One useful idea
A filename, extension or supplied Content-Length is not a measurement. Acquire into an exclusive NEW owned directory; retain at most the configured byte limit and read at most one extra byte to detect oversize. Refused input stays quarantined with a controlled reason. Unexpected bugs remain visible and can leave a partial new folder: no overwrite, automatic deletion or false success receipt.
The exact MIME policy permits audio/wav or video/mp4, with matching RIFF/WAVE or accepted MP4 ftyp signatures. Then the trusted explicit FFprobe executable reads the retained file and returns a positive finite duration. The code bounds inspection output and kills/awaits an owned timed-out child. Signature, container duration and hash parity do not prove complete playback, malware absence, ownership, privacy or safe decoder behavior. Accepted is still quarantined, not published.
For HTTPS, validate exact allowed host before DNS, check every resolved address and connect directly to a validated numeric address. Keep the original Host/SNI and certificate verification; do not disable TLS, follow redirects, use proxies or resolve the host again at connect time. The key is never sent. Recheck fresh DNS on each acquisition; a prior safe result is not permanent authority. Private, mapped and transition addresses are refused.
Headers must satisfy the narrow transport contract: no content/transfer encoding, duplicates or malformed length. Measure actual EOF rather than trusting Content-Length. Blocking DNS/connect/header work and body reads are not a hard whole-operation deadline; a body budget can overshoot by one blocking read. This owned local exercise is not a safe public upload service. Reviewed file/header/address/transport/inspection helpers are disclosed; your practice source and acquisition orchestration must not call the finished boundary.
Refresh first: Explicit limits, Owned output and read-back.
Trace a finished example
import hashlib, os
from pathlib import Path
from tempfile import TemporaryDirectory
from operation_tools import Settings, acquire_upload
from operation_tools.inspection import FfprobeInspector
# Set DVP_FFPROBE to an absolute executable you installed and trust.
inspector = FfprobeInspector(Path(os.environ["DVP_FFPROBE"]))
settings = Settings("fixture-only-not-a-provider-key",
("media.example.invalid",))
# Only this example-owned temporary directory is removed on exit.
with TemporaryDirectory(prefix="dvp-acquisition-example-") as owned:
with Path("fixtures/one-second.wav").open("rb") as reader:
result = acquire_upload(reader, "audio/wav", Path(owned) / "new-input",
settings, inspector=inspector)
print(result.disposition, result.media.kind, result.media.duration_seconds)
print(result.received_bytes,
hashlib.sha256(result.path.read_bytes()).hexdigest() == result.sha256)
print((result.path.parent / "receipt.json").is_file())Expected output
accepted wav 1.0
16078 True
TrueThis measures the included playable WAV with an actual trusted FFprobe, writes owned payload and receipt, then compares retained bytes with the write-time hash. It uses no network and no fake inspector. Temporary cleanup applies only to this explicitly owned example; normal demo outputs stay local for review.
The finished implementation is in operation_tools/acquisition.py. Reading it is guided practice, not independent evidence.
Predict oversize
The declared length is small, but actual bytes exceed the limit. What should happen?
Compare your answer · self-reviewed
Stop after measuring the extra byte, retain only the bounded prefix and quarantine with byte_limit. Never trust the header as the byte measurement or drain unlimited input.
Find the SSRF bug
The first DNS address is public and the second is private. Can you connect to the first?
Compare your answer · self-reviewed
No. Refuse the mixed answer before connection. Validate every fresh answer, pin the reviewed numeric address and preserve certificate hostname verification.
Explain acceptance
A matching signature and one-second duration pass. May the file be published automatically?
Compare your answer · self-reviewed
No. Accepted remains quarantined. Those observations do not establish full decoding, malware safety, rights, privacy or authenticity.
Change it, then build your own
One controlled change
Acquire the included MP4 into another NEW directory with video/mp4. Then try the WAV under video/mp4 and a byte ceiling below its actual size. Predict the controlled refusal. Keep retained evidence; do not reuse or clear a failed directory to make the run look clean.
Your independent task
Implement prepare_source, acquire_upload and acquire_url in practice.py. Use disclosed parser/address/path/header/hash/inspection helpers while owning allowlist-before-resolution, fresh all-address checks, actual bounded reads, exact MIME/signature, inspection and ordered receipt/refusal behavior. HTTPS transport is supplied assistance, not your socket implementation. Do not call finished acquisition functions or use fake media judgments.
What success looks like
The build3 group passes adversarial policy and measured-acquisition seams. Separately your actual trusted FFprobe demo accepts included valid media and refuses a changed limit/MIME, retaining NEW owned evidence. Passing seam tests alone does not prove external downloads or full decoding.
Hint 1 · a question
Order the boundaries: configuration, owned path, source policy, headers/bytes, signature, actual inspection, read-back and receipt. Which refusal leaves retained bytes?
Hint 2 · a concept cue
Request at most remaining+1 bytes; store only the remaining prefix. Validate all resolved addresses before a transport effect, with no unchecked second DNS lookup.
Hint 3 · a localized example
Compare the retained file before and after trusted inspection. A write-time prefix hash on a refused or changed file is not a certificate of current complete-file parity.
Need the complete worked solution?
Open operation_tools/acquisition.py from the kit. Trace it, close it, then try fresh inputs in your own files. Treat the attempt as guided; seeing the solution does not award a practical pass.
Course help is guidance, not independent evidence. With JavaScript, opening help records guidance locally; otherwise note it in your README. Reset does not erase that history.
Repair a failed check
If the example cannot launch FFprobe, correct the explicit trusted absolute path; do not silently search PATH or install a substitute. If a used directory fails, choose a NEW path and keep previous evidence. If length lies pass, read actual EOF and compare measurement. If refused content reports acceptance, trace exact expected exceptions; bugs must not be caught as success.
NotImplementedError means a practice stub is still unfinished. Read the failing test name and the last error line. Change one behavior, rerun that build, then rerun all implemented builds.
Show it works on new inputs
Use the second included media kind, a changed byte ceiling and a fresh invented URL policy case with controlled DNS. Retain your actual commands, disposition/reason, measured bytes and helper disclosure. Explain why these local checks do not authorize production uploads, public network access or publication.
Self-review: name the input, result, refused case and reason. Your local test output and explanation are separate from a quiz score; this page does not certify a pass.
Keep the idea
Measure what actually arrived, retain evidence and separate quarantine acceptance from permission to publish. Narrow bounds are useful only when their limits stay explicit.