feat(blender): pinned extension set in a read-only System repo, for the GUI and blender-run --extensions

Blender is now a mandatory stage in draupnir's pipeline (Prime, 2026-09-28), and draupnir asked
for eight add-ons from extensions.blender.org: SurfacePsycho 0.10.4, CAD Sketcher 0.32.1,
3D-Print Toolbox 1.4.1, STEP Importer 1.2.1, Bool Tool 2.1.0, LoopTools 4.7.7, MeasureIt 1.8.4,
3MF Import/Export 2.7.7.

- stacks/blender/extensions.lock pins each by version and archive sha256.
- scripts/blender-extensions sync builds fv-ml1:/tank/blender-extensions/5.2/system with Blender's
  own install-file, pre-warms and byte-compiles it, checks a read-only enable, then swaps it in.
  It refuses while the GUI or a blender-run job holds the old directory.
- conf/scripts/startup/fleet_extensions.py enables every package in the System repo: in a timer
  in the GUI (after the prefs load), and as --python ahead of the caller's args in
  blender-run --extensions (a failed enable exits 1 before the caller's script).
- It also patches SurfacePsycho's sp_overwrite_segment_selection from eval() to literal_eval():
  the eval walked past MCP safe mode (control: unpatched ran code, patched refuses).
- blender-run: --extensions (bind mounts via --mount so a missing source fails instead of being
  created); USER/LOGNAME set, which CAD Sketcher's getpass needs.
- compose.yaml mounts the repo read-only and the hook into the GUI container. NOT yet deployed.
- scripts/blender-probes/extensions_acceptance.py: one operator run per add-on, safe-mode
  compliant. Headless 8/9 online and with --network none; CAD Sketcher sketching is GUI-only.
  A Python audit hook saw no network/process events (positive control fired).
This commit is contained in:
vh
2026-09-28 12:50:57 -07:00
parent 7bd00ae77a
commit 83dc497b40
9 changed files with 675 additions and 9 deletions
+114 -1
View File
@@ -29,7 +29,8 @@ stays down.**
A one-shot `docker run --rm` of this image with Blender as the entrypoint. It needs no desktop and
does not collide with the GUI container's up/down. `--job DIR` stages a local dir to
`/tank/blender/jobs/<name>/` and copies results back. Engines tested headless on 2026-09-28:
Cycles GPU and CPU, EEVEE (EGL), Workbench. STL import is built in; there is **no STEP importer**.
Cycles GPU and CPU, EEVEE (EGL), Workbench. STL import is built in. **`--extensions`** also
enables the pinned add-on set (STEP import and export among them; see "Extensions" below).
Foot-guns and budget are in `docs/fleettools/blender.md`. First consumer: draupnir.
## Headless rendering inside the running GUI container
@@ -112,3 +113,115 @@ An MCP client on nh3-dev → `scripts/blender-mcp` → the in-container server
in a timer instead.
- A pre-flight `ssh` without `-n` swallowed the MCP client's `initialize`, and the session hung at
init.
## Extensions: the pinned add-on set (2026-09-28)
**Why:** Prime's ruling of 2026-09-28 makes Blender a mandatory stage in draupnir's pipeline
(requirements → functional shape in build123d → industrial design in Blender → print). draupnir
asked for these add-ons (thread `01M3MQEGGR0N981645WNZ9DMF3`). All come from extensions.blender.org,
all are GPL, and all are pinned by version and archive sha256 in [`extensions.lock`](extensions.lock).
| Add-on | Version | For | Wheels |
|---|---|---|---|
| SurfacePsycho | 0.10.4 | NURBS/Bezier patch surfacing; STEP/IGES export (the route back to build123d). Alpha. | cadquery-ocp-novtk 7.9.3.1 (cp313) |
| CAD Sketcher | 0.32.1 | Constraint-based precise profiles | slvs 3.2 (cp313) |
| 3D-Print Toolbox | 1.4.1 | Mesh cleanup (clean non-manifold) and checks before a mesh leaves Blender | none |
| STEP Importer (Clonephaze) | 1.2.1 | STEP in, from vendor parts and functional shapes | cascadio 0.0.18rc8 (abi3) |
| Bool Tool | 2.1.0 | Hard-surface booleans | none |
| LoopTools | 4.7.7 | Mesh helpers | none |
| MeasureIt | 1.8.4 | Dimensions drawn in the viewport (they show in screenshots) | none |
| 3MF Import/Export (Clonephaze) | 2.7.7 | 3MF, which carries units (STL does not) | none |
Deliberately skipped (draupnir): ND, HardOps, BoxCutter (modal only, an agent cannot drive them),
Quad Remesher (paid; the built-in QuadriFlow covers it), QRemeshify (not in the 5.2 catalogue).
### How it is wired
```
stacks/blender/extensions.lock ──scripts/blender-extensions sync──▶ fv-ml1:/tank/blender-extensions/5.2/system
│ mounted READ-ONLY as Blender's
│ System repo (/blender/5.2/extensions/system)
┌───────────────────────────────────────────┴──────────────────────────┐
GUI container (compose.yaml) blender-run --extensions
conf/scripts/startup/fleet_extensions.py enables all the same file runs as --python ahead of the
of it in a timer after the prefs load caller's args; any failure exits 1 first
```
- **Nobody installs from inside Blender.** MCP safe mode blocks `bpy.ops.extensions.*`,
`addon_enable` and `register_class`, and the repository is mounted read-only, so an agent can
neither add an add-on nor alter one. Everything in the System repo is enabled; that directory
holds exactly the lock.
- **Wheels** (OCP, slvs, cascadio) are unpacked by Blender into the USER extensions dir, about 60 MB.
In the GUI that is `/config` (= `/opt/docker/data/blender`, restic). In blender-run it is the
container's `/tmp`, rebuilt every run, so concurrent runs share nothing.
- **`scripts/blender-extensions sync`** downloads each archive (cached in
`/tank/blender-extensions/zips/`), checks its sha256, installs it with Blender's own
`--command extension install-file` into a staging dir, pre-warms and byte-compiles it, checks
it enables read-only, and only then swaps it in. It **refuses while the GUI container or a
blender-run job is running**, because they hold the old directory through the bind mount.
`scripts/blender-extensions status` compares what is installed with the lock.
- **Bumping a version:** edit the lock row, re-run the audit below on the new archive, stop the
GUI (`scripts/blender-mcp down`), `scripts/blender-extensions sync`, run the acceptance probe.
### Fleet-local fixes (in `fleet_extensions.py`, both paths)
- **SurfacePsycho `view3d.sp_overwrite_segment_selection` runs `eval()` on its string property.**
That walks straight past MCP safe mode: an agent's `bpy.ops` call passes the AST check, and the
string inside it is never parsed. Nothing in the add-on calls that operator, so the hook swaps
`eval` for `ast.literal_eval`, which keeps its documented use (a literal set of segment ids) and
refuses code. **Control (2026-09-28):** unpatched, the payload `[__import__('os').getpid()]` ran
and returned `[1]`; patched, it raised `ValueError: malformed node`; the literal `{3, 5}` worked
both ways. The hook logs a warning if the upstream code changes.
- **3MF's "please rate us" popup** (after five exports) is switched off.
### Phone-home audit (2026-09-28)
- **Manifests:** none of the eight declares the `network` permission (five declare `files` only).
- **Source:** no add-on imports `socket`, `urllib.request`, `requests`, `http`, `subprocess` or
`webbrowser` (3MF uses `urllib.parse` for path joining only). `wm.url_open` appears only behind
buttons a person clicks (CAD Sketcher's help links, 3MF's rating dialog), and safe mode blocks
`wm.url_open` in agent code anyway. The GUI hook logs `bpy.app.online_access`.
- **Runtime:** the full acceptance probe ran with `docker run --network none` under a Python
audit hook watching `socket.*`, `urllib.Request`, `http.client.*`, `subprocess.Popen`,
`os.system`/`exec`/`posix_spawn` and `webbrowser.open`. **Zero events**, and every operator
passed offline. **Positive control:** one deliberate `socket.getaddrinfo` in the same setup
showed up as an event. **Sensitivity floor:** the hook sees Python-level calls only. The native
wheels (OCCT, SolveSpace) could open a socket without Python seeing it, but nothing needed the
network to work, and none of them is a networking library.
### Foot-guns (all measured 2026-09-28)
- **`blender --addons x,y` is not the same as enabling.** It leaves the add-on out of
`preferences.addons`, and Bool Tool and LoopTools read their own prefs in `register()`, so
they failed with a KeyError. The hook enables them the way the Preferences button does.
- **3D-Print Toolbox writes a cache into its own package dir** on first import. On the read-only
mount that fails, which is why `sync` pre-warms the staging copy while it is still writable.
- **CAD Sketcher calls `getpass.getuser()`**, which fails for a uid with no passwd entry.
blender-run sets `USER`; the GUI's `abc` user exists.
- **CAD Sketcher's sketch operators need the GUI.** Creating a sketch activates a workspace tool,
and in `blender -b` there is none: `'NoneType' object has no attribute 'widget'`. The add-on
loads headless and its solver (`slvs`) imports; sketch authoring is a GUI/MCP job.
- **`Object.dimensions` is in local axes** and ignores rotation, so it cannot show which way an
import faces. The probe uses world-space bounds.
- **STEP Importer orientation:** a SurfacePsycho STEP (Z-up, mm) comes back the right way up with
the importer's default `up_axis="Y"`. `up_axis="Z"` stands it on its edge (this is the probe's
control for its own orientation check).
- **SurfacePsycho's default patch is 2 x 2 m** (Blender units), and STEP export scales ×1000 into
millimetres by default. Scale the object to part size first.
- **MeasureIt and LoopTools want a 3D View area.** In the GUI, override with the window's
VIEW_3D area; headless, a screen datablock's VIEW_3D area works (`view3d_override()` in the probe).
### Acceptance
The probe is [`scripts/blender-probes/extensions_acceptance.py`](../../scripts/blender-probes/extensions_acceptance.py):
one real operator run per add-on, written to pass MCP safe mode so the same code runs on both
paths. Files land in `fv-ml1:/tank/blender/acceptance/extensions/`.
**Headless, 2026-09-28:** 8 of 9 checks PASS, both online and with `--network none`: print3d
clean non-manifold (4 → 0 non-manifold edges), Bool Tool auto difference, LoopTools circle
(radius spread 4.14 mm → 0), MeasureIt segment, SurfacePsycho patch → STEP
(`sp-patch-headless.step`, 20 × 20 mm), STEP Importer read-back (20 × 20 × 0 mm world, plus the
wrong-axis control), 3MF out and back (20 mm cube kept its size). The one FAIL is CAD Sketcher,
for the GUI-only reason above. These runs used the same docker invocation blender-run makes.
**MCP (GUI) path:** pending the stack deploy that mounts the repo and hook into the GUI container.
+5
View File
@@ -43,6 +43,11 @@ services:
# startup hook that enables it and keeps its socket serving. Read-only; update via the repo.
- /opt/docker/conf/blender/scripts/addons/blender_mcp.py:/config/.config/blender/5.2/scripts/addons/blender_mcp.py:ro
- /opt/docker/conf/blender/scripts/startup/fleet_mcp.py:/config/.config/blender/5.2/scripts/startup/fleet_mcp.py:ro
# Pinned extensions (stacks/blender/extensions.lock, built by scripts/blender-extensions sync)
# as Blender's System repository, READ-ONLY: agents cannot install or alter add-ons. The
# startup hook enables every package in it once the prefs have loaded. README "Extensions".
- /tank/blender-extensions/5.2/system:/blender/5.2/extensions/system:ro
- /opt/docker/conf/blender/scripts/startup/fleet_extensions.py:/config/.config/blender/5.2/scripts/startup/fleet_extensions.py:ro
ports:
- "${HTTPS_PORT:-3001}:3001"
# ⚠ NO port for the MCP add-on socket (it runs arbitrary Python, no auth). It listens on the
@@ -0,0 +1,144 @@
"""Fleet extensions: enable the pinned add-ons in Blender's System extension repository, in the GUI
container and in `blender-run --extensions`. Part of eshpfi-management stacks/blender; see its
README, section "Extensions".
The add-ons (versions and sha256 pinned in conf/extensions.lock) are installed by
scripts/blender-extensions into fv-ml1:/tank/blender-extensions/5.2/system. Both the GUI container
and blender-run mount that directory READ-ONLY as the System repository
(/blender/5.2/extensions/system). Nobody installs anything from inside Blender: MCP safe mode blocks
bpy.ops.extensions.*, addon_enable and register_class, and the repository is read-only anyway.
Every package in that directory is enabled, because the directory holds exactly the pinned set.
This file runs in one of two ways:
- GUI: from the user scripts/startup dir, at every launch. The add-ons are enabled in a timer,
after the user preferences have loaded, because an earlier enable is undone by the prefs load
(same trap as fleet_mcp.py). Progress goes to /config/.local/state/fleet_extensions.log.
- Headless: blender-run --extensions passes this file as `--python` ahead of the caller's own
arguments. If any add-on fails to enable it raises, and with --python-exit-code the run exits 1
before the caller's script starts, so a job never runs silently without an add-on it needs.
Enabling follows the Preferences "enable" button: refresh the extension wheels with the pending
modules listed, then addon_utils.enable(default_set=True). `blender --addons` is NOT equivalent:
it leaves the add-on out of preferences.addons, and Bool Tool and LoopTools read their own prefs
in register() and fail with a KeyError (found 2026-09-28).
"""
import ast
import inspect
import os
import sys
import time
import traceback
import addon_utils
import bpy
REPO = "system"
LOG = "/config/.local/state/fleet_extensions.log"
def log(msg):
if bpy.app.background:
print(f"fleet_extensions: {msg}", file=sys.stderr, flush=True)
return
os.makedirs(os.path.dirname(LOG), exist_ok=True)
with open(LOG, "a") as f:
f.write(f"{time.strftime('%Y-%m-%d %H:%M:%S')} {msg}\n")
def repo_dir():
for repo in bpy.context.preferences.extensions.repos:
if repo.module == REPO:
return repo.directory
raise RuntimeError(f"no '{REPO}' extension repository in the preferences")
def packages():
"""Package ids in the System repository (one directory with a manifest per package)."""
d = repo_dir()
if not os.path.isdir(d):
return []
return sorted(n for n in os.listdir(d) if os.path.isfile(os.path.join(d, n, "blender_manifest.toml")))
def enable_all():
"""Enable every System-repository package. Returns (modules, failed, errors)."""
modules = [f"bl_ext.{REPO}.{p}" for p in packages()]
if not modules:
raise RuntimeError(f"no extensions in {repo_dir()}: is /tank/blender-extensions mounted?")
errors = []
addon_utils.extensions_refresh(
ensure_wheels=True,
addon_modules_pending=modules,
handle_error=lambda ex: errors.append(f"wheels: {ex}"),
)
for m in modules:
if not addon_utils.check(m)[1]:
addon_utils.enable(m, default_set=True, handle_error=lambda ex, m=m: errors.append(f"{m}: {ex!r}"))
failed = [m for m in modules if not addon_utils.check(m)[1]]
harden()
return modules, failed, errors
def harden():
"""Fleet-local fixes applied on top of the pinned add-ons. Each one names what it guards."""
# SurfacePsycho 0.10.4: view3d.sp_overwrite_segment_selection runs eval() on its string
# property. That walks straight past MCP safe mode: an agent's bpy.ops call passes the AST
# check, and the string inside it is never parsed. Nothing in the add-on calls this operator
# (audited 2026-09-28), so literal_eval keeps its documented use (a literal set/list of
# segment ids) and refuses code.
try:
from bl_ext.system.surfacepsycho.tools import overlay_segment_selection as oss
except ImportError:
oss = None
cls = getattr(oss, "SP_OT_overwrite_segment_selection", None)
if cls is not None and not getattr(cls.execute, "fleet_hardened", False):
if " eval(self.select_string)" in inspect.getsource(cls.execute):
def execute(self, context):
oss.SELECTED_SEGMENTS.clear()
for s in ast.literal_eval(self.select_string):
oss.SELECTED_SEGMENTS.append(s)
return {"FINISHED"}
execute.fleet_hardened = True
cls.execute = execute
log("hardened: surfacepsycho sp_overwrite_segment_selection eval -> literal_eval")
else:
log("WARNING: surfacepsycho sp_overwrite_segment_selection changed upstream; re-audit it")
# 3MF Import/Export 2.7.7 opens a "please rate us" popup after five exports. Off: agents
# export far more than five files and a popup is noise in the viewport screenshots.
entry = bpy.context.preferences.addons.get(f"bl_ext.{REPO}.ThreeMF_io")
if entry is not None and getattr(entry.preferences, "rating_prompt_after", -1) != -1:
entry.preferences.rating_prompt_after = -1
def _gui_timer():
"""GUI: runs once, after the user prefs have loaded."""
try:
modules, failed, errors = enable_all()
for e in errors:
log(f"error: {e}")
log(f"enabled {len(modules) - len(failed)}/{len(modules)}" + (f"; FAILED: {', '.join(failed)}" if failed else ""))
log(f"online access: {bpy.app.online_access}")
except Exception:
log("enable_all failed:\n" + traceback.format_exc())
return None
def register():
if bpy.app.background:
return
bpy.app.timers.register(_gui_timer, first_interval=2.0, persistent=True)
def unregister():
pass
if __name__ == "__main__":
# Headless (blender-run --extensions): fail the run if anything did not enable.
_modules, _failed, _errors = enable_all()
for _e in _errors:
log(f"error: {_e}")
if _failed:
raise RuntimeError(f"extensions failed to enable: {', '.join(_failed)}")
log(f"enabled {len(_modules)}: {', '.join(m.rsplit('.', 1)[1] for m in _modules)}")
+19
View File
@@ -0,0 +1,19 @@
# Blender extensions baked into fv-ml1's Blender, for the GUI (MCP) and for blender-run --extensions.
# See stacks/blender/README.md, section "Extensions". Built by scripts/blender-extensions sync.
#
# Pinned 2026-09-28 from extensions.blender.org for Blender 5.2 / linux-x64 (draupnir's request,
# Prime's ruling that Blender is a mandatory pipeline stage). All GPL. None declares the
# "network" permission; the code audit and the controls are in the README.
#
# Bumping a row = re-audit that add-on (README "Extensions" -> Audit), then run
# `scripts/blender-extensions sync` with the GUI container down.
#
# id version sha256 of the archive archive url
surfacepsycho 0.10.4 ea889cbbced58b069767b28186946b3f4caf3890e2ca3139d1163b1aa867db69 https://extensions.blender.org/download/sha256:ea889cbbced58b069767b28186946b3f4caf3890e2ca3139d1163b1aa867db69/add-on-surfacepsycho-v0.10.4-linux-x64.zip
CAD_Sketcher 0.32.1 2188c91753b8178cc3dc49384d69ddd18264aa468b66341db565700adbb398c6 https://extensions.blender.org/download/sha256:2188c91753b8178cc3dc49384d69ddd18264aa468b66341db565700adbb398c6/add-on-cad-sketcher-v0.32.1-linux-x64.zip
print3d_toolbox 1.4.1 cf5952c84d802a8df67368fd866e8fc01424bd1d71ab5db39d187dfbcfc6f2fd https://extensions.blender.org/download/sha256:cf5952c84d802a8df67368fd866e8fc01424bd1d71ab5db39d187dfbcfc6f2fd/add-on-print3d-toolbox-v1.4.1.zip
step_importer 1.2.1 9db6fa4a7f11c9cd1e43c061a4cdb3b1d4a376847991d60c94e80c9fb075c2ef https://extensions.blender.org/download/sha256:9db6fa4a7f11c9cd1e43c061a4cdb3b1d4a376847991d60c94e80c9fb075c2ef/add-on-step-importer-v1.2.1-linux-x64.zip
bool_tool 2.1.0 d3a282db25925d115dd1a7638aa28116f2f9198423b0afb6179e8127d59c06e1 https://extensions.blender.org/download/sha256:d3a282db25925d115dd1a7638aa28116f2f9198423b0afb6179e8127d59c06e1/add-on-bool-tool-v2.1.0.zip
looptools 4.7.7 ff1ca3b3fff73094379da8b1fa2c1acbc9d88d26b7dfc73bb9de5941a6b50108 https://extensions.blender.org/download/sha256:ff1ca3b3fff73094379da8b1fa2c1acbc9d88d26b7dfc73bb9de5941a6b50108/add-on-looptools-v4.7.7.zip
measureit 1.8.4 85b1836d97e5c2f0311afdf45cf9fd3cefa71bade074963864ce40ee15c26042 https://extensions.blender.org/download/sha256:85b1836d97e5c2f0311afdf45cf9fd3cefa71bade074963864ce40ee15c26042/add-on-measureit-v1.8.4.zip
ThreeMF_io 2.7.7 17c85812a331f8a7244629e3ee10a1aa0c7f7dc2a9eb9d60919677bba6e82d1d https://extensions.blender.org/download/sha256:17c85812a331f8a7244629e3ee10a1aa0c7f7dc2a9eb9d60919677bba6e82d1d/add-on-threemf-io-v2.7.7.zip