Slixer moves a robot arm. Bugs that let the arm move when it shouldn't, keep moving after STOP, or be driven by someone who shouldn't be driving it are treated as security issues, not just bugs.
Please don't open a public issue for anything security-sensitive. Report it privately through the
repository's Security tab (Report a vulnerability), or contact the maintainers, LaingLab on GitHub.
If there's no answer within 7 days, you may open a public issue.
Please include what happens, how to reproduce it, the version (uv run slixer/run.py --version), and the
platform (OS, Python version, and the firmware on the boards if it's relevant).
Slixer is in beta. Fixes go into the latest release only.
- The page has no login. Anyone who can reach it can drive the arm and upload files. That's why it
serves this PC only (
127.0.0.1) unless it's started with--host 0.0.0.0. Only do that on a network you trust. - Only Slixer's own page can drive it. A browser will open a connection to
localhostfor any website that asks, so Slixer refuses a WebSocket, or anything but a plain read, from a page of another origin, and any request whose Host is neither an IP address nor one of this PC's names (which is what DNS rebinding needs). With--host 0.0.0.0, this PC's own name works too, and--allow-host NAMEadds another. Programs that aren't browsers send no Origin and are let through: they already run somewhere that can reach the arm's link directly. - The arm's Wi-Fi link has no password of its own. The boards take poses as plain UDP on port 50101 from anything on the same network. The Wi-Fi password is the only protection, so keep the arms on a network where everyone who can join may also move them.
- Wi-Fi passwords go in each sketch's
wifi_config.h, which git ignores. Don't commit one, and check before sharing a copy of the firmware folder. - Imported STL files are parsed on the PC with trimesh, in a process of their own. Only import files you trust.
- Anything that needs physical access to the arm, the boards or the PC.
- The absence of collision checking: imported parts are drawn, not felt, and the documentation says so.