Files
LEDMatrix/docs/ARCHITECTURE.md
T
ChuckandClaude Opus 5.5 3967a6cffc fix(security): re-harden root sudo helpers; installer fixes; ARCHITECTURE and PERMISSIONS docs (#640)
* docs: add ARCHITECTURE and PERMISSIONS guides

ARCHITECTURE.md maps the processes, the state the display and web
services share through the cache, the display loop, the plugin system,
the web UI and the update path, with links into the code and a
where-to-start table.

PERMISSIONS.md lists who owns what after install, both sudoers files
(and why iptables is not granted), the polkit rule, and which
scripts/fix_perms script to run as which user.

Both are linked from the docs index, along with the MQTT bridge README
and src/common/README.md.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs: correct stale setup, service and troubleshooting claims

- README: quick actions run systemctl on ledmatrix.service (run.py), not
  display_controller.py; use_short_date_format has no effect; the
  installer uses system pip with --break-system-packages, not a venv.
- CONFIG_DEBUGGING: LEDMATRIX_DEBUG must be "true"; logs are in journald.
- GETTING_STARTED, WEB_INTERFACE_GUIDE, TROUBLESHOOTING: enabling a
  plugin, plugin settings, brightness and Vegas settings apply without a
  restart; matrix hardware settings still need one.
- TROUBLESHOOTING: install dependencies with sudo so the root service
  sees them; point permission problems at PERMISSIONS.md instead of a
  project-wide chown.
- ADVANCED_FEATURES: real BackgroundDataService stats keys; Vegas hooks
  return VegasDisplayMode and None falls back to capture; cache files
  are 0660; fix_web_permissions.sh runs as the web user and does not
  touch sudoers.
- STARLARK_APPS_GUIDE: only the linux-arm64 pixlet binary is downloaded.
- HOW_TO_RUN_TESTS: test class examples that exist.
- CLAUDE.md: PluginStoreManager, plugin_dirs.py, monorepo installs via
  the Trees API with ZIP fallback, requirements.txt is optional.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs: mark deprecated plugin APIs and state manifest fields once

Methods @deprecated("3.7.0") (the set pinned in test_deprecation.py)
were shown as current API in the quick reference, API reference,
advanced guide, development guide and FONT_MANAGER. Each is now marked
deprecated with its replacement. FONT_MANAGER is rewritten around the
current API; the override editor is gone and override methods are
deprecated.

Required manifest fields were stated three different ways. The API
reference now has one section: the 7 schema-required fields, the 4 the
store refuses without, class_name for the loader, and the 8 to set.
The other guides link to it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs: document every src/common module and every widget

- src/common/README.md covered 7 of 17 modules. It now has a table of
  all of them (purpose, whether plugins import it, release to floor
  on), a short entry each, and logging advice that matches the code.
- SPORTS_UNIFICATION listed two shared modules and called
  sports_helpers the first; it now lists all six.
- The widgets README lists all 28 registered widgets plus the support
  files, and absorbs the parts that only docs/widget-guide.md had
  (x-options.labels, x-advanced, x-display hidden, plugin-file-manager).
  docs/widget-guide.md is now a pointer to it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(security): fix_web_permissions.sh re-hardens the root sudo helpers

The script chowns the whole project to the web user. That included
scripts/fix_perms/safe_plugin_rm.sh and safe_pip_install.sh -- the two
helpers /etc/sudoers.d/ledmatrix_web lets the web user run as root -- so
running it turned both into a root shell for whoever can edit them. It
also re-grouped config_secrets.json away from ledmatrix.

After the chown it now does what first_time_install.sh's Steps 11 and
11.1 do: helpers back to root:root 755, and config_secrets.json back to
the web unit's User=:ledmatrix 640. Each step is non-fatal and prints the
manual command if it fails.

Also fixes what the script and its docs claimed: it never configured
sudoers, its closing hint pointed at ./configure_web_sudo.sh (wrong
path), and the README and ADVANCED_FEATURES.md said to run it with sudo,
which it refuses.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(security): validate and harden every sudoers drop-in the scripts write

configure_wifi_permissions.sh copied its rules into
/etc/sudoers.d/ledmatrix_wifi without `visudo -c`. A malformed drop-in
makes sudo refuse every command for every user, which on a headless Pi
leaves no way back in. It now checks first and leaves the installed file
alone when the rules do not parse, as the other two writers do. (It
already used mktemp, so that part of the review did not apply.)

It also grants the two literal commands wifi_manager.py runs for
NetworkManager's shared-mode dnsmasq drop-in -- `cp
/tmp/ledmatrix-nm-dnsmasq.conf .../dnsmasq-shared.d/ledmatrix-captive.conf`
and `rm -f` of that file. The directory's mkdir was granted, the file was
not. Both are pinned in test_sudo_allowlist_covers_calls.py.

configure_web_sudo.sh wrote its rules to /tmp/ledmatrix_web_sudoers_$$,
a predictable name in a world-writable directory; it now uses mktemp with
an EXIT trap, as first_time_install.sh does. It sets mode 440 on the
installed file instead of leaving the temp file's mode, and finds visudo
in /usr/sbin when that is not on the user's PATH, which skipped the
check silently.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(install): escape the project path in the DNS-fix and MQTT unit renderers

install_dns_fix.sh and install_mqtt_bridge.sh substituted
__PROJECT_ROOT_DIR__ with the raw path, while the other three renderers
go through sed_escape_replacement from lib_systemd_render.sh. A checkout
under a path containing `&`, `\` or `|` rendered a corrupted unit from
these two only. Both now source the helper and use it, and a test checks
that every placeholder substitution in scripts/install uses an escaped
value.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(install): stop the installer scripts reporting things that are not true

- first_time_install.sh printed "Password: ledmatrix123" for the setup
  access point. wifi_manager creates it as an open network ("No
  password" on the panel), so it now says so.
- Step 10.1 printed "✓ WiFi management permissions configured" straight
  after its own failure message; install_wifi_monitor.sh printed
  "✓ Package installation completed" after a failed apt install. The
  tick now only follows success.
- Step 7 printed "Web dependencies already installed ... in Step 5" in
  the one branch that runs because Step 5 did not install them, then
  created .web_deps_installed on that basis. It now warns and leaves the
  marker off so the next run retries, as the comment below it intends.
- check_system_compatibility.sh called Debian 12 Bookworm "full
  compatibility confirmed" while first_time_install.sh refuses anything
  but Debian 13. Bookworm, older Debian and non-Debian systems are now
  errors. Its counters used ((X++)), which under `set -e` exits the
  script at the first warning or error (the expression is 0), so the
  check never reached its summary on any system with one.
- configure_web_sudo.sh and configure_wifi_permissions.sh finished by
  testing `sudo -n test -f ...` and `sudo -n nmcli device status`,
  neither of which is granted, so they always reported a failure. They
  now ask `sudo -n -l` about commands the new rules do grant, which
  checks the rule without running anything.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(install): print the completion summary before rebooting

With -y -- and so for every one-shot `curl | bash` install, which always
passes -y -- first_time_install.sh ran `reboot` about 180 lines before
its "Installation Complete / Web UI Access" summary. reboot returns at
once, so the summary printed while the Pi was going down and the SSH
session usually dropped before the web UI address could be read.

The reboot block moves, unchanged, to the very end of the script. The
interactive prompt now also follows the summary. Because the summary now
runs before the -y reboot, its one command that could fail under
`set -Eeuo pipefail` (the SSID lookup, when nmcli reports a connected
device but no active network line) gets `|| true`; a missing SSID was
already handled as "SSID unknown".

one-shot-install.sh prints its "Next steps" after the installer returns,
by which time the reboot is under way, so it now says so, and README's
Quick Install mentions the automatic reboot.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* chore(scripts): correct wrong comments and messages, drop dead code

No behaviour change except the output text noted below.

- 2775 is setgid, not the sticky bit (first_time_install.sh Step 3.1,
  fix_plugin_permissions.sh), and root needs no "PWM hardware access"
  to plugin files.
- The 777 comments in first_time_install.sh Step 3's fallback and
  fix_assets_permissions.sh said root needs it to write. Root ignores
  mode bits; the comments now say what 777 actually opens. The 777
  itself is unchanged.
- apt_remove ends in `|| true`, so Step 12's "Some packages could not be
  removed" branch could never run; it is gone and the helper stays
  non-fatal.
- detect_web_service_user's comment named Step 8 for the web unit
  (install_service.sh installs it in Step 7.5) and now says which
  branch actually runs.
- Step 5 described an "already installed" check that does not exist;
  the ACTUAL_USER comment described the re-exec backwards.
- on_error printed a literal "\n" before "Common fixes:".
- Dead code: one-shot-install.sh's uncalled fix_tmp_permissions,
  LEDMATRIX_ELEVATED=1 (never read) on the sudo re-exec, and
  configure_web_sudo.sh's unused PYTHON_PATH, which also made a missing
  python3 fatal for rules that never mention it.
- start_display.sh / stop_display.sh said "for user: <you>"; the
  service runs as root.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* refactor(fix_perms): fix_cache_permissions.sh uses setup_cache.sh's model

There were two models for /var/cache/ledmatrix. setup_cache.sh (the
installer's Step 2) and install_web_service.sh share it through the
ledmatrix group: root:ledmatrix, 2775, files 660, which is also what
DiskCache relies on to give files the directory's group.
fix_cache_permissions.sh instead made it 777 and re-grouped it to the
invoking user's group, undoing that.

It now runs setup_cache.sh for /var/cache/ledmatrix and keeps its own
handling of ~/.ledmatrix_cache. Dropped: /var/cache/ledmatrix/
placeholder_logos (nothing reads it) and the checks against the
`daemon` user (no service runs as daemon).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* ci: pin actions/checkout in the Claude workflows, drop template comments

claude.yml and claude-code-review.yml used actions/checkout@v4 while
test.yml and release-version-check.yml pin the v4.2.2 commit SHA; they
now pin the same SHA. The commented-out starter-template settings
(prompt, claude_args, paths, author filter) are removed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(scripts): index every script and list removal candidates

New scripts/README.md gives one line per top-level script and scripts
directory, marked keep, dev-only or diagnostic, and lists the eight
scripts nothing in the repo refers to as candidates for removal (kept
for now). The install, utils and dev READMEs now list the files they
were missing.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* test: tighten two checks that mutation testing showed were too loose

- The wifi sudoers check matched `visudo -c -f "$TEMP_SUDOERS"` in the
  error report too, so replacing the check with `if false` still passed.
  It now requires the command as the condition.
- The summary test never had the setup access point up, so reinstating
  the bogus "Password: ledmatrix123" line went unnoticed. A case with
  hostapd active now checks the AP is described as open.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(permissions): describe the repaired fix_perms scripts and new WiFi grants

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(changelog): docs-scripts

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-24 17:31:41 -04:00

14 KiB

Architecture

A map of the codebase for a new contributor: which process does what, how they talk to each other, and where to start reading for common changes.

Processes

systemd unit Runs as Runs Installed by
ledmatrix.service root run.py → DisplayController install_service.sh
ledmatrix-web.service the installing user start_web_conditionally.py → web_interface/start.py (Flask, port 5000) install_service.sh, install_web_service.sh
ledmatrix-update-verify.path / .service the web user Health check after an automatic update the same installers, or src/auto_update_setup.py at runtime
ledmatrix-wifi-monitor.service root wifi_monitor_daemon.py install_wifi_monitor.sh
ledmatrix-mqtt-bridge.service root MQTT bridge (optional) install_mqtt_bridge.sh
ledmatrix-dns-fix.service root DNS workaround (optional) install_dns_fix.sh

Unit templates are in systemd/. The display runs as root because the LED matrix library needs direct GPIO access. The web interface runs unprivileged and uses a fixed list of sudo rules for the few privileged things it does; see PERMISSIONS.md.

start_web_conditionally.py exits without starting Flask when web_display_autostart is explicitly false in config.json.

How the two main processes share state

The display and the web interface are separate processes that never call each other. They share three things:

  1. config/config.json and config/config_secrets.json. The web interface writes them through ConfigManager (src/config_manager.py); the display notices through ConfigService (below).
  2. The disk cache, /var/cache/ledmatrix (owned root:ledmatrix, setgid, files 0660), read and written through CacheManager (src/cache_manager.py, src/cache/disk_cache.py). Readers in the other process pass memory_ttl=0 so they do not serve a stale in-memory copy.
  3. A few files in /tmp.
State Where Written by Read by
On-demand request cache display_on_demand_request web: start_on_demand_display() / stop_on_demand_display() in api_v3/display.py display: _poll_on_demand_requests()
On-demand state cache display_on_demand_state display: _publish_on_demand_state() web: /api/v3/display/on-demand/status
Current screen cache display_current_state display web: /api/v3/display/current-status
Plugin errors cache plugin_error_snapshot display: ErrorSnapshotPublisher (src/error_aggregator.py) web: read_error_report() for /api/v3/errors/*
Error clear cache plugin_error_clear_request web display
Font usage cache font_usage_snapshot display: FontUsagePublisher (src/font_usage.py) web: Fonts tab
Plugin health cache plugin_health:<id> display (web writes on reset) web: /api/v3/plugins/health
Preview frame /tmp/led_matrix_preview.png display: DisplayManager, gated by snapshot_policy web: display SSE stream, /api/v3/health (file age)
Preview viewer marker /tmp/led_matrix_preview_viewer web, while a preview is open display: writes full-rate snapshots only while it is fresh
Hardware init status /tmp/led_matrix_hw_status.json display web: /api/v3/hardware/status

The on-demand start route also restarts ledmatrix.service by default so the request takes effect straight away.

Display loop

src/display_controller.py, class DisplayController. __init__ loads config, starts the cache and the error-snapshot publisher, runs the startup validator, creates the DisplayManager (src/display_manager.py), FontManager and PluginManager, loads the enabled plugins in parallel, runs an initial update() pass within a 20-second budget (_INITIAL_UPDATE_BUDGET_SECONDS; a plugin that misses it is deferred to the scheduler), and sets up Vegas mode.

run() is the main loop. Each pass, in order: apply a pending plugin enable/disable, poll on-demand requests, run scheduled plugin updates, check the on/off schedule and brightness, then show one screen. Priority is on-demand, then WiFi status messages, then live priority, then Vegas mode, then normal rotation.

  • Rotation. available_modes is the ordered list of display modes; current_mode_index advances after each screen. _apply_plugin_rotation_order() applies display.plugin_rotation_order.
  • Durations. _get_display_duration(): display.display_durations[mode], else the plugin's get_display_duration(), else 30 s. Plugins that support dynamic duration run until is_cycle_complete(), capped by display.dynamic_duration.max_duration_seconds (default 180 s).
  • On-demand. A request from the web interface pins one plugin (or mode) for a duration. _activate_on_demand() / _clear_on_demand(); the session is saved under display_on_demand_config so it survives a restart. It also keeps the display on during scheduled off hours.
  • Live priority. _check_live_priority() looks for a plugin whose has_live_priority() and has_live_content() are both true and switches to it, rotating between several live games.
  • Schedule and dim schedule. _check_schedule() reads schedule; _check_dim_schedule() reads dim_schedule and display.hardware.brightness. Both are re-evaluated once a minute.
  • Long screens. While a screen is showing (a dwell, a scroll, a Vegas iteration), _service_pending_changes() repeats the on-demand, schedule and brightness checks every 0.25 s, so a change does not wait for the screen to end.
  • Config hot reload. ConfigService (src/config_service.py) polls the config and secrets files' mtimes every 2 s and notifies subscribers when the content changes. The controller refreshes its cached settings; enabling or disabling a plugin queues _reconcile_enabled_plugins(), which loads or unloads it on the display thread; each plugin gets on_config_change() for its own section. Set LEDMATRIX_HOT_RELOAD=false to turn this off. Matrix hardware settings are only read at start-up.
  • Vegas mode. src/vegas_mode/: the display loop calls VegasModeCoordinator.run_iteration() (coordinator.py) when display.vegas_scroll.enabled is set. PluginAdapter gets each plugin's content (get_vegas_content(), else its scroll_helper image, else a capture of display()), StreamManager orders it and RenderPipeline scrolls it. See ADVANCED_FEATURES.md.
  • Multi-display sync. DisplaySyncManager (src/common/sync_manager.py), enabled by sync.role: a leader sends a follower its share of each frame over UDP (port 5765).

Plugin system

src/plugin_system/:

Area Where
Base class plugins implement base_plugin.py (BasePlugin, VegasDisplayMode)
Finding a plugin's directory plugin_dirs.py: manifest id first, then directory <id> or ledmatrix-<id>
Discovery, load, unload, scheduled updates plugin_manager.py (PluginManager)
Import and instantiate plugin_loader.py (PluginLoader.load_plugin(): dependencies, module, class)
Timeouts plugin_executor.py (PluginExecutor, 30 s default; a timed-out thread is abandoned, not killed)
Circuit breaker plugin_health.py (PluginHealthTracker: 3 consecutive failures open the circuit for 300 s)
Resource metrics resource_monitor.py
Config schemas and defaults schema_manager.py
Install, update, uninstall store_manager.py (PluginStoreManager)
Core-version gate compatibility.py

Discovery scans only plugin_system.plugins_directory (default plugin-repos/). Scheduled update() calls run on one background worker thread; a per-plugin lock keeps display() from running during an update.

Store flow. install_plugin() renames any existing copy aside (<id>.standalone-backup-preinstall), installs the new one, and puts the old copy back if the install fails. Monorepo plugins come from the GitHub Trees API, falling back to the repository ZIP; other plugins by git clone or download. The manifest is checked (see required fields), the core version gate runs, then dependencies are installed as root through scripts/fix_perms/safe_pip_install.sh. update_plugin() pulls git installs, undoing a pull whose new version is incompatible, and reinstalls everything else through _reinstall_with_rollback().

Web interface

  • App. web_interface/app.py builds the Flask app at import time, creates the managers, and registers two blueprints. web_interface/start.py runs it on port 5000.
  • Pages. blueprints/pages_v3.py serves the shell templates/v3/base.html at / and each tab as a partial at /partials/<name> (templates in web_interface/templates/v3/partials/). Plugin configuration tabs are rendered from the plugin's schema by plugin_config.html.
  • API. blueprints/api_v3/ is one blueprint at /api/v3, split by area: backup.py, config.py, display.py, fonts.py, misc.py (health, logs, errors, cache, sync), plugins.py, starlark.py, system.py (service actions, updates, git), wifi.py. __init__.py defines the blueprint and shared helpers and imports the modules so their routes register. Endpoints are listed in REST_API_REFERENCE.md.
  • Front end. HTMX loads each tab's partial on first open (hx-trigger="loadtab"); Alpine.js holds page state. Scripts are in web_interface/static/v3/js/; form widgets are bundled from js/widgets/.
  • Server-sent events (app.py): /api/v3/stream/stats (CPU, memory, temperature, service state, every 10 s), /api/v3/stream/display (preview frames when the PNG changes) and /api/v3/stream/logs (journal of both services). One generator thread per stream is shared by all clients.

Updates

  • Update Code on the Overview tab and the automatic updater both call perform_core_update() in api_v3/system.py: git pull --rebase, reinstall changed requirement files, report whether a restart is needed.
  • Automatic updates (auto_update.enabled, off by default): AutoUpdater in web_interface/auto_update.py runs in the web process, checks every 30 minutes, and updates at most weekly between 02:00 and 05:00. Before pulling it copies scripts/utils/auto_update_verify.py to data/auto_update_verifier.py, then writes data/auto_update_verify.request. That file triggers ledmatrix-update-verify.path, which runs the verifier as a separate unit (so restarting the web service does not kill it). The verifier restarts both services, waits for the web API to answer and the display service to stay up, and on failure resets to the previous commit and restarts again. Plugin updates run only after a verified core update. State is in data/auto_update_state.json and data/auto_update_pending.json.
  • Startup validator. StartupValidator (src/startup_validator.py) runs twice in DisplayController.__init__: config and cache directory first, then enabled plugins once the plugin manager exists. It also warns when an installed systemd unit differs from its template in systemd/. Results are logged; startup continues either way.

Where to start reading

Task Start with
Change rotation, durations or priorities DisplayController.run() and _get_display_duration() in display_controller.py
Add a config key CONFIG_REFERENCE.md, config/config.template.json, the tab's partial and api_v3/config.py
Change drawing or fonts display_manager.py, font_manager.py, src/common/bdf_font.py
Add a plugin-facing API base_plugin.py or src/common/; document it in PLUGIN_API_REFERENCE.md
Plugin install/update bugs PluginStoreManager in store_manager.py
A plugin that won't load PluginManager.load_plugin() and PluginLoader.load_plugin(); python3 scripts/check_plugin.py --plugin <id>
Add an API endpoint the matching module in api_v3/
Add a web UI tab or control templates/v3/base.html, the tab's partial, pages_v3.py
Vegas scroll src/vegas_mode/coordinator.py
Installer or permissions first_time_install.sh, scripts/install/, PERMISSIONS.md
Work without a Pi DEV_PREVIEW.md, EMULATOR_SETUP_GUIDE.md, HOW_TO_RUN_TESTS.md