The image installs forgeext beside forgefirm-sandbox. The recipe installs the init script from forgeext's own tree (start 91, after forgectrl at 90, whose read-only routes the host takes the machine's state from; stop 9, down before it). The host runs nothing while ext_enabled is 0, the default. setup.extensions-consent (takeover): the Extensions advisory is served and is no first-run document; ext_enabled=1 is refused without the advisory's hash, with a stale one, without the phrase, with the phrase in another case, and whole beside a write the daemon refuses, each leaving the setting and the record on disk untouched; with the hash and the phrase it is accepted, recorded under on_demand.extensions, and the data directory gains the search bit and nothing else. The setting, the directory's mode, and the record are put back, the record under a forgectrl restart. exthost.service (takeover): a reference package built on the board, signed with a key made there and added as an owner key. It is unverified before the key is the owner's and community after; the install is refused without the consent. Turned on over the advisory, the service is looked at from outside (account, no_new_privs, seccomp, group, limits, chain) and from inside (what it can read, write, dial, and open), its first line is looked for in the forgeext logger's file, safe mode stops it, a host killed with the service in its quiet loop takes it along within 2 s and comes back, and ext_enabled=0 leaves no group and no chain. The package, the key, the setting, the mode, and the record are put back, and the extension root is compared with how it was found. The reference package exists only while the test runs: no image carries it, and no image trusts its key. Proven. forgetest's unit suite: 422 tests pass, 0 undefined names. On the bench reference, image 20260920211625 with the cross-built forgectrl and host from /tmp: setup.extensions-consent PASS and, against the image's own daemon, FAIL at its first request; exthost.service PASS and, with the init wrapper's kill taken out, FAIL at the killed-host check. The first runs of exthost.service found what the host tests could not: /data/forgefirm is 0700 on the bench reference, and the service ended with EACCES on its own entry point until forgectrl opened the directory for search with the consent. Acceptance. Both tests are new. exthost.service covers forgeext whole and forgectrl's src/main.c and src/logs.*; setup.extensions-consent covers forgectrl's consent path. The recipe, the image line, and the init script's install are layer content, in the platform identity of every fingerprint. forgeext joins scripts/manifest-from-tree.py with its first pin.
OpenGlow / ForgeFIRM firmware for Glowforge
BETA
ForgeFIRM is in beta. Every release below 0.1.0 is a beta release. Expect problems, and expect frequent updates. Upgrade whenever a newer release is available, and report what you find on the community forum.
Open firmware for Glowforge brand CNC lasers. ForgeFIRM replaces the cloud-dependent factory software on the stock control board, with no hardware modification, and gives the machine a local controller, a local web control panel, and a standard Grbl interface. The factory cloud experience stays available as an option.
This repository is the base of the build and of the release: the
meta-forgefirm Yocto layer, the kas configuration, the image recipes, the
install and release scripts, the acceptance tool (forgetest/), the bench
tools (scripts/bench/), the bench actuator firmware (fixture/), and the
release artifacts (releases/).
Start here
https://docs.forgefirm.org/ is the documentation, and the source of truth for every fact about the machine and the firmware.
| Read this first | Safety |
| Put it on a machine | Installation |
| Use it | Usage, LightBurn |
| How the machine works | Technical |
| How ForgeFIRM works with it | ForgeFIRM internals |
| Build, test, release | Developers |
| Downloads | Releases |
| Questions | Community forum |
Build
kas build kas/forgefirm-glowforge.yml
Build covers the host setup, the two images, the source variant and the debug kernel. Release flow covers the pins, the push order and the signing pipeline.
Test
cd forgetest && python3 -m unittest discover -s tests -v
The acceptance catalog that gates a release, and the bench tools, are on Acceptance and The bench.
Contributing
AGENTS.md carries the rules for this repository and for the project: safety ordering, proof before done, the push order, and the writing rules. They apply to human contributors too, and Contribute is the same set on the site.
What this costs
Nothing. ForgeFIRM is free in both senses, under MIT and GPL licenses. There is no paid tier, no license key, no subscription and no Pro edition. If someone offers to sell it to you, the licenses allow it, but what you take home is their build rather than this one: get it from the source.
Safety
These machines contain a CO2 laser: it burns, blinds, and starts fires. Never defeat the lid switches or the interlock. Never leave a running job unattended. Keep a fire extinguisher within reach. Read Safety before you cut your first job, and Regulatory and legal before you install.
This is experimental software. Use of it could seriously maim or kill you or others, and it may void your warranty. Use it at your own risk.
Glowforge is a trademark of Glowforge, Inc. This project is not affiliated with, authorized by, or endorsed by Glowforge, Inc.