feat(blender): pinned extension set in a read-only System repo, for the GUI and blender-run --extensions
Blender is now a mandatory stage in draupnir's pipeline (Prime, 2026-09-28), and draupnir asked for eight add-ons from extensions.blender.org: SurfacePsycho 0.10.4, CAD Sketcher 0.32.1, 3D-Print Toolbox 1.4.1, STEP Importer 1.2.1, Bool Tool 2.1.0, LoopTools 4.7.7, MeasureIt 1.8.4, 3MF Import/Export 2.7.7. - stacks/blender/extensions.lock pins each by version and archive sha256. - scripts/blender-extensions sync builds fv-ml1:/tank/blender-extensions/5.2/system with Blender's own install-file, pre-warms and byte-compiles it, checks a read-only enable, then swaps it in. It refuses while the GUI or a blender-run job holds the old directory. - conf/scripts/startup/fleet_extensions.py enables every package in the System repo: in a timer in the GUI (after the prefs load), and as --python ahead of the caller's args in blender-run --extensions (a failed enable exits 1 before the caller's script). - It also patches SurfacePsycho's sp_overwrite_segment_selection from eval() to literal_eval(): the eval walked past MCP safe mode (control: unpatched ran code, patched refuses). - blender-run: --extensions (bind mounts via --mount so a missing source fails instead of being created); USER/LOGNAME set, which CAD Sketcher's getpass needs. - compose.yaml mounts the repo read-only and the hook into the GUI container. NOT yet deployed. - scripts/blender-probes/extensions_acceptance.py: one operator run per add-on, safe-mode compliant. Headless 8/9 online and with --network none; CAD Sketcher sketching is GUI-only. A Python audit hook saw no network/process events (positive control fired).
This commit is contained in:
+21
-6
@@ -2,9 +2,9 @@
|
||||
# blender-run — one-shot HEADLESS Blender on fv-ml1 GPU 3, for scripted/CLI callers (draupnir etc.).
|
||||
# The agent-driven, interactive path is scripts/blender-mcp; this is the batch path.
|
||||
#
|
||||
# scripts/blender-run [--job DIR] -- <blender args after -b>
|
||||
# scripts/blender-run [--job DIR] [--extensions] -- <blender args after -b>
|
||||
# scripts/blender-run --job /mnt/smithy/draupnir/j42 -- --python render.py -- --out out.png
|
||||
# scripts/blender-run -- --python-expr 'import bpy; print(bpy.app.version_string)'
|
||||
# scripts/blender-run --extensions -- --python-expr 'import bpy; print(bpy.app.version_string)'
|
||||
#
|
||||
# Each call is its own `docker run --rm` of the stacks/blender image (Blender 5.2.2 LTS, Python
|
||||
# 3.13): no desktop, no MCP socket, gone when Blender exits. So it never collides with the on-demand
|
||||
@@ -16,6 +16,12 @@
|
||||
# output path against the working directory: "cannot save 'out.png'". Python file I/O and
|
||||
# importers do use the cwd.
|
||||
#
|
||||
# --extensions: also enable the pinned add-on set (stacks/blender/extensions.lock: SurfacePsycho,
|
||||
# CAD Sketcher, 3D-Print Toolbox, STEP Importer, Bool Tool, LoopTools, MeasureIt, 3MF). It mounts
|
||||
# /tank/blender-extensions/5.2/system read-only as Blender's System repository and runs
|
||||
# fleet_extensions.py ahead of your arguments. If any add-on fails to enable, the run exits 1
|
||||
# before your script starts. Off by default, so a plain render stays factory-clean.
|
||||
#
|
||||
# Files: fv-ml1 does NOT mount /mnt/smithy. With --job DIR, DIR is mirrored to
|
||||
# fv-ml1:/tank/blender/jobs/<basename>-<hash of DIR's absolute path>/, Blender runs WITH THAT AS ITS
|
||||
# WORKING DIRECTORY, and new or changed files are copied back into DIR afterwards (nothing is ever
|
||||
@@ -32,11 +38,18 @@ set -euo pipefail
|
||||
HOST=${BLENDER_SSH_HOST:-infra-ops@10.251.50.54}
|
||||
ENV_FILE=/opt/docker/compose/blender/.env
|
||||
JOB=""
|
||||
EXT=""
|
||||
while [ $# -gt 0 ]; do
|
||||
case "$1" in
|
||||
--job) JOB=${2:?--job needs a directory}; shift 2 ;;
|
||||
--extensions)
|
||||
# --mount, not -v: a missing source is an error, where -v would silently create it as an
|
||||
# empty root-owned DIRECTORY on fv-ml1 (and a directory where the hook file belongs).
|
||||
EXT="--mount type=bind,src=/tank/blender-extensions/5.2/system,dst=/blender/5.2/extensions/system,readonly \
|
||||
--mount type=bind,src=/opt/docker/conf/blender/scripts/startup/fleet_extensions.py,dst=/fleet/fleet_extensions.py,readonly"
|
||||
shift ;;
|
||||
--) shift; break ;;
|
||||
-h|--help) sed -n 2,23p "$0"; exit 0 ;;
|
||||
-h|--help) sed -n 2,35p "$0"; exit 0 ;;
|
||||
*) echo "blender-run: unknown option $1 (blender args go after --)" >&2; exit 2 ;;
|
||||
esac
|
||||
done
|
||||
@@ -59,13 +72,15 @@ fi
|
||||
|
||||
# Arguments travel as one shell-quoted string: ssh flattens argv into a remote command line.
|
||||
ARGS=$(printf '%q ' "$@")
|
||||
PRE=""
|
||||
[ -n "$EXT" ] && PRE="--python /fleet/fleet_extensions.py"
|
||||
set +e
|
||||
ssh -n -o BatchMode=yes "$HOST" "IMG=\$(grep '^IMAGE=' $ENV_FILE | cut -d= -f2) && \
|
||||
exec docker run --rm --name blender-run-\$\$ --runtime nvidia \
|
||||
-e NVIDIA_VISIBLE_DEVICES=3 -e NVIDIA_DRIVER_CAPABILITIES=all \
|
||||
--user 1002:1003 -e HOME=/tmp --memory 64g --cpus 48 \
|
||||
-v /tank/blender:/work -w $WORKDIR --entrypoint /blender/blender \"\$IMG\" \
|
||||
-b --factory-startup --python-exit-code 1 $ARGS"
|
||||
--user 1002:1003 -e HOME=/tmp -e USER=infra-ops -e LOGNAME=infra-ops --memory 64g --cpus 48 \
|
||||
-v /tank/blender:/work $EXT -w $WORKDIR --entrypoint /blender/blender \"\$IMG\" \
|
||||
-b --factory-startup --python-exit-code 1 $PRE $ARGS"
|
||||
RC=$?
|
||||
set -e
|
||||
if [ -n "$JOB" ]; then
|
||||
|
||||
Reference in New Issue
Block a user