mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-09-30 11:12:35 +02:00
Two attacker-controlled strings were being joined to library_dir with no
resolve + containment check in the project ZIP import endpoint:
- linked_folders[*].name from the request's project.json
- per-entry zf.namelist() paths from the ZIP itself
An absolute path in either field collapsed the join (Path("/lib") / "/etc"
becomes Path("/etc") because pathlib discards the left side when the right
is absolute) and the next write_bytes landed wherever the attacker chose.
Adjacent finding from the routes audit: GET /archives/{id}/photos/{filename}
had NO validation on filename and FileResponse-served arbitrary paths -
the DELETE counterpart at least gated on the photos membership check.
Adjacent finding from the services audit: ArchiveService.attach_timelapse
wrote archive_dir / filename where filename ultimately came from a printer's
FTP listing (compromised-printer threat model) or the /timelapse/select
query param. A malicious printer that exposes a directory entry with ..
segments could write the timelapse outside the archive directory.
New backend/app/utils/safe_path.py::safe_join_under(parent, *parts) is the
single source of truth: rejects empty / null-byte / absolute parts up-front,
joins under parent, resolves both sides, asserts is_relative_to. Returns the
resolved canonical path on success, raises HTTPException(400) on escape, or
PathTraversalError when http=False (for service-layer callers that need to
match a non-HTTP return contract).
Wired into the import vectors, both archive photo handlers, and the
attach_timelapse service. The full audit sweep inspected every Path/Name
join in backend/app/api/routes/ AND backend/app/services/ - 25 route-layer
sites + 8 service-layer sites confirmed safe and tagged with
# SEC-PATH-OK: <reason> so future audits trust the inline guard at a glance.
Fifth CI backstop test_route_path_arithmetic_is_safe_joined_or_marked
AST-walks both layers and fails the build on any <dir-like>/<bare variable>
join that doesn't either route through safe_join_under or carry the marker.
The services layer is in scope because it receives values verbatim from the
routes AND from external sources Bambuddy has no control over (the printer
FTP-listing case above).
SECURITY.md gets a fifth rule + a fifth row in the CI test mapping table;
the rule now names the printer FTP-listing case explicitly so future
services-layer audits set the right expectation.
--------------
fix(library): suppress warning storm when bulk-uploading ZIPs of empty/stub STL files
Uploading a ZIP of stub or empty STL files (e.g. the 24-byte
"solid test\nendsolid test" shape) produced one WARNING per file in
stl_thumbnail.py::generate_stl_thumbnail. The warnings were technically
correct - trimesh returns a valid Mesh with zero vertices, the safeguard
matches, and the function returns None so the library entry is still
created without a thumbnail - but the volume turned a successful upload
into thousands of WARNING lines in the journal.
Two changes:
1. The per-file "Failed to load STL or empty mesh" message in
stl_thumbnail.py is now logger.debug instead of logger.warning. It's
a per-file content observation, not an actionable error; the caller
already handles None correctly. The branch now catches the rare
"large enough but trimesh still can't parse it" case, visible in
debug logs without spamming production.
2. New module constant MIN_USABLE_STL_BYTES = 200 (smallest binary STL
with one triangle is 134B, smallest ASCII ~150B; 200 is a safe floor
below any real STL). The three thumbnail call sites in library.py
(extract_zip_file, single-file upload, _backfill_external_stl_thumbnails)
pre-skip files below this size before calling generate_stl_thumbnail.
Stubs never enter the trimesh pipeline at all.
Behavior is unchanged for real STLs: any file >=200 bytes runs through
the existing pipeline, MAX_VERTICES still triggers simplification at
100k vertices for the 256x256 thumbnail render, large files still get
thumbnails.
------------
fix(stl-thumbnail): silence matplotlib first-import noise (writable cache + font_manager log level)
On first STL upload, three matplotlib-internal log lines surfaced:
WARNING [matplotlib] /opt/claude/.config/matplotlib is not a writable directory
INFO [matplotlib.font_manager] Failed to extract font properties from NotoColorEmoji.ttf
INFO [matplotlib.font_manager] generated new fontManager
The writable-dir warning fired because Bambuddy's $HOME isn't writable for
matplotlib's default config path; matplotlib fell back to /tmp/matplotlib-XXX
which lost the font cache on every host reboot, so font_manager rebuilt it
each cold start - producing another batch of INFO lines.
Fix is two small additions in stl_thumbnail.py before the matplotlib import:
1. New _configure_matplotlib_cache() sets MPLCONFIGDIR to
settings.base_dir/.cache/matplotlib (mkdir if missing) so the cache
persists across container restarts and the writable-dir warning never
fires. Respects an externally-set MPLCONFIGDIR so operators who chose
their own path aren't overridden. Best-effort with a debug fallback if
settings can't be imported or the mkdir fails.
2. logging.getLogger("matplotlib.font_manager").setLevel(WARNING) at module
import demotes the per-font INFO scan that fires when font_manager
builds its cache cold. Real font warnings (>= WARNING) still surface.
3 new tests: font_manager logger at WARNING after module import;
_configure_matplotlib_cache creates the directory under base_dir and sets
MPLCONFIGDIR; an externally-set MPLCONFIGDIR is preserved verbatim.
5516 backend tests green, frontend gates clean.
212 lines
8.1 KiB
Python
212 lines
8.1 KiB
Python
"""STL Thumbnail Generation Service.
|
|
|
|
Generates thumbnail images from STL files using trimesh and matplotlib.
|
|
"""
|
|
|
|
import logging
|
|
import os
|
|
import uuid
|
|
from pathlib import Path
|
|
|
|
logger = logging.getLogger(__name__)
|
|
|
|
# Matplotlib's font_manager emits one INFO line per font on first import
|
|
# while it builds its cache, including a noisy "Failed to extract font
|
|
# properties from NotoColorEmoji.ttf" for the COLR/COLR1 emoji format it
|
|
# doesn't support. These are not actionable — demote to WARNING so real
|
|
# font issues still surface but the first STL upload doesn't produce a
|
|
# multi-line matplotlib preamble in the journal.
|
|
logging.getLogger("matplotlib.font_manager").setLevel(logging.WARNING)
|
|
|
|
|
|
def _configure_matplotlib_cache() -> None:
|
|
"""Point matplotlib's config/cache directory at a writable persistent path.
|
|
|
|
Without this, matplotlib falls back to ``/tmp/matplotlib-XXXXXX`` whenever
|
|
``$HOME/.config/matplotlib`` isn't writable — which is the case under
|
|
Bambuddy's container / systemd-service deployments where ``$HOME`` is set
|
|
to a non-writable path. The fallback emits a WARNING on every cold start
|
|
AND loses the font cache on host reboot, so font_manager rebuilds it
|
|
every time → another batch of INFO lines.
|
|
|
|
Setting ``MPLCONFIGDIR`` to ``settings.base_dir / .cache / matplotlib``
|
|
eliminates both: the warning never fires, and the cache survives across
|
|
restarts so the per-font scan only runs once per deployment.
|
|
Idempotent — respects an externally-set ``MPLCONFIGDIR`` if the operator
|
|
chose their own path.
|
|
"""
|
|
if os.environ.get("MPLCONFIGDIR"):
|
|
return
|
|
try:
|
|
from backend.app.core.config import settings
|
|
|
|
cache_dir = Path(settings.base_dir) / ".cache" / "matplotlib"
|
|
cache_dir.mkdir(parents=True, exist_ok=True)
|
|
os.environ["MPLCONFIGDIR"] = str(cache_dir)
|
|
except Exception as exc:
|
|
# Best-effort. If settings isn't importable or the mkdir fails (read-only
|
|
# FS, permission denied), let matplotlib fall back to /tmp with its
|
|
# built-in warning — same as today's behaviour, no worse.
|
|
logger.debug("Could not configure MPLCONFIGDIR: %s", exc)
|
|
|
|
|
|
# Bambu green color for rendering
|
|
BAMBU_GREEN = "#00AE42"
|
|
BACKGROUND_COLOR = "#1a1a1a"
|
|
|
|
# Maximum vertices before simplification
|
|
MAX_VERTICES = 100000
|
|
|
|
# Minimum STL file size that could possibly contain a usable mesh:
|
|
# - Binary STL with one triangle: 80B header + 4B count + 50B triangle = 134B
|
|
# - ASCII STL with one triangle: header + "facet ... endfacet" + footer ≈ 150B
|
|
# Files below this are stubs / placeholders / corrupted; trimesh would return an
|
|
# empty mesh anyway. Pre-skipping at the call sites suppresses the warning storm
|
|
# bulk-uploaded ZIPs of small test STLs used to produce.
|
|
MIN_USABLE_STL_BYTES = 200
|
|
|
|
|
|
def generate_stl_thumbnail(
|
|
stl_path: Path,
|
|
thumbnails_dir: Path,
|
|
size: int = 256,
|
|
) -> str | None:
|
|
"""Generate a thumbnail image from an STL file.
|
|
|
|
Args:
|
|
stl_path: Path to the STL file
|
|
thumbnails_dir: Directory to save the thumbnail
|
|
size: Thumbnail size in pixels (default 256x256)
|
|
|
|
Returns:
|
|
Path to the generated thumbnail, or None on failure
|
|
"""
|
|
# Callers historically pass either Path or str; coerce so the `thumbnails_dir
|
|
# / thumb_filename` join at the end of this function can't fail with the
|
|
# str-divided-by-str TypeError (see #1299).
|
|
stl_path = Path(stl_path)
|
|
thumbnails_dir = Path(thumbnails_dir)
|
|
|
|
try:
|
|
# Must precede the matplotlib import — MPLCONFIGDIR is read at
|
|
# matplotlib import time, not on subsequent attribute access.
|
|
_configure_matplotlib_cache()
|
|
|
|
import matplotlib
|
|
import trimesh
|
|
|
|
# Use Agg backend for headless rendering
|
|
matplotlib.use("Agg")
|
|
import matplotlib.pyplot as plt
|
|
from mpl_toolkits.mplot3d import Axes3D # noqa: F401
|
|
from mpl_toolkits.mplot3d.art3d import Poly3DCollection
|
|
|
|
# Load the STL file
|
|
mesh = trimesh.load(str(stl_path), force="mesh")
|
|
|
|
if mesh is None or not hasattr(mesh, "vertices") or len(mesh.vertices) == 0:
|
|
# Demoted from warning to debug: this is a per-file content
|
|
# observation (the STL is empty / stub / corrupted), not an
|
|
# actionable error. The caller proceeds correctly with no
|
|
# thumbnail. The call sites also pre-skip files below
|
|
# MIN_USABLE_STL_BYTES so the common stub-STL case never gets
|
|
# this far — this branch now catches only the rare "large
|
|
# enough but trimesh still can't parse it" case.
|
|
logger.debug("Failed to load STL or empty mesh: %s", stl_path)
|
|
return None
|
|
|
|
# Simplify large meshes for performance
|
|
if len(mesh.vertices) > MAX_VERTICES:
|
|
logger.info("Simplifying mesh from %s vertices", len(mesh.vertices))
|
|
try:
|
|
# Calculate reduction ratio (0-1 range)
|
|
# e.g., 124633 vertices -> 100000 means keep ~80%, so reduce by ~20%
|
|
keep_ratio = MAX_VERTICES / len(mesh.vertices)
|
|
target_reduction = 1.0 - keep_ratio
|
|
# Clamp to valid range (0.01 to 0.99)
|
|
target_reduction = max(0.01, min(0.99, target_reduction))
|
|
mesh = mesh.simplify_quadric_decimation(target_reduction)
|
|
logger.info("Simplified mesh to %s vertices", len(mesh.vertices))
|
|
except Exception as e:
|
|
logger.warning("Mesh simplification failed, using original: %s", e)
|
|
|
|
# Get mesh bounds and center it
|
|
vertices = mesh.vertices
|
|
bounds_min = vertices.min(axis=0)
|
|
bounds_max = vertices.max(axis=0)
|
|
center = (bounds_min + bounds_max) / 2
|
|
vertices_centered = vertices - center
|
|
|
|
# Scale to fit in view
|
|
max_extent = (bounds_max - bounds_min).max()
|
|
if max_extent > 0:
|
|
scale = 1.0 / max_extent
|
|
vertices_scaled = vertices_centered * scale
|
|
else:
|
|
vertices_scaled = vertices_centered
|
|
|
|
# Create figure with dark background
|
|
fig = plt.figure(figsize=(size / 100, size / 100), dpi=100)
|
|
fig.patch.set_facecolor(BACKGROUND_COLOR)
|
|
|
|
ax = fig.add_subplot(111, projection="3d")
|
|
ax.set_facecolor(BACKGROUND_COLOR)
|
|
|
|
# Create polygon collection from mesh faces
|
|
faces = mesh.faces
|
|
poly3d = [[vertices_scaled[vertex] for vertex in face] for face in faces]
|
|
|
|
collection = Poly3DCollection(
|
|
poly3d,
|
|
facecolors=BAMBU_GREEN,
|
|
edgecolors=BAMBU_GREEN,
|
|
linewidths=0.1,
|
|
alpha=0.9,
|
|
)
|
|
ax.add_collection3d(collection)
|
|
|
|
# Set axis limits
|
|
ax.set_xlim(-0.6, 0.6)
|
|
ax.set_ylim(-0.6, 0.6)
|
|
ax.set_zlim(-0.6, 0.6)
|
|
|
|
# Set view angle (isometric-ish)
|
|
ax.view_init(elev=25, azim=45)
|
|
|
|
# Remove axes and grid
|
|
ax.set_axis_off()
|
|
ax.grid(False)
|
|
|
|
# Remove margins
|
|
plt.subplots_adjust(left=0, right=1, top=1, bottom=0)
|
|
|
|
# Save thumbnail
|
|
thumb_filename = f"{uuid.uuid4().hex}.png"
|
|
thumb_path = thumbnails_dir / thumb_filename # SEC-PATH-OK: thumb_filename = uuid.uuid4().hex + ".png"
|
|
|
|
fig.savefig(
|
|
thumb_path,
|
|
format="png",
|
|
facecolor=BACKGROUND_COLOR,
|
|
edgecolor="none",
|
|
bbox_inches="tight",
|
|
pad_inches=0.05,
|
|
dpi=100,
|
|
)
|
|
plt.close(fig)
|
|
|
|
logger.info("Generated STL thumbnail: %s", thumb_path)
|
|
return str(thumb_path)
|
|
|
|
except ImportError as e:
|
|
logger.warning("STL thumbnail generation unavailable (missing dependencies): %s", e)
|
|
return None
|
|
except Exception as e:
|
|
# Log the traceback, not just the message: a bare
|
|
# "unsupported operand type(s) for /: 'str' and 'str'" gives no clue
|
|
# which line failed, and the fault is data-/environment-specific
|
|
# enough that it can't be reproduced from a clean STL — the traceback
|
|
# in the next support bundle is what pinpoints it (#1480).
|
|
logger.warning("Failed to generate STL thumbnail for %s: %s", stl_path, e, exc_info=True)
|
|
return None
|