Add timeout and retry to the developer mode probe. After a keep-alive
timeout, paho auto-reconnects but the session can be half-broken: the
printer sends status but ignores commands. The probe had no recovery —
one unanswered probe permanently blocked retries. Now times out after
10s with one retry; two consecutive failures force-close the socket for
a clean reconnect.
Skip AMS remain% weight sync in on_ams_change while a print session is
active. The MQTT FINISH message triggers both the AMS weight sync (SET
from remain%) and the usage tracker (ADD from 3MF data) in the same
event loop cycle, causing double deduction. The active-session check is
snapshotted before any await to prevent a race with on_print_complete
popping the session during interleaved execution.
Camera snapshot, test, and plate detection endpoints created temporary
JPEG files with default 0644 permissions. Switch from NamedTemporaryFile
to mkstemp with explicit 0600 permissions.
Set X-Content-Type-Options, X-Frame-Options, and Referrer-Policy on all
responses. CSP omitted (React inline styles would require unsafe-inline,
negating protection). HSTS omitted (LAN app commonly accessed over HTTP).
An API key with printer_ids=[] was treated the same as null (global
access) due to a falsy check. Now None means global access and []
means no printer access. Added a startup migration to normalize any
existing [] rows to NULL so they retain their intended global access.
Also fixed the webhook /queue endpoint which used the same falsy
check, allowing []-scoped keys to see all printers.
The bug report endpoints (start-logging, stop-logging, submit) had no
authentication, allowing anyone on the network to enable debug logging,
retrieve sanitized system logs, and trigger bug report submissions when
auth was enabled. All three now require permission when auth is enabled:
start-logging requires settings:update, stop-logging and submit require
settings:read. Endpoints remain open when auth is disabled (default).
Archive upload endpoints used the client-supplied filename directly
in file paths, allowing an authenticated attacker to write files
outside the intended directory (e.g. ../../evil.3mf bypasses the
.3mf extension check). Added _safe_filename() helper that normalizes
backslashes and extracts the basename before constructing paths.
Stream tokens are stored in-memory and lost on restart. The frontend
cached the old token for up to 50 minutes (staleTime) and never
refetched, so all thumbnail/stream requests failed with 401 until
a manual page reload.
Added a global error listener in useStreamTokenSync that detects
when img/video elements fail to load with the current stream token
and automatically invalidates the camera-stream-token query to
fetch a fresh one. Debounced with a 5s cooldown to avoid spamming
when many images fail at once.
The touchscreen display blanked right after boot, requiring a touch
to wake. Two issues: no consoleblank=0 in cmdline.txt (kernel blanks
the console during Plymouth→labwc transition), and the wlr-randr
anti-blank loop slept 60s before its first run.
- Add consoleblank=0 to kernel cmdline in install.sh
- Move sleep after wlr-randr in labwc autostart so it fires immediately
New SJF toggle badge on the queue page. When enabled, the scheduler
picks shorter print jobs before longer ones instead of FIFO. A
starvation guard flags jobs that get skipped once, moving them to
the front on the next cycle so long jobs can't be postponed indefinitely.
- Add print_time_seconds and been_jumped columns to PrintQueueItem
- Cache print duration from 3MF metadata at queue item creation
- SJF query: printer_id, target_model, been_jumped DESC, print_time_seconds ASC, position
- Mark jumped items in-memory after each print start
- Toggle badge on queue page header with live state indicator
- Frontend auto-sorts to match scheduler order when SJF enabled
- Settings schema, boolean parsing, and migration (SQLite + PostgreSQL)
- i18n badge keys for all 7 locales
- 10 integration tests for SJF ordering and starvation logic
- Wiki, website, README, and changelog updated
Move H2S from the drying-unsupported blocklist to the firmware-gated
list, requiring minimum firmware 01.02.00.00 (released end of March
2026). Both remote AMS drying and queue auto-drying now work on H2S.
Printer cards and stream overlay now display the plate number when
printing plate 2+ of a multi-plate 3MF (e.g. "MyModel — Plate 3").
Queue items using model-based assignment ("Any P1S") now show the
actual assigned printer name once the scheduler picks a printer,
instead of continuing to show the generic target.
Display the active database backend (SQLite or PostgreSQL) and its
version in the Database section of the System Info page. SQLite queries
sqlite_version(), PostgreSQL queries SELECT version() and
pg_database_size(). Helps users verify which database is in use.
The "Clear Plate & Start Next" button on printer cards appeared
even when "Require plate-clear confirmation" was disabled in
Settings. The backend correctly auto-dispatched without waiting,
but the frontend widget always showed the prompt. Thread the
require_plate_clear setting through PrinterCard → PrinterQueueWidget
so the widget shows a passive queue link when the setting is off.
Bambuddy can now use an external PostgreSQL database via the
DATABASE_URL environment variable. SQLite remains the default.
Dialect-aware helpers handle upserts, PRAGMAs, FTS (FTS5 vs
tsvector+GIN), backup/restore, and health checks. All migration
blocks use savepoints to prevent Postgres transaction poisoning.
Backups are always portable SQLite format regardless of backend.
Cross-database restore imports SQLite backups into PostgreSQL
with automatic boolean/datetime conversion, NOT NULL default
filling, and FK constraint handling.
REST/Webhook smart plugs can now fetch power and energy data from
individual URLs instead of requiring all values in a single status
response. Each value falls back to the shared Status URL when no
separate URL is set, preserving backward compatibility. Added power
and energy multipliers for unit conversion (e.g. 0.001 for Wh→kWh).
Race condition in _update_state: dev mode probe released GIL via MQTT
publish between raw_data overwrite and vt_tray list restoration, letting
the event loop iterate over raw dict keys (strings) instead of spool
dicts. Affects A1, P1, and X1Plus firmware that don't send the fun field.
Fix: normalize vt_tray dict→list before raw_data assignment, restore
preserved fields before any GIL-releasing work, add defensive guard in
printer_state_to_dict.
The test conftest.py model import list was out of sync with database.py,
missing slot_preset, project_bom, spool_k_profile, and spoolbuddy_device.
Base.metadata.create_all() never created those tables in the test DB.
The bottom message bar showed stale warnings from the previous printer
after switching via dropdown or swipe. Cached AMS data was shared across
all printers in a single ref, so switching to a printer whose status
hadn't loaded fell back to the wrong printer's data. The Layout also
unconditionally cleared alerts set by child pages. Fixed by keying the
AMS cache per printer ID and only clearing Layout-owned alerts.
The periodic cleanup of old AMS sensor history entries (every ~24h)
failed with "can't compare offset-naive and offset-aware datetimes".
The cutoff used datetime.now(timezone.utc) but recorded_at stores
naive datetimes via SQLite's func.now(). Use utcnow() instead.
Replace polling-based bed cooldown monitor with event-driven approach.
Some firmware stops sending bed_temper after print completion, causing
the 30-min polling loop to time out on stale cached values. Now reacts
instantly to bed_temper MQTT data via a new on_bed_temp_update callback.
Thread event_type and template variables through the webhook call chain so
all generic webhook payloads include an "event" field and event-specific
data (printer, filename, duration, etc.) as top-level JSON fields. Existing
title/message/timestamp/source fields are unchanged. Slack format unaffected.
GitHub backup can now optionally include spool inventory (with usage
history) and print archive metadata as JSON. Both toggles are off by
default. No binary files (gcode/3MF) are included.
Single-nozzle printers (X1C, P1S, A1) report tray_now=254 for external
spool, but BambuStudio sends ams_id=255 (VIRTUAL_TRAY_MAIN_ID) in the
print command's ams_mapping2 field. Bambuddy was passing 254 as-is,
causing firmware to target AMS tray 0 instead of external spool —
resulting in 07FF_8012 "Failed to get AMS mapping table" or prints stuck
at heatbed heating when an AMS is connected but empty.
Map external spool to ams_id=255 for all non-H2D printers. H2D
dual-nozzle printers retain 254 (deputy) / 255 (main) distinction.
When multiple AMS spools match the same type/color criteria, an optional
setting now prefers the spool with the lowest remaining filament. This
helps consume partial spools before starting new ones. Sorting applies
to all matching paths: queue scheduler, print modal, and multi-printer
mapping. Unknown remain values (-1) sort to end.
Select multiple printer cards and apply bulk actions (stop, pause,
resume, clear notifications, clear bed) from a floating toolbar.
Selection shortcuts: Select All, Select by State (printing/paused/
finished/idle/error/offline), Select by Location. Action buttons are
smart-enabled based on selected printers' current states. Confirmation
modals for destructive actions. The status summary bar now shows all
printer states.
Admins can now filter the Statistics page by user via a new
stats:filter_by_user permission. A user dropdown appears in the stats
header showing all users plus "No User (System)" for prints without
attribution. The filter applies to all stats widgets, failure analysis,
and CSV/Excel exports. Backend validates the permission on all 4 stats
endpoints, returning 403 if the filter is used without authorization.
Stagger option now available when printing directly to multiple printers,
not just in queue mode. Prints are automatically queued with staggered
start times using group size/interval from Settings. New "Require
plate-clear confirmation" setting lets farm users disable per-printer
plate confirmations so queued prints start automatically on finished
printers.
Also fixes settings API type parsing for require_plate_clear (boolean),
stagger_group_size and stagger_interval_minutes (integer) — without this,
saved values returned as strings would cause the settings toggle to
always show enabled and trigger a permanent save loop.
Printers with no AMS hardware (P1S/P1P with only external spool)
rejected print commands with "Failed to get AMS mapping table"
because use_ams was always sent as true. Now auto-sets use_ams=false
when all filament slots map to external spools or are unmapped.
H2D-series excluded since they use use_ams for nozzle routing.
scan_external_folder stored raw 3MF metadata containing _thumbnail_data
bytes directly in the JSON column, causing a serialization error. Applied
the same clean_metadata() pattern used by upload/zip extraction and
removed the call to the non-existent parser.extract_thumbnail().
The archives page only fetched the 50 most recent prints due to a
hardcoded API limit default. Added client-side pagination with
configurable page sizes (25/50/100/200/All) and bumped the fetch
limit to return all archives. Page size is persisted to localStorage.
Queue page redesign: compact stats bar replaces summary cards, color-
coded left borders for status scanning, collapsible history with
condensed rows, and a new production schedule timeline view (#823)
showing estimated completion times grouped by hour with filter tabs
and day navigation. i18n keys added for all 7 languages.
Fix plate thumbnails returning 401 in print modal when auth is enabled
(missing stream token). Fix schedule calendar picker opening off-screen
(hidden input positioned with sr-only instead of near the date field).
on_print_complete returned early when no archive_id was found (auto-
archive off), skipping both internal inventory tracking (AMS remain%
deltas) and Spoolman usage reporting. Moved the filament usage tracking
block to run before the archive_id early-return so consumption is
always recorded regardless of the auto-archive setting.