端驗證;無急迫行動。
  • 例行:確認 SSH PasswordAuthentication=no;考慮日後開 Landlock sandbox。
  • memory/2026-08-18/daily-ops-notes.md name: daily-ops-notes description: 2026-08-18 ops 日記:①Hindsight consolidation 卡死修復(op 4004ba24 卡 llm.litellm.consolidation attempt 2/4,根因=opencode free chain 429 fallback + HINDSIGHT_API_LLM_TIMEOUT=600 死等;改 env rows 616/611/613/612 → azure-gpt-4o + timeout 180s,facts 1142→1192,新 op 74851e0c 46s 完成)+ 三層防護(源頭 Azure、n8n Hindsight Ops Watchdog n3zTSYiumWkxQjAx 每 10 分鐘查 operations、processing>8min/pending>15min→Telegram,execution 14901 success;MEMORY.md 記 recover API)。②n8n_shinggo_bot /start 冇 handler 屬正常(只有 /backup 已停用 xZoe37YVEo0fyTTz inactive),TeamChat 插件未定案。③Meta Muse Spark 接入 LiteLLM:真實 endpoint=api.meta.ai/v1(OpenAI 兼容,dev 頁面登入保護),Infisical 存 META_MUSE_API_KEY,LiteLLM 建 meta/muse-spark-{1.1,1.2,1.2-contributor}(model_id d125e0a3/5306c5f1/41a8d136,建後要補 api_base 否則路由去 OpenAI),E2E 通過回覆「Hi there」;reasoning model 要用 max_completion_tokens(~550 tokens 先出 content)。④Meta Muse contributor virtual key 完成:*** 只限 meta/muse-spark-1.2-contributor、無限 budget、永不過期、E2E 回覆 OK;已存 Infisical LITELLM_KEY_meta-muse-contributor;首條 fastmcp 生成 key 被 secret redaction 食 plaintext 已棄用。⑤Meta Muse Pricing/Rate limits 研究:Standard 4.25 per M(cached 0.10/0.002,Meta 會拎 prompt/output 訓練;輸入平 12.5x 輸出平 21x);rate limits per team Standard 3000RPM/4M TPM、Contributor 100RPM/3M TPM(background 600/min 另計,超額 429 建議 exponential backoff+jitter,header x-ratelimit-* 睇餘額);冇 long-context premium;web search grounding 0.15/$0.002;steering context 免費;contributor key 唔好放敏感/production data,要量產轉 META_MUSE_API_KEY。⑥Meta Muse fallback 配置完成(先前待決定已定案:預設 contributor、撞 limit fallback deepseek first):router fallbacks 加 meta/muse-spark-{1.1,1.2,1.2-contributor} → deepseek-first(/config/update,host 直打 API,litellm 容器冇 curl;原有 chain vision-first/free-first/azure-gpt-4o/opencode 全保留),router settings 驗證生效,MEMORY.md 同步;運作=任何 consumer(含 contributor key)撞 429/rate limit 自動落 deepseek-first(DeepSeek V4 Flash)唔會 fail;提醒 contributor tier prompt/output 會俾 Meta 訓練,fallback 解決唔到,敏感數據用 standard 或唔用,Contributor RPM 100/min 對一般 agent 流量夠用。
  • memory/2026-08-18/memory-slimming-archive-20260818.md
  • memory/2026-08-18/opencli-research.md name: opencli-research description: 研究報告:GitHub 項目 OpenCLI(jackwener/opencli)—— 將任意網站/Electron App 變成 CLI 並畀 AI Agent 透過已登入 Chrome 操作網頁。記錄核心架構(CLI+Browser Bridge 擴充+daemon/CDP)、三層功能(100+ adapters / browser 原語 / CLI hub)、生態(6 技能包+plugin)、局限,以及同本環境(agent-reach、browserless+browser_use、QwenPaw browser skill)嘅對比結論同待辦(主機實測)。Apache-2.0、28.3k stars、npm @jackwener/opencli v1.8.6。
  • memory/2026-08-18/sandbox-bubblewrap-status.md name: sandbox-bubblewrap-status description: 2026-08-18 系統運維記錄:① 清 build cache 6.45G→2.89G 釋放 3.5G,磁碟 77%→75%(剩 47G);② 用戶懷疑 sandbox 關閉,實測證實其實已啟用(config.json line 1029 sandbox_enabled=true、mode=BUBBLEWRAP、log 有 sandbox_fallback=bubblewrap 決策),Landlock 無需開啟(bwrap 靠 user+mount namespace 不靠 LSM,比 Landlock 強),決定保持現狀零動作;③ MEMORY.md「ARM64 / 安全」政策「禁 Web Port 映射 Host」新增特例:3x-ui 443 映射 host(vless 要用)。