[Fix] Virtual Printer proxy: transparent TCP for X1C/X1 compatibility (#757)

The closed-source bambu_networking DLL validates TLS connection parameters
  and rejects connections where the certificate doesn't match the printer's
  real BBL CA certificate. The TLS-terminating proxy presented Bambuddy's
  own certificate, causing X1C/X1 prints to silently fail after verify_job.

  Switch to transparent TCP proxying for FTP, FileTransfer, Camera, and FTP
  data — only MQTT remains TLS-terminated (required for IP rewriting). The
  slicer now gets end-to-end TLS directly with the printer's real certificate.

  Changes:
  - SlicerProxyManager uses TCPProxy for FTP (990), FileTransfer (6000),
    Camera (322), and pre-listens on FTP data ports (50000-50100)
  - Only MQTT (8883) uses TLSProxy for IP rewriting
  - Remove debug logging from MQTT and FTP proxy code
  - Fix install.sh missing AmbientCapabilities=CAP_NET_BIND_SERVICE
  - Update module docstring, migration docs, README proxy description
  - Add tests verifying transparent proxy architecture
This commit is contained in:
maziggy
2026-03-19 15:43:11 +01:00
parent 94134e1861
commit 332a7c6ac8
6 changed files with 340 additions and 80 deletions
+2 -2
View File
@@ -22,8 +22,8 @@ Proxy mode now requires two additional ports:
| Port | Protocol | Purpose |
|------|----------|---------|
| 6000 | TCP/TLS | File transfer tunnel (verify_job + print uploads) |
| 322 | TCP/TLS | RTSP camera streaming (X1/H2/P2 series) |
| 6000 | TCP | File transfer tunnel (transparent proxy, end-to-end TLS) |
| 322 | TCP | RTSP camera streaming (transparent proxy, end-to-end TLS) |
These ports are proxied automatically — no iptables rules needed. If you have
a firewall, ensure these ports are open between the slicer and Bambuddy.