mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-10-02 12:15:36 +02:00
Two attacker-controlled strings were being joined to library_dir with no
resolve + containment check in the project ZIP import endpoint:
- linked_folders[*].name from the request's project.json
- per-entry zf.namelist() paths from the ZIP itself
An absolute path in either field collapsed the join (Path("/lib") / "/etc"
becomes Path("/etc") because pathlib discards the left side when the right
is absolute) and the next write_bytes landed wherever the attacker chose.
Adjacent finding from the routes audit: GET /archives/{id}/photos/{filename}
had NO validation on filename and FileResponse-served arbitrary paths -
the DELETE counterpart at least gated on the photos membership check.
Adjacent finding from the services audit: ArchiveService.attach_timelapse
wrote archive_dir / filename where filename ultimately came from a printer's
FTP listing (compromised-printer threat model) or the /timelapse/select
query param. A malicious printer that exposes a directory entry with ..
segments could write the timelapse outside the archive directory.
New backend/app/utils/safe_path.py::safe_join_under(parent, *parts) is the
single source of truth: rejects empty / null-byte / absolute parts up-front,
joins under parent, resolves both sides, asserts is_relative_to. Returns the
resolved canonical path on success, raises HTTPException(400) on escape, or
PathTraversalError when http=False (for service-layer callers that need to
match a non-HTTP return contract).
Wired into the import vectors, both archive photo handlers, and the
attach_timelapse service. The full audit sweep inspected every Path/Name
join in backend/app/api/routes/ AND backend/app/services/ - 25 route-layer
sites + 8 service-layer sites confirmed safe and tagged with
# SEC-PATH-OK: <reason> so future audits trust the inline guard at a glance.
Fifth CI backstop test_route_path_arithmetic_is_safe_joined_or_marked
AST-walks both layers and fails the build on any <dir-like>/<bare variable>
join that doesn't either route through safe_join_under or carry the marker.
The services layer is in scope because it receives values verbatim from the
routes AND from external sources Bambuddy has no control over (the printer
FTP-listing case above).
SECURITY.md gets a fifth rule + a fifth row in the CI test mapping table;
the rule now names the printer FTP-listing case explicitly so future
services-layer audits set the right expectation.
--------------
fix(library): suppress warning storm when bulk-uploading ZIPs of empty/stub STL files
Uploading a ZIP of stub or empty STL files (e.g. the 24-byte
"solid test\nendsolid test" shape) produced one WARNING per file in
stl_thumbnail.py::generate_stl_thumbnail. The warnings were technically
correct - trimesh returns a valid Mesh with zero vertices, the safeguard
matches, and the function returns None so the library entry is still
created without a thumbnail - but the volume turned a successful upload
into thousands of WARNING lines in the journal.
Two changes:
1. The per-file "Failed to load STL or empty mesh" message in
stl_thumbnail.py is now logger.debug instead of logger.warning. It's
a per-file content observation, not an actionable error; the caller
already handles None correctly. The branch now catches the rare
"large enough but trimesh still can't parse it" case, visible in
debug logs without spamming production.
2. New module constant MIN_USABLE_STL_BYTES = 200 (smallest binary STL
with one triangle is 134B, smallest ASCII ~150B; 200 is a safe floor
below any real STL). The three thumbnail call sites in library.py
(extract_zip_file, single-file upload, _backfill_external_stl_thumbnails)
pre-skip files below this size before calling generate_stl_thumbnail.
Stubs never enter the trimesh pipeline at all.
Behavior is unchanged for real STLs: any file >=200 bytes runs through
the existing pipeline, MAX_VERTICES still triggers simplification at
100k vertices for the 256x256 thumbnail render, large files still get
thumbnails.
------------
fix(stl-thumbnail): silence matplotlib first-import noise (writable cache + font_manager log level)
On first STL upload, three matplotlib-internal log lines surfaced:
WARNING [matplotlib] /opt/claude/.config/matplotlib is not a writable directory
INFO [matplotlib.font_manager] Failed to extract font properties from NotoColorEmoji.ttf
INFO [matplotlib.font_manager] generated new fontManager
The writable-dir warning fired because Bambuddy's $HOME isn't writable for
matplotlib's default config path; matplotlib fell back to /tmp/matplotlib-XXX
which lost the font cache on every host reboot, so font_manager rebuilt it
each cold start - producing another batch of INFO lines.
Fix is two small additions in stl_thumbnail.py before the matplotlib import:
1. New _configure_matplotlib_cache() sets MPLCONFIGDIR to
settings.base_dir/.cache/matplotlib (mkdir if missing) so the cache
persists across container restarts and the writable-dir warning never
fires. Respects an externally-set MPLCONFIGDIR so operators who chose
their own path aren't overridden. Best-effort with a debug fallback if
settings can't be imported or the mkdir fails.
2. logging.getLogger("matplotlib.font_manager").setLevel(WARNING) at module
import demotes the per-font INFO scan that fires when font_manager
builds its cache cold. Real font warnings (>= WARNING) still surface.
3 new tests: font_manager logger at WARNING after module import;
_configure_matplotlib_cache creates the directory under base_dir and sets
MPLCONFIGDIR; an externally-set MPLCONFIGDIR is preserved verbatim.
5516 backend tests green, frontend gates clean.
328 lines
11 KiB
Python
328 lines
11 KiB
Python
"""Unit tests for the STL thumbnail service."""
|
|
|
|
import os
|
|
import tempfile
|
|
from pathlib import Path
|
|
|
|
import pytest
|
|
|
|
|
|
def _check_trimesh_available():
|
|
"""Check if trimesh is available for import."""
|
|
try:
|
|
import trimesh
|
|
|
|
return True
|
|
except ImportError:
|
|
return False
|
|
|
|
|
|
class TestStlThumbnailService:
|
|
"""Tests for STL thumbnail generation service."""
|
|
|
|
def test_generate_stl_thumbnail_imports_available(self):
|
|
"""Test that required imports are available."""
|
|
try:
|
|
import matplotlib
|
|
import trimesh
|
|
|
|
assert trimesh is not None
|
|
assert matplotlib is not None
|
|
except ImportError as e:
|
|
pytest.skip(f"Required dependencies not installed: {e}")
|
|
|
|
def test_generate_stl_thumbnail_returns_none_on_missing_deps(self):
|
|
"""Test graceful degradation when dependencies are missing."""
|
|
from backend.app.services.stl_thumbnail import generate_stl_thumbnail
|
|
|
|
with tempfile.TemporaryDirectory() as tmpdir:
|
|
stl_path = Path(tmpdir) / "test.stl"
|
|
thumbnails_dir = Path(tmpdir)
|
|
|
|
# Create a dummy STL file (will fail to parse)
|
|
stl_path.write_text("invalid stl content")
|
|
|
|
# Should return None on failure, not raise
|
|
result = generate_stl_thumbnail(stl_path, thumbnails_dir)
|
|
assert result is None
|
|
|
|
@pytest.mark.skipif(
|
|
not _check_trimesh_available(),
|
|
reason="trimesh not installed",
|
|
)
|
|
def test_generate_stl_thumbnail_with_simple_cube(self):
|
|
"""Test thumbnail generation with a simple cube STL."""
|
|
from backend.app.services.stl_thumbnail import generate_stl_thumbnail
|
|
|
|
with tempfile.TemporaryDirectory() as tmpdir:
|
|
stl_path = Path(tmpdir) / "cube.stl"
|
|
thumbnails_dir = Path(tmpdir)
|
|
|
|
# Create a simple ASCII STL cube
|
|
stl_content = """solid cube
|
|
facet normal 0 0 -1
|
|
outer loop
|
|
vertex 0 0 0
|
|
vertex 1 0 0
|
|
vertex 1 1 0
|
|
endloop
|
|
endfacet
|
|
facet normal 0 0 -1
|
|
outer loop
|
|
vertex 0 0 0
|
|
vertex 1 1 0
|
|
vertex 0 1 0
|
|
endloop
|
|
endfacet
|
|
facet normal 0 0 1
|
|
outer loop
|
|
vertex 0 0 1
|
|
vertex 1 1 1
|
|
vertex 1 0 1
|
|
endloop
|
|
endfacet
|
|
facet normal 0 0 1
|
|
outer loop
|
|
vertex 0 0 1
|
|
vertex 0 1 1
|
|
vertex 1 1 1
|
|
endloop
|
|
endfacet
|
|
facet normal 0 -1 0
|
|
outer loop
|
|
vertex 0 0 0
|
|
vertex 1 0 1
|
|
vertex 1 0 0
|
|
endloop
|
|
endfacet
|
|
facet normal 0 -1 0
|
|
outer loop
|
|
vertex 0 0 0
|
|
vertex 0 0 1
|
|
vertex 1 0 1
|
|
endloop
|
|
endfacet
|
|
facet normal 1 0 0
|
|
outer loop
|
|
vertex 1 0 0
|
|
vertex 1 0 1
|
|
vertex 1 1 1
|
|
endloop
|
|
endfacet
|
|
facet normal 1 0 0
|
|
outer loop
|
|
vertex 1 0 0
|
|
vertex 1 1 1
|
|
vertex 1 1 0
|
|
endloop
|
|
endfacet
|
|
facet normal 0 1 0
|
|
outer loop
|
|
vertex 0 1 0
|
|
vertex 1 1 0
|
|
vertex 1 1 1
|
|
endloop
|
|
endfacet
|
|
facet normal 0 1 0
|
|
outer loop
|
|
vertex 0 1 0
|
|
vertex 1 1 1
|
|
vertex 0 1 1
|
|
endloop
|
|
endfacet
|
|
facet normal -1 0 0
|
|
outer loop
|
|
vertex 0 0 0
|
|
vertex 0 1 0
|
|
vertex 0 1 1
|
|
endloop
|
|
endfacet
|
|
facet normal -1 0 0
|
|
outer loop
|
|
vertex 0 0 0
|
|
vertex 0 1 1
|
|
vertex 0 0 1
|
|
endloop
|
|
endfacet
|
|
endsolid cube"""
|
|
stl_path.write_text(stl_content)
|
|
|
|
result = generate_stl_thumbnail(stl_path, thumbnails_dir)
|
|
|
|
# Should return a path to the generated thumbnail
|
|
if result:
|
|
assert Path(result).exists()
|
|
assert Path(result).suffix == ".png"
|
|
# If result is None, dependencies might not be fully functional
|
|
# which is acceptable
|
|
|
|
def test_generate_stl_thumbnail_nonexistent_file(self):
|
|
"""Test thumbnail generation with nonexistent file."""
|
|
from backend.app.services.stl_thumbnail import generate_stl_thumbnail
|
|
|
|
with tempfile.TemporaryDirectory() as tmpdir:
|
|
stl_path = Path(tmpdir) / "nonexistent.stl"
|
|
thumbnails_dir = Path(tmpdir)
|
|
|
|
result = generate_stl_thumbnail(stl_path, thumbnails_dir)
|
|
assert result is None
|
|
|
|
def test_generate_stl_thumbnail_empty_file(self):
|
|
"""Test thumbnail generation with empty file."""
|
|
from backend.app.services.stl_thumbnail import generate_stl_thumbnail
|
|
|
|
with tempfile.TemporaryDirectory() as tmpdir:
|
|
stl_path = Path(tmpdir) / "empty.stl"
|
|
thumbnails_dir = Path(tmpdir)
|
|
|
|
# Create empty file
|
|
stl_path.write_bytes(b"")
|
|
|
|
result = generate_stl_thumbnail(stl_path, thumbnails_dir)
|
|
assert result is None
|
|
|
|
@pytest.mark.skipif(
|
|
not _check_trimesh_available(),
|
|
reason="trimesh not installed",
|
|
)
|
|
def test_string_arguments_accepted_without_typeerror(self):
|
|
"""Regression for #1299: external-scan path passed both args as str.
|
|
|
|
Before the fix, the function did ``thumbnails_dir / thumb_filename`` on
|
|
a ``str`` and raised ``TypeError: unsupported operand type(s) for /:
|
|
'str' and 'str'`` for every STL on an external folder scan. The fix
|
|
coerces both args to ``Path`` at entry. This test passes string args
|
|
and asserts the function either succeeds or returns ``None`` — but
|
|
never raises the TypeError.
|
|
"""
|
|
from backend.app.services.stl_thumbnail import generate_stl_thumbnail
|
|
|
|
with tempfile.TemporaryDirectory() as tmpdir:
|
|
stl_path = Path(tmpdir) / "cube.stl"
|
|
# Minimal valid binary STL: header (80 bytes) + tri count (0)
|
|
stl_path.write_bytes(b"\x00" * 80 + (0).to_bytes(4, "little"))
|
|
|
|
# str args — the exact shape the external-scan call site used.
|
|
result = generate_stl_thumbnail(str(stl_path), str(tmpdir))
|
|
|
|
# Zero-triangle mesh either yields no thumbnail or fails the
|
|
# downstream render — both are acceptable; what's NOT acceptable
|
|
# is a TypeError leaking out, which is what the str/str bug did.
|
|
assert result is None or Path(result).exists()
|
|
|
|
|
|
class TestStlThumbnailConstants:
|
|
"""Tests for STL thumbnail service constants."""
|
|
|
|
def test_bambu_green_color(self):
|
|
"""Test that Bambu green color is defined."""
|
|
from backend.app.services.stl_thumbnail import BAMBU_GREEN
|
|
|
|
assert BAMBU_GREEN == "#00AE42"
|
|
|
|
def test_background_color(self):
|
|
"""Test that background color is defined."""
|
|
from backend.app.services.stl_thumbnail import BACKGROUND_COLOR
|
|
|
|
assert BACKGROUND_COLOR == "#1a1a1a"
|
|
|
|
def test_max_vertices_threshold(self):
|
|
"""Test that max vertices threshold is defined."""
|
|
from backend.app.services.stl_thumbnail import MAX_VERTICES
|
|
|
|
assert MAX_VERTICES == 100000
|
|
|
|
def test_min_usable_stl_bytes_threshold(self):
|
|
"""MIN_USABLE_STL_BYTES is the call-site pre-skip floor.
|
|
|
|
Binary STL with one triangle = 80B header + 4B count + 50B triangle
|
|
= 134B. ASCII STL with one triangle ≈ 150B. Anything below this size
|
|
cannot contain a usable mesh.
|
|
"""
|
|
from backend.app.services.stl_thumbnail import MIN_USABLE_STL_BYTES
|
|
|
|
assert MIN_USABLE_STL_BYTES == 200
|
|
# Verify it sits between "smaller than smallest real STL" and
|
|
# "common stub size" — the 24-byte ``solid test\nendsolid test``
|
|
# stubs that triggered the warning storm.
|
|
assert MIN_USABLE_STL_BYTES > 134 # smallest binary STL with one triangle
|
|
assert MIN_USABLE_STL_BYTES > 150 # smallest ASCII STL with one triangle
|
|
assert MIN_USABLE_STL_BYTES > 24 # the ZIP-stub case in the bug report
|
|
|
|
def test_font_manager_logger_demoted_to_warning(self):
|
|
"""matplotlib.font_manager's per-font INFO scan is demoted at module
|
|
import so the first STL upload doesn't surface a multi-line preamble
|
|
of matplotlib internals in the journal."""
|
|
import logging
|
|
|
|
# Importing the module sets the level as a side effect.
|
|
import backend.app.services.stl_thumbnail # noqa: F401
|
|
|
|
assert logging.getLogger("matplotlib.font_manager").level >= logging.WARNING
|
|
|
|
def test_configure_matplotlib_cache_sets_mplconfigdir(self, tmp_path, monkeypatch):
|
|
"""``_configure_matplotlib_cache`` points matplotlib at a writable
|
|
persistent path so it doesn't fall back to ``/tmp/matplotlib-XXX``
|
|
on every cold start."""
|
|
from backend.app.services.stl_thumbnail import _configure_matplotlib_cache
|
|
|
|
# Ensure we start with no value so the helper actually runs.
|
|
monkeypatch.delenv("MPLCONFIGDIR", raising=False)
|
|
monkeypatch.setattr(
|
|
"backend.app.services.stl_thumbnail.Path",
|
|
__import__("pathlib").Path,
|
|
)
|
|
|
|
# Stub settings.base_dir to point inside tmp_path.
|
|
from backend.app.core import config as core_config
|
|
|
|
monkeypatch.setattr(core_config.settings, "base_dir", tmp_path, raising=False)
|
|
|
|
_configure_matplotlib_cache()
|
|
|
|
assert "MPLCONFIGDIR" in os.environ
|
|
configured = Path(os.environ["MPLCONFIGDIR"])
|
|
assert configured.exists()
|
|
assert configured.is_dir()
|
|
# And the directory sits under base_dir, not /tmp/matplotlib-XXX.
|
|
assert tmp_path in configured.parents
|
|
|
|
def test_configure_matplotlib_cache_respects_externally_set_value(self, tmp_path, monkeypatch):
|
|
"""If the operator (or container init) has set MPLCONFIGDIR already,
|
|
the helper must leave it alone — they made a deliberate choice."""
|
|
from backend.app.services.stl_thumbnail import _configure_matplotlib_cache
|
|
|
|
external = str(tmp_path / "external-mpl-cache")
|
|
monkeypatch.setenv("MPLCONFIGDIR", external)
|
|
_configure_matplotlib_cache()
|
|
assert os.environ["MPLCONFIGDIR"] == external
|
|
|
|
def test_empty_mesh_logged_at_debug_not_warning(self, caplog):
|
|
"""An empty STL (header present, no triangles) must log at DEBUG, not
|
|
WARNING — bulk uploads used to log thousands of WARNING lines per
|
|
ZIP. Per-file content observations stay observable in debug logs
|
|
but don't spam production journals."""
|
|
import logging
|
|
import tempfile
|
|
from pathlib import Path
|
|
|
|
from backend.app.services.stl_thumbnail import generate_stl_thumbnail
|
|
|
|
# The exact 24-byte stub from the bug report
|
|
stub_content = b"solid test\nendsolid test"
|
|
|
|
with tempfile.TemporaryDirectory() as tmpdir:
|
|
tmpdir_path = Path(tmpdir)
|
|
stl_path = tmpdir_path / "stub.stl"
|
|
stl_path.write_bytes(stub_content)
|
|
|
|
with caplog.at_level(logging.DEBUG, logger="backend.app.services.stl_thumbnail"):
|
|
result = generate_stl_thumbnail(stl_path, tmpdir_path)
|
|
|
|
assert result is None
|
|
# The empty-mesh message must NOT appear at WARNING level.
|
|
warning_records = [r for r in caplog.records if r.levelno >= logging.WARNING and "empty mesh" in r.getMessage()]
|
|
assert warning_records == [], (
|
|
f"Empty-mesh path still logs at WARNING: {[r.getMessage() for r in warning_records]}"
|
|
)
|