Files
bambuddy/deploy/bambuddy.service
T
maziggy 7d4dfd5a7d fix(vp): stop uvloop from silently truncating VP FTP uploads (#1896)
Native (non-Docker) installs launched uvicorn without --loop asyncio, so
uvicorn[standard] auto-selected uvloop. uvloop's SSL layer drops
already-received but still-buffered data when the client closes the data
connection without a TLS close_notify while the reader is flow-control
paused on slow storage. cmd_STOR writes each chunk to disk inside the read
loop, so a slow consumer falls behind, the tail is lost, read() returns a
clean EOF, and the loop exits with no exception -- the server acked 226 for
a file it truncated itself, then archived, queued, and forwarded the corrupt
3MF to the real printer.

Fix in two independent layers:

1. Remove the trigger: add --loop asyncio to every native launch path,
   matching the Dockerfile -- deploy/bambuddy.service, install/install.sh
   (systemd + launchd), spoolbuddy/install/install.sh, the Windows NSSM
   service, README, CONTRIBUTING dev command.

2. Defense in depth (loop-independent): cmd_STOR now validates that a
   received .3mf opens as a ZIP (reads the central directory, no
   decompression) before replying 226. A truncated/corrupt file is dropped
   and answered with 426, and on_file_received never runs -- so a broken
   upload surfaces as an immediate slicer-side send error instead of being
   archived and pushed to the printer. Scoped to .3mf; other filetypes pass
   through unchanged.
2026-07-05 10:32:13 +02:00

67 lines
1.9 KiB
Desktop File

# BamBuddy Systemd Service Template
#
# INSTALLATION:
# 1. Copy this file to /etc/systemd/system/bambuddy.service
# 2. Replace placeholders:
# - INSTALL_PATH: Where BamBuddy is installed (e.g., /opt/bambuddy)
# - SERVICE_USER: User to run as (e.g., bambuddy)
# - DATA_DIR: Data directory (e.g., /opt/bambuddy/data)
# - LOG_DIR: Log directory (e.g., /opt/bambuddy/logs)
# 3. Run: sudo systemctl daemon-reload
# 4. Run: sudo systemctl enable bambuddy
# 5. Run: sudo systemctl start bambuddy
#
# Or use the install script: ./install/install.sh
#
[Unit]
Description=BamBuddy - Bambu Lab Print Management
Documentation=https://github.com/maziggy/bambuddy
After=network.target
[Service]
Type=simple
User=SERVICE_USER
Group=SERVICE_USER
WorkingDirectory=INSTALL_PATH
# Environment file (optional - created by install script)
EnvironmentFile=-INSTALL_PATH/.env
# Use virtual environment
Environment="PATH=INSTALL_PATH/venv/bin:/usr/local/bin:/usr/bin:/bin"
# Server configuration
# --loop asyncio is required: uvloop's SSL layer can silently truncate VP FTP
# uploads on a ragged client close over slow storage (#1896). Do not remove.
ExecStart=INSTALL_PATH/venv/bin/uvicorn backend.app.main:app --host 0.0.0.0 --port ${PORT:-8000} --loop asyncio
# Restart policy
Restart=on-failure
RestartSec=5
# Graceful shutdown
TimeoutStopSec=10
# Kill zombie ffmpeg processes (timelapse processing)
ExecStartPre=-/usr/bin/pkill -9 -f "ffmpeg.*bambuddy"
ExecStopPost=-/usr/bin/pkill -9 -f "ffmpeg.*bambuddy"
# Logging
StandardOutput=journal
StandardError=journal
SyslogIdentifier=bambuddy
# Security hardening
NoNewPrivileges=true
PrivateTmp=true
ProtectSystem=strict
# ProtectHome=true hides /home/* and breaks ExecStart when INSTALL_PATH is
# under /home (issue #1685). Default is the safer read-only; flip to true if
# your INSTALL_PATH is outside /home (e.g. /opt/bambuddy).
ProtectHome=read-only
ReadWritePaths=DATA_DIR LOG_DIR INSTALL_PATH
[Install]
WantedBy=multi-user.target