Compare commits

..
9 changed files with 97 additions and 50 deletions
-2
View File
@@ -4094,8 +4094,6 @@ int CLI::run(int argc, char **argv)
flush_and_exit(CLI_MIXED_FILAMENT_INVALID);
}
}
if (filament_count > 0)
resize_mixed_filament_metadata(m_print_config, size_t(filament_count), size_t(filament_count));
m_print_config.option<ConfigOptionEnum<PrinterTechnology>>("printer_technology", true)->value = printer_technology;
+18
View File
@@ -3601,6 +3601,24 @@ void PresetBundle::export_selections(AppConfig &config)
BOOST_LOG_TRIVIAL(info) << __FUNCTION__ << boost::format(": printer %1%, print %2%, filaments[0] %3% ")%printers.get_selected_preset_name() % prints.get_selected_preset_name() %filament_presets[0];
}
// Preserve metadata only for existing colour slots; new slots get false/empty defaults.
static void resize_mixed_filament_metadata(DynamicPrintConfig &config, size_t old_slot_count, size_t new_slot_count)
{
auto resize = [old_slot_count, new_slot_count](auto *opt) {
if (opt) {
opt->values.resize(std::min(old_slot_count, opt->values.size()));
opt->values.resize(new_slot_count);
}
};
resize(config.option<ConfigOptionBools>("filament_is_mixed"));
resize(config.option<ConfigOptionStrings>("filament_mixed_components"));
resize(config.option<ConfigOptionStrings>("filament_mixed_sublayer_ratios"));
resize(config.option<ConfigOptionBools>("filament_mixed_gradient"));
resize(config.option<ConfigOptionStrings>("filament_mixed_gradient_range"));
resize(config.option<ConfigOptionStrings>("filament_mixed_gradient_curve"));
resize(config.option<ConfigOptionBools>("filament_mixed_gradient_per_part"));
}
void PresetBundle::set_num_filaments(unsigned int n, std::string new_color)
{
unsigned old_filament_count = this->filament_presets.size();
-15
View File
@@ -10838,21 +10838,6 @@ void set_filament_dev_options(DynamicPrintConfig &config, const std::vector<cons
}
}
void resize_mixed_filament_metadata(DynamicPrintConfig &config, size_t old_slot_count, size_t new_slot_count)
{
auto resize = [old_slot_count, new_slot_count](auto *opt) {
opt->values.resize(std::min(old_slot_count, opt->values.size()));
opt->values.resize(new_slot_count);
};
resize(config.option<ConfigOptionBools>("filament_is_mixed", true));
resize(config.option<ConfigOptionStrings>("filament_mixed_components", true));
resize(config.option<ConfigOptionStrings>("filament_mixed_sublayer_ratios", true));
resize(config.option<ConfigOptionBools>("filament_mixed_gradient", true));
resize(config.option<ConfigOptionStrings>("filament_mixed_gradient_range", true));
resize(config.option<ConfigOptionStrings>("filament_mixed_gradient_curve", true));
resize(config.option<ConfigOptionBools>("filament_mixed_gradient_per_part", true));
}
//used for object/region config
//use the smallest of multiple to single
-4
View File
@@ -933,10 +933,6 @@ extern std::set<std::string> filament_dev_options;
// filament_configs, one config per filament in slot order, as the filaments' values one after another.
void set_filament_dev_options(DynamicPrintConfig &config, const std::vector<const DynamicPrintConfig *> &filament_configs);
// Orca: sizes the per-slot mixed-colour metadata options to new_slot_count, keeping the first
// old_slot_count values; an option the config lacks is created.
void resize_mixed_filament_metadata(DynamicPrintConfig &config, size_t old_slot_count, size_t new_slot_count);
extern void update_static_print_config_from_dynamic(ConfigBase& config, const DynamicPrintConfig& dest_config, std::vector<int> variant_index, std::set<std::string>& key_set1, int stride = 1);
extern void compute_filament_override_value(const std::string& opt_key, const ConfigOption *opt_old_machine, const ConfigOption *opt_new_machine, const ConfigOption *opt_new_filament, const DynamicPrintConfig& new_full_config,
t_config_option_keys& diff_keys, DynamicPrintConfig& filament_overrides, std::vector<int>& f_map_indices);
+74 -9
View File
@@ -115,6 +115,9 @@ static const std::unordered_map<std::string, AuditEventCategory> audit_event_cat
{"subprocess.Popen", AuditEventCategory::ProcessCreate},
{"_winapi.CreateProcess", AuditEventCategory::ProcessCreate},
{"_posixsubprocess.fork_exec", AuditEventCategory::ProcessCreate},
// threading
{"_thread.start_new_thread", AuditEventCategory::Threading},
};
// Returns the category event_name belongs to, or AuditEventCategory::None when it isn't audited.
@@ -735,6 +738,12 @@ std::vector<std::string> audit_targets(const std::string& event_name, AuditEvent
}
return targets;
}
case AuditEventCategory::Threading:
// Thread creation exposes no user-supplied target. Use a fixed sentinel so the grant
// persists per plugin: the permission list matches targets by exact string, and the
// started function's repr embeds an address that changes every run.
targets.emplace_back("thread");
return targets;
default:
break;
}
@@ -761,6 +770,7 @@ std::vector<std::string>* permission_list_for(AuditEventCategory category, Plugi
case AuditEventCategory::Http: return &permissions.network_http;
case AuditEventCategory::Socket: return &permissions.network_socket;
case AuditEventCategory::ProcessCreate: return &permissions.process;
case AuditEventCategory::Threading: return &permissions.threading;
default: return nullptr;
}
}
@@ -832,11 +842,74 @@ wxString audit_message(AuditEventCategory category, const wxString& plugin_name,
return wxString::Format(_L("Plugin \"%s\" is requesting to open a network connection to:\n%s"), plugin_name, target_list);
case AuditEventCategory::ProcessCreate:
return wxString::Format(_L("Plugin \"%s\" is requesting to run the following command(s):\n%s"), plugin_name, target_list);
case AuditEventCategory::Threading:
return wxString::Format(_L("Plugin \"%s\" is requesting permission to create a thread."), plugin_name);
default:
return wxString::Format(_L("Plugin \"%s\" is requesting permission for the Python audit event \"%s\"."), plugin_name, event_name);
}
}
// Builds and shows the modal permission prompt. Must run on the GUI thread.
bool prompt_for_targets(AuditEventCategory category, const std::string& plugin_name, const std::string& event_name,
const std::vector<std::string>& unresolved)
{
wxString target_list;
for (const auto& target : unresolved)
target_list += wxString::FromUTF8(target.c_str()) + "\n";
wxMessageDialog dialog(nullptr,
audit_message(category, wxString::FromUTF8(plugin_name.c_str()),
wxString::FromUTF8(event_name.c_str()), target_list),
_L("Plugin permission request"), wxYES_NO | wxICON_WARNING);
return dialog.ShowModal() == wxID_YES;
}
// Records a grant in the plugin's sidecar so it is not asked again. Reads the install state
// freshly because the async prompt outlives the caller's stack copy of it.
void persist_grant(const std::string& plugin_key, AuditEventCategory category, const std::vector<std::string>& targets)
{
PluginInstallState state;
if (!PluginManager::instance().get_install_state(plugin_key, state))
return;
std::vector<std::string>* permission_list = permission_list_for(category, state.permissions);
if (!permission_list)
return;
for (const auto& target : targets)
persist_permission(plugin_key, state, *permission_list, target);
}
// Requests permission for an audited event, returning true when it is already granted or the user
// approves an inline prompt.
//
// An audited event can fire on a thread the UI thread may itself be blocked waiting on: the
// SlicingPipeline hook runs on the slicing worker thread (see PluginHooks.cpp), and
// BackgroundSlicingProcess::stop()/stop_internal() park the UI thread until that worker stops.
// Blocking the worker on a marshaled modal -- which is safe for the plugin-load worker that
// request_filesystem_read_permissions runs on -- would therefore deadlock the application (the
// invariant PluginHostUi.cpp documents for slicing-hook UI calls). Off the main thread the prompt
// is therefore posted asynchronously and the current event denied (fail closed, like an unanswered
// prompt); the grant is persisted once the user accepts, so a later attempt succeeds without
// re-prompting.
bool request_permission(AuditEventCategory category, const std::string& plugin_key, const std::string& plugin_name,
const std::string& event_name, const std::vector<std::string>& unresolved)
{
if (wxTheApp == nullptr || GUI::wxGetApp().is_closing())
return false;
if (wxIsMainThread())
return prompt_for_targets(category, plugin_name, event_name, unresolved);
GUI::wxGetApp().CallAfter([category, plugin_key, plugin_name, event_name, unresolved]() {
if (wxTheApp == nullptr || GUI::wxGetApp().is_closing())
return;
if (prompt_for_targets(category, plugin_name, event_name, unresolved))
persist_grant(plugin_key, category, unresolved);
});
return false;
}
int decide_audited_event(PluginAuditManager& mgr,
PluginInstallState& state,
const std::string& plugin_key,
@@ -857,15 +930,7 @@ int decide_audited_event(PluginAuditManager& mgr,
return 0;
}
wxString target_list;
for (const auto& target : unresolved)
target_list += wxString::FromUTF8(target.c_str()) + "\n";
wxMessageDialog dialog(nullptr,
audit_message(category, wxString::FromUTF8(plugin_name.c_str()),
wxString::FromUTF8(event_name.c_str()), target_list),
_L("Plugin permission request"), wxYES_NO | wxICON_WARNING);
if (dialog.ShowModal() != wxID_YES)
if (!request_permission(category, plugin_key, plugin_name, event_name, unresolved))
return report_denied(mgr, event_name, {false, "audit permission required"});
if (permission_list)
+2
View File
@@ -807,6 +807,7 @@ bool read_install_state(const boost::filesystem::path& plugin_dir, PluginInstall
read_string_list("network_http", parsed.permissions.network_http);
read_string_list("network_socket", parsed.permissions.network_socket);
read_string_list("process", parsed.permissions.process);
read_string_list("threading", parsed.permissions.threading);
}
if (state.contains("enabled") && state["enabled"].is_boolean())
@@ -850,6 +851,7 @@ bool write_install_state(const boost::filesystem::path& plugin_dir, const Plugin
{"network_http", state.permissions.network_http},
{"network_socket", state.permissions.network_socket},
{"process", state.permissions.process},
{"threading", state.permissions.threading},
};
nlohmann::json capabilities = nlohmann::json::array();
+1
View File
@@ -92,6 +92,7 @@ struct PluginPermissions
std::vector<std::string> network_http;
std::vector<std::string> network_socket;
std::vector<std::string> process;
std::vector<std::string> threading;
};
struct PluginInstallState {
@@ -826,23 +826,3 @@ TEST_CASE("The device drying options are rebuilt as each filament's values in sl
set_filament_dev_options(config, {&two_values, &no_value});
REQUIRE(config.option<ConfigOptionStrings>("filament_dev_ams_drying_ams_limitations")->values == std::vector<std::string>({"1", "0", ""}));
}
TEST_CASE("The mixed filament metadata is sized to the filament count", "[Config]")
{
DynamicPrintConfig config;
config.option<ConfigOptionBools>("filament_is_mixed", true)->values = {false, false, true};
config.option<ConfigOptionStrings>("filament_mixed_components", true)->values = {"", "", "1,2"};
config.option<ConfigOptionBools>("filament_mixed_gradient", true)->values = {false};
config.option<ConfigOptionStrings>("filament_mixed_gradient_range", true)->values = {""};
resize_mixed_filament_metadata(config, 3, 3);
REQUIRE(config.option<ConfigOptionBools>("filament_is_mixed")->values == std::vector<unsigned char>({false, false, true}));
REQUIRE(config.option<ConfigOptionStrings>("filament_mixed_components")->values == std::vector<std::string>({"", "", "1,2"}));
REQUIRE(config.option<ConfigOptionBools>("filament_mixed_gradient")->values == std::vector<unsigned char>({false, false, false}));
REQUIRE(config.option<ConfigOptionStrings>("filament_mixed_gradient_range")->values == std::vector<std::string>({"", "", ""}));
REQUIRE(config.option<ConfigOptionStrings>("filament_mixed_gradient_curve")->values == std::vector<std::string>({"", "", ""}));
resize_mixed_filament_metadata(config, 2, 4);
REQUIRE(config.option<ConfigOptionBools>("filament_is_mixed")->values == std::vector<unsigned char>({false, false, false, false}));
REQUIRE(config.option<ConfigOptionStrings>("filament_mixed_components")->values == std::vector<std::string>({"", "", "", ""}));
}
@@ -122,6 +122,7 @@ TEST_CASE("install-state sidecar is the source of truth for a cloud plugin's ins
state.permissions.network_http = {"https://api.example.com"};
state.permissions.network_socket = {"192.168.45.6:443"};
state.permissions.process = {"/usr/bin/curl"};
state.permissions.threading = {"thread"};
REQUIRE(write_install_state(plugin_dir, state));
// Permission data is persisted in the same sidecar as the installation metadata.
@@ -132,6 +133,7 @@ TEST_CASE("install-state sidecar is the source of truth for a cloud plugin's ins
CHECK(persisted.permissions.network_http == state.permissions.network_http);
CHECK(persisted.permissions.network_socket == state.permissions.network_socket);
CHECK(persisted.permissions.process == state.permissions.process);
CHECK(persisted.permissions.threading == state.permissions.threading);
// Reading the sidecar back onto a freshly-scanned descriptor (whose header version is still
// 1.0.0) must surface the cloud-installed 1.2.0. This is what lets update_cloud_metadata compare