Commit Graph
11 Commits
Author SHA1 Message Date
maziggy fb1e9a917e fix(install): use ProtectHome=read-only for /home-rooted installs (#1685)
bambuddy.service shipped with ProtectHome=true, which makes /home/* invisible
  to the service namespace. Installing into /home/bambuddy/ (instead of the
  default /opt/bambuddy/) made ExecStart=/home/bambuddy/venv/bin/uvicorn fail
  with status=203/EXEC because systemd couldn't resolve the binary path.
  ReadWritePaths=$INSTALL_PATH does not reliably re-expose /home/* subpaths for
  exec resolution.

  install/install.sh now detects /home/* INSTALL_PATH and emits ProtectHome=read-only;
  default /opt/bambuddy installs keep ProtectHome=true. The manual deploy template
  defaults to read-only with a comment on when to tighten it.

  read-only keeps /home immutable to the service - no security regression, since
  ReadWritePaths still gates writes to the install/data/log dirs only.
2026-06-09 07:31:23 +02:00
maziggy 6a426c74d5 Updated install/install.sh 2026-04-24 10:37:38 +02:00
maziggy 37231d9991 Updated install/install.sh 2026-04-24 10:34:23 +02:00
maziggy a36a0e09eb Fix daily beta release contributors list and add VP ports 2024-2026 to docker-compose
Strip @mentions from changelog text in docker-publish-daily-beta.sh
  so GitHub doesn't auto-generate a "Contributors" section in release
  notes. Add --generate-notes=false for extra safety. Also add ports
  2024-2026 (A1/P1S proprietary) to the docker-compose.yml bridge-mode
  port mapping and update the install script comment.
2026-03-25 16:47:27 +01:00
maziggy 332a7c6ac8 [Fix] Virtual Printer proxy: transparent TCP for X1C/X1 compatibility (#757)
The closed-source bambu_networking DLL validates TLS connection parameters
  and rejects connections where the certificate doesn't match the printer's
  real BBL CA certificate. The TLS-terminating proxy presented Bambuddy's
  own certificate, causing X1C/X1 prints to silently fail after verify_job.

  Switch to transparent TCP proxying for FTP, FileTransfer, Camera, and FTP
  data — only MQTT remains TLS-terminated (required for IP rewriting). The
  slicer now gets end-to-end TLS directly with the printer's real certificate.

  Changes:
  - SlicerProxyManager uses TCPProxy for FTP (990), FileTransfer (6000),
    Camera (322), and pre-listens on FTP data ports (50000-50100)
  - Only MQTT (8883) uses TLSProxy for IP rewriting
  - Remove debug logging from MQTT and FTP proxy code
  - Fix install.sh missing AmbientCapabilities=CAP_NET_BIND_SERVICE
  - Update module docstring, migration docs, README proxy description
  - Add tests verifying transparent proxy architecture
2026-03-19 15:43:11 +01:00
maziggy 4981c60389 Add --branch support to install script with validation
The install script hardcoded origin/main, so beta testers told to
  install from a dev branch silently got the stable release instead.
  Add a --branch CLI option and interactive prompt (defaults to main).
  Invalid branch names are validated via git ls-remote before any work
  is done, showing available branches on failure.
2026-03-05 11:01:06 +01:00
maziggy 3a0b3f8035 Add --branch support to install script
The install script hardcoded origin/main, so beta testers told to
  install from a dev branch silently got the stable release instead.
  Add a --branch CLI option and interactive prompt (defaults to main).
  Fresh installs use git clone --branch, existing installs checkout
  and reset to the selected branch.
2026-03-05 10:58:29 +01:00
maziggy 0faf03ecb3 Fix Python 3.10 compatibility (StrEnum requires 3.11)
enum.StrEnum was added in Python 3.11, but the documented minimum is
  3.10. Add a compatibility shim in backend/app/core/compat.py that falls
  back to (str, Enum) on older versions. Updated all 5 import sites and
  lowered pyproject.toml target-version to py310.
2026-03-05 10:44:24 +01:00
maziggy f094c16012 Updated install scripts and related docs 2026-02-08 18:24:51 +01:00
maziggy 75c049b05c Updated install scripts and related docs 2026-02-08 18:21:19 +01:00
maziggy 196b7a93e9 Added one-shot install scripts 2026-01-31 14:31:10 +01:00