This broke against a real P1P: after auto-pinning, the immediate retry failed with 'self-signed certificate in certificate chain' / 'unable to get local issuer certificate' - the exact error OpenSSL gives when a trust-anchor certificate isn't a well-formed CA, or when a device presents a chain (leaf + its own separate self-signed root) that doesn't terminate at whatever got pinned. My earlier test only covered a leaf that happened to have CA:TRUE (openssl req -x509's default), which masked this. Fixed by switching Custom(pem) from chain validation to true fingerprint pinning: connect with verification off, then byte-compare the certificate actually presented (via to_der()) against the pinned bytes, rather than asking OpenSSL's PKI path-builder to accept an arbitrary leaf as a root. BundledCa/Insecure are untouched - this only affects the Custom path. Reproduced the exact failure locally (a leaf signed by a separate self-signed root, served as a 2-cert chain - a properly non-CA leaf, not my earlier accidentally-CA:TRUE test cert) before fixing it, then verified against that same repro: first-run auto-pin now succeeds, second run is silent, and - regression check - presenting a genuinely different certificate after pinning still correctly fails, with a clear message instead of an opaque OpenSSL error.
continuum-proxy
Edge gateway daemon for the Continuum print farm platform. Runs on a Linux
SBC on-site, talks to printers over the LAN, and keeps a connection to the
cloud control plane (continuum-backend).
This is a learning-stage boilerplate
This repo is deliberately minimal right now — real printer protocol clients
(Bambu MQTT+FTPS, PrusaLink REST, Klipper/Moonraker WebSocket) are not
implemented yet. Each vendor is a stub that just prints what it would do
(src/printer/bambu.rs, prusa.rs, klipper.rs). The idea is to learn
Rust's polymorphism pattern (trait + enum, since Rust has no class
inheritance) on something simple before adding real networking on top.
Getting started
cp .env.example .env
cargo run # the daemon: cloud uplink + go2rtc watchdog
cargo run --example printer_polymorphism # standalone demo, no network/env needed
cp printers.example.toml printers.toml # fill in your real printers (gitignored)
cargo run --example test_bambu_certs # real TLS handshake test against each Bambu printer
Structure
src/
main.rs Runs the uplink and the go2rtc watchdog side by side
config.rs Loads settings from environment variables
fleet.rs Loads printers.toml into ready-to-use PrinterHandles
uplink/ WebSocket client to continuum-backend: connect, heartbeat, reconnect on drop
printer/ GenericPrinter trait + PrinterBase + PrinterHandle enum + one stub per vendor
go2rtc.rs Restarts the go2rtc camera-restreaming process if it dies
examples/
printer_polymorphism.rs Runs all five printer stubs through one `connect()` call site
test_bambu_certs.rs Loads printers.toml, does a real TLS handshake to each Bambu printer
src/printer/ is where the "inheritance" question lives — see that
module's doc comment for the trait+enum pattern this project uses instead
of class inheritance, and run printer_polymorphism to see it work.
printers.toml (gitignored — copy from printers.example.toml) holds real
per-printer connection details: host, access code, and — since not every
Bambu printer trusts the same certificate (see certs/README.md) — an
optional per-printer CA override. src/fleet.rs loads it; nothing in
main.rs uses it yet, but test_bambu_certs does, as a real (if narrow —
just the TLS handshake, no MQTT) way to check a printer's certificate
without needing the full MQTT client built yet.
What's not here yet (on purpose)
- Real MQTT/FTPS/HTTP/WebSocket printer clients —
src/printer/*.rshas aprintln!where each of these will go. - Local SQLite buffering for telemetry across connectivity gaps.
- LAN printer discovery (SSDP/mDNS).
- The mechanical plate-changer interface (serial/GPIO).
Add these back in one at a time as you get comfortable with the Rust underneath them — each is its own small lesson (async I/O, a new crate's API, error handling for a real protocol) rather than something to absorb all at once.