feat(blender): pinned extension set in a read-only System repo, for the GUI and blender-run --extensions
Blender is now a mandatory stage in draupnir's pipeline (Prime, 2026-09-28), and draupnir asked for eight add-ons from extensions.blender.org: SurfacePsycho 0.10.4, CAD Sketcher 0.32.1, 3D-Print Toolbox 1.4.1, STEP Importer 1.2.1, Bool Tool 2.1.0, LoopTools 4.7.7, MeasureIt 1.8.4, 3MF Import/Export 2.7.7. - stacks/blender/extensions.lock pins each by version and archive sha256. - scripts/blender-extensions sync builds fv-ml1:/tank/blender-extensions/5.2/system with Blender's own install-file, pre-warms and byte-compiles it, checks a read-only enable, then swaps it in. It refuses while the GUI or a blender-run job holds the old directory. - conf/scripts/startup/fleet_extensions.py enables every package in the System repo: in a timer in the GUI (after the prefs load), and as --python ahead of the caller's args in blender-run --extensions (a failed enable exits 1 before the caller's script). - It also patches SurfacePsycho's sp_overwrite_segment_selection from eval() to literal_eval(): the eval walked past MCP safe mode (control: unpatched ran code, patched refuses). - blender-run: --extensions (bind mounts via --mount so a missing source fails instead of being created); USER/LOGNAME set, which CAD Sketcher's getpass needs. - compose.yaml mounts the repo read-only and the hook into the GUI container. NOT yet deployed. - scripts/blender-probes/extensions_acceptance.py: one operator run per add-on, safe-mode compliant. Headless 8/9 online and with --network none; CAD Sketcher sketching is GUI-only. A Python audit hook saw no network/process events (positive control fired).
This commit is contained in:
@@ -20,6 +20,7 @@ reaching fv-ml1 as `infra-ops@10.251.50.54` over ssh. **No HTTP API** and no ope
|
||||
|
||||
```sh
|
||||
scripts/blender-run --job /path/to/jobdir -- --python render.py -- out.png
|
||||
scripts/blender-run --extensions --job /path/to/jobdir -- --python model.py
|
||||
scripts/blender-run -- --python-expr 'import bpy; print(bpy.app.version_string)'
|
||||
```
|
||||
|
||||
@@ -34,8 +35,19 @@ scripts/blender-run -- --python-expr 'import bpy; print(bpy.app.version_string)'
|
||||
EEVEE id is `BLENDER_EEVEE` (`BLENDER_EEVEE_NEXT` is gone). For Cycles GPU, set
|
||||
`prefs.compute_device_type = 'OPTIX'` and enable the OPTIX devices, then
|
||||
`scene.cycles.device = 'GPU'`. Factory startup defaults to CPU.
|
||||
- **Import:** STL is built in (`bpy.ops.wm.stl_import`). **No STEP importer** is installed or
|
||||
built in.
|
||||
- **Import:** STL is built in (`bpy.ops.wm.stl_import`). STEP, 3MF and the other add-ons need
|
||||
`--extensions` (below).
|
||||
- **`--extensions`** enables the pinned add-on set: SurfacePsycho 0.10.4 (NURBS patches, STEP/IGES
|
||||
export via its bundled OCP), CAD Sketcher 0.32.1, 3D-Print Toolbox 1.4.1, STEP Importer 1.2.1,
|
||||
Bool Tool 2.1.0, LoopTools 4.7.7, MeasureIt 1.8.4, 3MF Import/Export 2.7.7. Pins:
|
||||
`stacks/blender/extensions.lock`. If any add-on fails to enable, the run exits 1 before your
|
||||
script starts. It adds a few seconds of startup (the add-on wheels unpack per run), so it is
|
||||
off by default. **CAD Sketcher's sketch operators need the GUI** (they activate a workspace
|
||||
tool); headless they fail with "'NoneType' object has no attribute 'widget'". Operators that
|
||||
want a 3D View (MeasureIt, LoopTools) take a `bpy.context.temp_override(area=...)` with a
|
||||
screen datablock's VIEW_3D area. Worked calls for every add-on:
|
||||
`scripts/blender-probes/extensions_acceptance.py`. Full notes and foot-guns: the stack README,
|
||||
section "Extensions".
|
||||
- **Budget:** each run is capped at 64 GB RAM and 48 CPUs, with up to the whole 96 GB of VRAM.
|
||||
Keep to about 2 concurrent renders. It is not on irv-ml1, so irv-ml1's working-set budget
|
||||
does not apply.
|
||||
|
||||
Reference in New Issue
Block a user