Running from a git checkout? The old docker-compose.yml is now
docker-compose.advanced.yml; docker-compose.yml now runs the single-container
image. See UPGRADE.md before pulling.
Compose installs: both Compose files now mount one printstash volume at
/data instead of five. Copy your data into it before starting the new file
(one command, in UPGRADE.md), or the app starts empty at first-run setup.
Added
-
ZIP uploads now prepare and validate their contents as a visible background
Job. When ready, a notification and Tasks open a folder-based file picker;
only selected 3D files are imported, through a second Job. The upload itself
appears in Tasks immediately, leaves the form free, and can be cancelled;
transfer failures remain visible there. During transfer, Tasks shows bytes,
percentage, upload speed and estimated time remaining. Large ZIPs stream
through the web proxy without an extra buffered copy; Tasks distinguishes
browser transfer, server receipt and ZIP preparation. The ZIP picker has
consistent folder and file cards, and can select whole folders or every
importable file in one action. -
OrcaSlicer uploads now carry one versioned native metadata context. Exact
single-object source matches become idempotentneeds_testG-code Revisions;
named-but-unknown or ambiguous sources fail without orphan rows,
multi-object plates never attach to their first object, and.gcode.3mf
context is supported.
The standard-library hook also has a non-secret diagnostic mode and keeps
exiting successfully when PrintStash is unavailable. -
Settings → Background work shows every lane with a runtime concurrency
override, each kind of Job with its queue and schedule, the processes running
work, and recent failures to retry; administrators can derive missing or
regenerate every thumbnail or metadata output. Each source Artifact shows what
is still being prepared and offers a retry for a failure. -
Optional workers:
docker-compose.advanced.yml --profile workersadds
python -m app.workercontainers beside the API, on PostgreSQL with the
API's volumes, declared withVAULT_SHARED_STORAGE=true; with
VAULT_API_RUNS_JOBS=falsethe API leaves every Job to them. Realtime notices
cross processes over PostgreSQLNOTIFY. Both Compose files keep running
everything in one process by default..env.exampledocuments the
background-work settings, and the advanced file forwards
VAULT_MAX_RENDER_JOBSandVAULT_JOBS_INGEST_CONCURRENCY;
VAULT_INGEST_WORKER_COUNT, which nothing read, is gone. -
Similar candidates are available from the Model detail Similar tab. The
library-wide Similar Models page is linked from Library tools on desktop and
remains in mobile navigation. -
The search bar now uses an icon-only AI control to switch between AI and
keyword results. Search results use the full browsing surface with visible
filters and simpler result cards instead of a nested results panel. Print
duration filters show readable time in the results toolbar. -
First administrator from the deployment.
VAULT_SETUP_MODE=environment
withVAULT_SETUP_ADMIN_USERNAMEandVAULT_SETUP_ADMIN_PASSWORD(plus
optionalVAULT_SETUP_ADMIN_EMAIL) creates the first administrator at
startup, for app-store install forms and unattended deployments that cannot
use browser registration. The administrator signs in and chooses storage in
the browser. The variables are used once and never change an existing
account. The mode and variables are checked together: a contradicting
combination keeps setup closed instead of silently falling back to browser
registration. -
App-store manifests for Runtipi, Umbrel and CasaOS/ZimaOS live in
catalogues/and are published with each release. The Unraid template now
shows optional administrator username, password and email fields, and the
PUID/PGIDfields, without opening Advanced. -
When the browser cannot create the first administrator, the setup page now
says why and lists what to change: the address PrintStash saw, or the
first-run variables that don't fit together. It previously showed a single
"registration is disabled" message. -
DXF files can be imported as source Artifacts, downloaded with their original
bytes, and included in backups. Drawing previews are not yet available. -
Managed source Artifacts can be moved to trash and restored individually from
Model detail. The Model, sibling Artifacts, Revisions and print history remain.
Linked Library-source originals stay protected. -
A PNG version of the PrintStash icon for Unraid and other container dashboards
that cannot use SVG icons. -
AI Search adds transactional text indexing for Models, Collections, Multipart
Models and Documents, authorized lexical suggestions, hybrid results with match
evidence, and local image/geometry search. Image queries support file selection,
drag-and-drop and device camera capture. Pinned BGE, CLIP and OpenShape models
use one bounded CPU runtime; acquisition and activation require explicit action.
AI inference is optional and off by default; library features and ordinary
keyword search require no model, inference server or OpenAI account. -
AI Search settings manage encrypted compatible endpoints, model provenance,
capacity estimates and resumable index rebuilds. Serving generations remain
available during replacement; float, int8/binary and approved MRL transforms
preserve native vectors. SQLite/PostgreSQL derivatives can fall back to portable
retrieval and rebuild after restore. Local models warm after restart while
lexical search remains available. -
Separate captions preserve human descriptions and require explicit render
consent. Editable print-history filters use actual duration and timezone-aware
calendar bounds; optional personal natural-language consent enables parsing and
Saved Views. Optional local SPLADE expansion stores bounded weighted terms
separately from original text. The AI master disables these inference consumers;
query text and images stay out of durable search data and request/error logs. -
PostgreSQL supports the existing backup API through verified portable snapshots.
A dry-run-first SQLite-to-PostgreSQL command preserves encrypted fields, IDs,
cyclic library references and native vector bytes without re-embedding. -
Similar Models offers opt-in local geometry analysis, resumable library scans,
a filtered review queue and synchronized comparisons at shared physical scale.
Evidence confirmation keeps each Model, Artifact and Revision separate; verified
part/plate matches can create or extend an existing Multipart Model. -
Full installations can analyze STEP assemblies and use operator-supplied CPU
ONNX models for local text-to-shape or Model queries. Learned neighbors remain
separate from verified geometry, and analysis never downloads model weights. -
Verified, resumable Vault migration with create-only destination copies,
online ingestion deltas, journal-backed cutover recovery, generation-pinned
reads, and explicit receipt-scoped source retention and cleanup (#104). -
Multipart model selection now browses thumbnail cards and nested collections,
pages through large libraries, and keeps multiple selections across searches
and pages. Add selected Models as separate parts or as variants of one part. -
Optional scheduled Quick and Full Vault audits with maintenance windows, safe regression and recovery alerts, history, and verified opt-in derived-data repair.
-
Storage presets: Synology, TrueNAS, QNAP and Unraid mounted-folder guidance; explicit Synology/QNAP WebDAV, MinIO, Garage, SeaweedFS, Hetzner Object Storage, Storage Box SFTP/WebDAV, and Koofr connections. Presets reuse existing transports and encrypted credentials, with endpoint validation and separate delivery/safety facts.
-
Capacity admission supports percentage headroom and retains durable upload, migration and restore budgets across process failure.
-
Storage insights with logical and unique-object inventory, shared-volume capacity reservations, dated growth evidence, and explicit audited cleanup for expired staging and receipt-verified derived STL cache. Heavy operations now preserve configurable disk headroom before allocation.
-
Download strategy and proxied-byte diagnostics use bounded labels; signed query credentials are redacted from application and access logs.
-
Authorized Artifact downloads can offload managed S3 bodies through short-lived
HTTPS redirects when browser CORS is supported. Local files retain range
delivery; originals, previews and thumbnails now revalidate privately, and
shares/slicer downloads remain noncacheable. -
The unified Docker image runs the full API and web UI in one container,
with the default single-service Compose file and tested AMD64/ARM64 publishing
to GHCR. -
Optional verified remote Artifact cache with bounded disk usage, active-reader leases, administrator controls, and authoritative audit bypass.
-
Successful browser-extension CI jobs provide the validated Chrome Web Store
ZIP as a direct download, retained for 30 days. -
The browser importer includes offline help and privacy information, with a
validated Chrome Web Store ZIP command and a publishing guide. -
Vault, Library and backup connection forms use one typed provider catalogue.
S3 and Nextcloud presets resolve consistently across uses. Connection editing
preserves omitted credentials, supports explicit replacement and prevents
changing a target while linked sources or owned backups depend on it. -
BGCODE v1 toolpath previews use the pinned official libbgcode converter in full
and lite API images on amd64/arm64. Conversion and browser parsing have explicit
resource limits; G92 coordinate resets and G2/G3 arcs are rendered. Travel lifts
no longer create empty layers. Originals
remain unchanged for downloads and PrusaLink. -
Backup run history records every selected destination, including invalid
connections and partial failures. Administrators can retry an exact failed
replica from a verified surviving archive; successful copies remain available.
Publication, verification and retry history are reported separately in Settings
and operational health. -
Multipart builds snapshot part quantities and selected Revisions for a concrete
manufacturing run. Linked print jobs reserve units; explicit usable-output
confirmations track missing pieces and retain previous physical attempts.
Builds can be duplicated with fresh results or archived with their history. -
Remote Library discovery streams large directories into a durable inventory.
Completed pages resume without rereading the directory, interrupted discovery
cannot remove linked Artifacts, and transport deadlines bound stalled requests.
Setup probes inspect only their own prefix. S3, WebDAV and SFTP directory
benchmarks cover 1,000, 10,000 and 100,000 entries. -
Browser-based first-owner registration on explicitly enabled trusted networks,
with a guided account, storage-check and first-model flow. Local Compose no
longer requires a setup credential from API logs. Database serialization
prevents competing API processes from creating multiple initial administrators;
authenticated recovery preserves an account when storage preparation is pending. -
A minimal, standalone Compose file for local deployment, with optional settings
and customization examples in a separate deployment guide.
Changed
-
Background work settings now lead with running, waiting, and failed work and
show each active Job's state, progress and cancel action. They also show where
to check a model's preview status. Queue tools and worker controls sit in
separate views, and mobile Settings links bring the selected tab into view. -
Collection tree badges now count Models in child folders, use the complete
total when only part of a large library is loaded, and stay visible in the
default sidebar width. -
Storage settings now show one clear current safety state and the location,
while remote file cache is visible without nested dropdowns. Cache limits
and activity have separate views; sizes use MB or GB. Storage cards reserve
their layout while loading, and remote connection setup uses the same visible
category and provider choices as Move Vault storage. -
One data volume. Every path PrintStash writes (database, files,
thumbnails, staging, backups, caches) lives underVAULT_DATA_ROOT,/data
in the container, so a deployment mounts one volume. Each directory can still
be moved on its own with its existing variable. The artifact cache and
downloaded AI search models, previously left in the container's own layer,
now persist across updates. The Unraid template's Appdata field now says to
keep that folder on one pool with no second mapping inside it, so imports
keep hard-linking. -
Model Families have been removed. Existing Models, files, G-code revisions and
print history remain independent; existing Family relationships and covers
are retired when the database migration runs. Multipart Models continue to
support named parts and alternative Models. -
Nine Compose files became two in the repository root:
docker-compose.yml
starts PrintStash as one container (web UI and full API) with no
configuration, anddocker-compose.advanced.ymlwires every setting with its
default, plus optional PostgreSQL, S3 and background workers. The light,
production and build-from-source variants are folded into the advanced file;
maintainer stacks moved underdeploy/. -
CI no longer runs the eight per-image Docker build and Grype jobs or the
legacy MinIO-to-SeaweedFS migration job. Container publishing no longer runs
Grype scans; release builds and the legacy migration helper remain available. -
Background work runs on a durable engine. Imports, previews, metadata,
backups, scans, notifications, fleet dispatch, audits, migrations and AI
Search projection, indexing, captions, expansion and model downloads are Jobs
on DBOS, found by a reconciler from what the database says is owed, so a
crash, restart or upgrade resumes them instead of losing them. Uploads now
commit the Artifact and return; its metadata, thumbnail and binary G-code
toolpath are derived afterwards and appear on an open page without a reload.
A new kind or a renderer change re-derives the library in the background
while current previews stay visible. Native work is bounded by its lane, not
a database permit: indexing runs as similarity and search Jobs, and a search
query embeds inside the request, ahead of background inference, in a worker
with its own memory and time limits. An index build and a model download are
each a Job, followed and cancelled through the Jobs API. -
Follow any Job at
GET /api/v1/jobs/{id}(cancel and retry beside it) and
live changes on the/api/v1/events/wssocket. Breaking:
/api/v1/ingest/jobs,POST /api/v1/files/thumbnails/rebuild, plain
POST /api/v1/ingest/archiveandPOST /api/v1/storage/migrations/{id}/advance
are removed;POST /api/v1/backupsand
POST /api/v1/backups/runs/destinations/{id}/retrynow answer 202 with a
job_id, and the backup (or the retried destination) is the Job's result; a
binary toolpath still being derived answers 202; Pending Imports expose
job_idinstead ofbackground_job_id; similarity runs no longer report
last_activity_at. -
Similarity runs, backup runs and destination retries each follow their Job:
the engine, not a lease the run held, decides what is running, and the next
attempt of an interrupted Job settles what the previous one left open.
Upgrading settles backups an interrupted process left running. -
Restoring a backup rebuilds the engine's state from the restored database:
work the snapshot shows as owed is found again even though the engine that
was running it is gone, and a backup the snapshot shows in progress no longer
blocks the next one. -
AI Search settings now separate guided setup, search types, AI servers and
technical options. Search types and compatible models appear as visible choices;
the active search is clearly separate from a new index build. Specialist index
tuning has its own view; server editing and custom model choices no longer
depend on nested dropdown sections. -
Storage and Maintenance settings now lead with plain-language tasks, usage, and
library checks. Technical cache, migration, and audit controls open on demand;
Maintenance actions and backup verification align across narrow screens;
Similar Models has its own analysis and paired candidate review flow. An empty
audit history no longer generates a failed latest-audit request, and schedules
remain available if history fails to load. Collection usage now compares sizes
in a compact view with readable B, KB, MB, or GB units and direct Model drilldown.
Storage insights now highlights stored files and free space, groups usage by
purpose, and shows a dated history chart. File types and provider evidence remain
available in Measurement details with readable file-type labels. Collection
storage now shows recorded sizes with model counts instead of bars scaled to
the largest item on each page. Opening a collection now shows its models in
the same fixed-size Collection storage area, preserving the two-column
collection layout and links to Model details. Model pages fit fully above the
pager even for large collections. Pagination
shows the visible range, and recent storage activity appears directly when
there is something to report. Cleanup actions appear only for measured
candidates and lead with the reclaimable size. -
The getting-started reminder can be dismissed with Don't show again. The choice
is remembered per user in the current browser across Settings and the empty library. -
First-run setup uses a centered, responsive form with inline password visibility
controls. Storage choices and server folders are visible immediately, with a
clear access-check step before account creation and guidance in English and Spanish.
A compact branded frame, slim progress steps, and a prominent server-storage
choice bring the guide closer to the app's forms and reduce mobile scrolling.
The first-model guide now offers a focused file upload or a two-field folder
connection that starts scanning immediately. Upload progress, recoverable scan
errors, and verified Model links stay visible in the guide; backup and printer
shortcuts follow the first Model. -
Artifact downloads use the canonical
/files/{id}/downloadendpoint. The
separatedownload-urlanddownload-directendpoints have been removed. -
Interface text, accessible labels, errors, plural counts and offline screens
use shared language catalogs. Dates and numbers follow the selected language;
the language menu supports adding further locales without a two-language toggle.
Catalogs are static, typo-friendly sources with guarded imperative feedback and
a safe scaffold command for adding complete language drafts. -
Backend code is organized by capability, with separate startup, storage,
backup recovery and library query modules. G-code Revision deletion uses a
shared business operation with product-specific authorization and persistence. -
The simple Docker Compose deployment now uses the light API image.
-
The browser extension is now named PrintStash in the browser, help and store
listing. Its connection settings and extension identity are unchanged.
Fixed
-
Similar model analysis now appears in Tasks with live run status and a link back
to the analysis page. Starting a second scan for the same scope shows a clear
explanation instead of a connection error. -
ZIP imports now show how many selected Models have been imported while work is running. The task progress bar advances for each file attempted, including files that fail or are skipped.
-
Completing first-run setup now clears task history left in the browser by a
previous installation, so old Jobs no longer appear as failed in a new vault. -
3MF imports no longer exhaust container memory on repeated project parts. Mesh metadata and previews now use a bounded 3MF resource loader that checks placed instances before composing geometry. Over-budget projects keep their original Artifact and embedded preview without crashing the API; existing mesh derivatives are refreshed at the new recipe version. (#259)
-
Search action buttons now sit inside the search field border, and model names
in the field no longer receive browser spellcheck underlines. -
AI Search index builds now finish library reconciliation even when its source
and orphan scans finish on different passes. Smaller reconciliation pages
release SQLite writer locks sooner. Deferred embedding failures wait for their
scheduled retry; failed builds and manually activated builds release their
background jobs, while a retry or later content change starts a tracked job.
Automatic activation reports permanent errors and rechecks changed content.
Active indexes sleep until a deferred embedding retry is due and wake when an
administrator retries a failed input. Local embedding contention yields the
search lane for interactive inference. Index ETAs now use recent completed
vectors, so time spent reconciling or stuck before backfill is excluded.
Guided setup names the current phase, shows vector counts only during indexing,
offers failed builds a retry, and discloses that local AI uses the CPU. -
Portable ZIP imports now update processed file counts while they run. The completed import task links administrators to Background work, where preview generation has its own queue status.
-
Library source setup now distinguishes a mounted folder that needs temporary
write permission for enrollment from one that cannot be read. Testing a
shared remote connection also checks Library source listing, and failed
listings show a useful message instead of a server-reachability error. New
remote connections default to Library-only use, so a read-only SFTP account
is not tested for backup access unless selected (#262). -
Trash GC preview now loads the active plan when another request claims it
first, so operators can review and abort the existing plan instead of seeing
an error. -
Unify local create-only publication on filesystems without hard links (#249):
uploads, URL imports, native completion, cache fills and root markers use the
same safe copy fallback. Probe staging for every Vault provider and report
its limitations once at startup and in Settings, without changing the Vault's
safety tier. Preserve pinned-directory and identity checks during recovery. -
File uploads now stage successfully on Unraid SHFS and other filesystems
that refuse hard links, including resumable uploads and native multipart
completion. Staging and storage downloads use an exclusive copy without
overwriting existing files. The Unraid guide explains the fallback and how
to rotate and preserve diagnostic container logs. -
A process that started while an interrupted restore or Vault migration still
needed recovery now starts its background work once recovery resolves it,
instead of queueing work nothing ran until the next restart. -
Opening a folder in the library no longer swaps the grid for a loading
skeleton; the current folder stays on screen until the next one is ready.
Folders are also prefetched when the pointer rests on them or they receive
keyboard focus, and a folder's readme is requested only when it has one and
is cached for later visits (CollectionReadgainshas_readme). -
Mounted Library source folders keep their exact capitalization and spaces in
collection labels and write-back destinations. Case- or punctuation-distinct
folders remain separate, including on rescan of previously indexed sources. -
Double-clicking a collection in the library sidebar keeps that collection open
instead of returning to All Models. -
Long nested collection paths stay within the upload dialog's collection selector.
-
"Or select a folder" in the Bulk upload tab opens the folder picker again. The
hidden inputs sat inside the clickable drop zone, so the folder input's click
bubbled to the zone and the file picker opened on top of it; only drag-and-drop
could queue a folder. -
Browser Back now returns through the Vault's collection navigation before leaving for an earlier page.
-
Model cards show the collection name in their badge instead of its full hierarchy path.
-
Long collection paths no longer push the Create Family model picker beyond the dialog edge.
-
A fault inside the browser tab is no longer reported as "Couldn't reach the
server". Only realfetchrejections map to that message; any otherTypeError
now says to reload the page, and keeps its original text for diagnostics. -
The Unraid Community Applications catalog has one current PrintStash listing;
the old API and frontend templates are marked deprecated for existing users. -
The Unraid template uses the unified image with one persistent appdata mount,
a working first-run setup default, and Unraid file-owner defaults. -
Printables captures request each selected file host's browser permission once
before downloading, avoiding repeated permission dialogs for multi-file imports. -
Browser captures accept multi-file selections within the review limit, release
unfinished upload slots after transfer failures, and explain capacity errors. -
Uploads work again when PrintStash is opened over plain HTTP on a LAN address
(for examplehttp://192.168.1.10:3000). Browsers hidecrypto.subtleoutside
secure contexts, so the new resumable upload failed while hashing the file and
reported "Couldn't reach the server" before sending anything. The browser now
falls back to a JavaScript SHA-256 there. -
Provider connection errors now distinguish missing MyMiniFactory OAuth setup,
rejected Cults credentials, provider outages, and invalid provider responses. -
Routine HTTP client requests no longer fill INFO logs during PrusaLink polling;
printer errors and transport warnings remain visible. -
AI Search mutations enforce token write scope, including caption edits, settings,
generation management, local model operations and personal preferences. -
Library search keeps typing and Enter in the current library view. A labeled
“Search with AI” action opens AI results; result cards no longer show retrieval
explanations. -
Model detail tabs stay in one row, scrolling within the tab bar when needed.
Similar Models keep readable names and reachable comparison actions in narrow panels. -
The library exposes multipart creation as a separate action on desktop and mobile.
-
AI search recovers bounded name misspellings, finds functional holder metadata,
and rejects weak short-query matches before combining retrieval signals. -
Caption edits and dismissal reserve the SQLite writer before reading, avoiding
failed updates when background indexing commits concurrently. -
Sparse search avoids temporary SQL query-name collisions on Python 3.13 while
preserving keyword scores and candidate filtering. -
The legacy MinIO migration helper pulls its unchanged, digest-pinned release
from the official Quay registry. -
AI Search guides setup and preserves keyboard focus between basic and advanced controls. Clearing a query cancels stale navigation; result views support a grid, list and on-demand match details.
-
Deferred search projection commits bounded source notifications with content edits and hides stale evidence until refreshed. Sparse ranking preserves independent SQL identities without excessive nesting.
-
Search backfill yields to complete user write requests, including upload staging
and cleanup, without holding a database transaction while waiting. -
AI Search bounds permission checks and Model-card loading to result identities,
avoids repeated full top-k sorting during portable vector scans, and keeps
periodic SQLite projection-repair transactions short during browsing. -
Search backfill drains bounded batches between periodic pauses, removing the
one-second delay per embedding batch while preserving maintenance and shutdown
coordination. Settled active generations stop a burst without inference. -
Restoring AI Search backups no longer requires optional vector extensions to
inspect unversioned databases. Durable vectors remain searchable through the
portable backend while native acceleration is disabled. -
AI Search activation acquires the SQLite writer lock before verification, so
concurrent worker commits cannot invalidate the cutover snapshot. Search and
ordinary Model results start without optional search annotations. -
Caption text and unsaved edits now clear when the signed-in account changes,
including account changes received from another browser tab. -
Browser Pending Imports accept signed-in session cookies while preserving bearer-token precedence and browser-device scope restrictions.
-
Printables capture and selected-file downloads use supported GraphQL fields, retaining creator and license metadata.
-
Preserve the original HTTPS scheme when the frontend proxy sits behind a TLS-terminating reverse proxy.
-
Mounted Library sources retain preview and download access when their indexed
Artifacts have a source key, without treating them as remote storage connections. -
Idle similarity polling no longer transiently blocks backup restoration with a storage-retention conflict.
-
Ordinary dense meshes such as the repository Benchy now receive complete
similarity analysis at the default budget. Geometry ordering, convex hulls,
nearest-surface queries and thumbnail allocation use less work and memory;
repeated exact comparisons reuse compatible proofs after checking source bytes.
Capture and ingestion share these improvements, including bounded STEP output
and Linux service memory-limit detection. -
Active print jobs no longer remain paused indefinitely after an out-of-band
emergency stop. Authoritative idle printer updates now close interrupted jobs,
with an operator recovery action for stale history when no update arrives. -
The Model detail back arrow returns to its containing collection instead of
always returning to the library root, including nested collection paths. -
Mounted Library source enrollment now rolls back known marker failures instead
of leaving a conflicted source behind, reports read-only marker failures
explicitly, and documents the one-time writable mount required for enrollment. -
Removing a library source no longer fails with a server error when one of its
files was already in the trash. The failed attempt had also moved the source's
models to the trash while leaving the source itself in place. -
PrusaLink now discovers the printer's advertised storage root, using
/usb
on Buddy/Core One firmware while retaining/localcompatibility, so file
inventory, upload, start and deletion no longer surface a false authentication
failure. -
Pending Imports remain readable when an older or damaged capture manifest is incomplete, without overwriting the stored capture data.
-
Browser pairing accepts local addresses without a scheme and explains invalid
setup input. First-run setup keeps pairing controls visible in the popup;
transfers remind users to keep it open until completion. Chrome and Edge
packages omit Firefox-only manifest settings. -
Documented pinned Nextcloud and WsgiDAV cleanup evidence, including ETag
collisions, conditional quarantine and lock expiry. WebDAV physical deletion
and automatic retention remain disabled; replacement bytes stay protected by
the production adapter's guarded cleanup policy. -
Remote Library sources and backup replicas use explicit streaming transport
contracts. Reader and directory handles close on early exit, and replica
publication no longer implies managed atomic creation. SFTP recovery is
exercised through the shipped image; native Local and S3 Vault paths remain. -
Backup deletion refuses destinations without an exact owned-object deletion operation, including manually confirmed requests. Unsupported retention keeps replicas and ownership evidence intact without repeated provider-error warnings. Mutable S3 null versions use conditional ETags.
-
Verified OpenDAL S3 backup replicas can now witness GC when current target and failure-domain evidence proves independence. Approval and finalization remain bound to the exact owned archive and quarantine deadline.
-
SFTP backup profiles can probe, list, verify and restore remote-only archives.
Manifest reads stream through bounded buffers and close their remote handles
on early exit; failed downloads remove their temporary bytes. -
Remote Library scans preserve ETags, versions and unknown modification times.
Equal-size changes trigger the next scan; sources without change markers are
hashed on every scan. Reads use supported version or conditional constraints
and reject metadata drift before indexing. -
Storage settings and backup lists distinguish catalog removal, exact physical
deletion, automatic retention and GC evidence. Unavailable image services and
retained bytes have explicit explanations; a connection probe does not imply
safe deletion. Guarded catalog removal keeps its confirmation and now states
that stored bytes remain. -
The full container image includes the S3 transport used by remote Library
sources and backup connections. Image checks now exercise remote-only S3
recovery on both supported architectures. -
SFTP streaming releases its connection, reader, and event loop when opening
fails, a read is cancelled, or cleanup itself encounters an error. -
Garbage collection requires current evidence of independent storage failure
domains. Different profiles, credentials, or prefixes cannot authorize
deletion using a backup on the same storage. Custom targets require an
administrator declaration; changes invalidate an approved plan. -
Remote Library sources reject incomplete or oversized downloads before
indexing, so a truncated first read cannot create an Artifact from partial bytes.
Performance
-
Bound each geometric similarity comparison to three minutes so a pathological
mesh pair cannot occupy the scan worker for hours; exhausted pairs are counted
as failed verifications and the scan continues. -
Similar Model analysis now reuses triangle measurements during surface
comparisons and avoids Trimesh array tracking inside geometry calculations,
reducing CPU time without changing comparison evidence. -
Imports no longer copy files into local storage. A staged upload, URL
import, library-transfer archive entry or Bambu print capture
becomes its library file by hard link when staging shares the library's
mount, which the single/datavolume guarantees: instant, whatever the file
size, with no second copy on disk. Local backups publish their archive the
same way when no remote replica needs it. Where a link is impossible (another
mount, or a filesystem without hard links) the file is copied as before, and
Settings warns "Imports are copied, not hard-linked" with a link to the
storage layout guide, which lists the layouts that keep hard links.
Full changelog: v0.13.0...v0.14.0