exthost.catalog (suite/extcat.py, its own module): GET /ext/catalog answers the index the host keeps and the one address it is fetched from. On a scratch root under /tmp, with a throwaway key standing in for the OpenGlow extension key, the machine's own forgeext keeps an index signed with it, and the author key it names for one id makes a package of that id read as community and endorsed, where before it was unverified; the same key on another id counts for nothing. On the machine's own root that index is refused in words, a package handed over as an index is refused by the product gate, and the index kept is left as it was. The relay refuses an id with no such form (400) and one the kept index does not list (404, or 409 with none kept) before anything is fetched, and a refresh from the fixed address keeps OpenGlow's index when one is published there and is 502 in curl's words when none is, the kept index left as it was. Nothing is left in the staging directory. The coverage lint had a gap: coverage_report() let the allowlist's docs/** and **/*.md take out a path the BEHAVIORAL list keeps in every fingerprint, so the four first-run advisory documents were covered by no test and the lint passed. A change to the privacy advisory would have invalidated nothing. A behavioral path is now never allowed away, and setup.advisories-rehash, which accepts every first-run document at its current hash, covers the four. Proof: on the bench reference, with forgectrl 848ccc1 and forgeext a64b933 bind-mounted and the privacy document accepted again at its new hash with the fixture's press, exthost.catalog PASS (the refresh was 502: GitHub answered 404, nothing is published at the address yet), and setup.advisories-rehash PASS with the rest of the campaign. The lint's new unit test reports the uncovered advisory, and the old reading (the override ignored) reports nothing for it, which is the gap. forgetest's unit tests pass (452), and the coverage lint passes with --enforce.
OpenGlow / ForgeFIRM firmware for Glowforge
BETA
ForgeFIRM is in beta. Every release below 0.1.0 is a beta release. Expect problems, and expect frequent updates. Upgrade whenever a newer release is available, and report what you find on the community forum.
Open firmware for Glowforge brand CNC lasers. ForgeFIRM replaces the cloud-dependent factory software on the stock control board, with no hardware modification, and gives the machine a local controller, a local web control panel, and a standard Grbl interface. The factory cloud experience stays available as an option.
This repository is the base of the build and of the release: the
meta-forgefirm Yocto layer, the kas configuration, the image recipes, the
install and release scripts, the acceptance tool (forgetest/), the bench
tools (scripts/bench/), the bench actuator firmware (fixture/), and the
release artifacts (releases/).
Start here
https://docs.forgefirm.org/ is the documentation, and the source of truth for every fact about the machine and the firmware.
| Read this first | Safety |
| Put it on a machine | Installation |
| Use it | Usage, LightBurn |
| How the machine works | Technical |
| How ForgeFIRM works with it | ForgeFIRM internals |
| Build, test, release | Developers |
| Downloads | Releases |
| Questions | Community forum |
Build
kas build kas/forgefirm-glowforge.yml
Build covers the host setup, the two images, the source variant and the debug kernel. Release flow covers the pins, the push order and the signing pipeline.
Test
cd forgetest && python3 -m unittest discover -s tests -v
The acceptance catalog that gates a release, and the bench tools, are on Acceptance and The bench.
Contributing
AGENTS.md carries the rules for this repository and for the project: safety ordering, proof before done, the push order, and the writing rules. They apply to human contributors too, and Contribute is the same set on the site.
What this costs
Nothing. ForgeFIRM is free in both senses, under MIT and GPL licenses. There is no paid tier, no license key, no subscription and no Pro edition. If someone offers to sell it to you, the licenses allow it, but what you take home is their build rather than this one: get it from the source.
Safety
These machines contain a CO2 laser: it burns, blinds, and starts fires. Never defeat the lid switches or the interlock. Never leave a running job unattended. Keep a fire extinguisher within reach. Read Safety before you cut your first job, and Regulatory and legal before you install.
This is experimental software. Use of it could seriously maim or kill you or others, and it may void your warranty. Use it at your own risk.
Glowforge is a trademark of Glowforge, Inc. This project is not affiliated with, authorized by, or endorsed by Glowforge, Inc.