feat(blender): pinned extension set in a read-only System repo, for the GUI and blender-run --extensions
Blender is now a mandatory stage in draupnir's pipeline (Prime, 2026-09-28), and draupnir asked for eight add-ons from extensions.blender.org: SurfacePsycho 0.10.4, CAD Sketcher 0.32.1, 3D-Print Toolbox 1.4.1, STEP Importer 1.2.1, Bool Tool 2.1.0, LoopTools 4.7.7, MeasureIt 1.8.4, 3MF Import/Export 2.7.7. - stacks/blender/extensions.lock pins each by version and archive sha256. - scripts/blender-extensions sync builds fv-ml1:/tank/blender-extensions/5.2/system with Blender's own install-file, pre-warms and byte-compiles it, checks a read-only enable, then swaps it in. It refuses while the GUI or a blender-run job holds the old directory. - conf/scripts/startup/fleet_extensions.py enables every package in the System repo: in a timer in the GUI (after the prefs load), and as --python ahead of the caller's args in blender-run --extensions (a failed enable exits 1 before the caller's script). - It also patches SurfacePsycho's sp_overwrite_segment_selection from eval() to literal_eval(): the eval walked past MCP safe mode (control: unpatched ran code, patched refuses). - blender-run: --extensions (bind mounts via --mount so a missing source fails instead of being created); USER/LOGNAME set, which CAD Sketcher's getpass needs. - compose.yaml mounts the repo read-only and the hook into the GUI container. NOT yet deployed. - scripts/blender-probes/extensions_acceptance.py: one operator run per add-on, safe-mode compliant. Headless 8/9 online and with --network none; CAD Sketcher sketching is GUI-only. A Python audit hook saw no network/process events (positive control fired).
This commit is contained in:
@@ -43,6 +43,11 @@ services:
|
||||
# startup hook that enables it and keeps its socket serving. Read-only; update via the repo.
|
||||
- /opt/docker/conf/blender/scripts/addons/blender_mcp.py:/config/.config/blender/5.2/scripts/addons/blender_mcp.py:ro
|
||||
- /opt/docker/conf/blender/scripts/startup/fleet_mcp.py:/config/.config/blender/5.2/scripts/startup/fleet_mcp.py:ro
|
||||
# Pinned extensions (stacks/blender/extensions.lock, built by scripts/blender-extensions sync)
|
||||
# as Blender's System repository, READ-ONLY: agents cannot install or alter add-ons. The
|
||||
# startup hook enables every package in it once the prefs have loaded. README "Extensions".
|
||||
- /tank/blender-extensions/5.2/system:/blender/5.2/extensions/system:ro
|
||||
- /opt/docker/conf/blender/scripts/startup/fleet_extensions.py:/config/.config/blender/5.2/scripts/startup/fleet_extensions.py:ro
|
||||
ports:
|
||||
- "${HTTPS_PORT:-3001}:3001"
|
||||
# ⚠ NO port for the MCP add-on socket (it runs arbitrary Python, no auth). It listens on the
|
||||
|
||||
Reference in New Issue
Block a user