tfaour 38944a1287 Fix stack buffer overflow in face-labels parsing
fetch_face_labels() clamped the server-reported label count against
max_labels by casting the count to int first -- a value >= 2^31 (a
perfectly ordinary decimal in JSON) went negative under that cast, so
the comparison was always false and the clamp never fired. The loop
then ran with the full, unclamped count, writing past the caller's
fixed MANAGE_FACE_LABELS_MAX-element stack array on a crafted
/frame/face-labels response. Reachable by a compromised/malicious
tools server, or a MITM on the default plain-HTTP connection.

Fixed by comparing unsigned instead of casting to int.
2026-07-22 16:21:23 -04:00

ESPresso Frame

A DIY e-ink photo frame: an ESP32-C6 pulls photos from your Immich library and displays them on a 7.3" full-color e-paper panel, waking on a timer to refresh and spending the rest of its time in deep sleep.

  • No cables to a computer, no SD card shuffling. Provisioning is a captive portal with a QR code drawn on the panel itself -- scan, join, fill in your WiFi and server address, done.
  • The frame never decodes an image. A small self-hosted server does all the work (pulling from Immich, cropping, dithering, packing into the panel's exact pixel format) and hands the device a stream it can write straight to SPI. The ESP32-C6 has no PSRAM and not much SRAM to spare -- keeping it a dumb display client is what makes that workable.
  • Crops toward faces, not just the center, using face bounding boxes Immich already computed for its own People feature -- no bundled face detector.
  • Refresh interval and album are configurable from a web UI, no reflashing needed to change them.

Hardware

See docs/hardware.md for wiring and docs/architecture.md for how the two halves talk to each other.

Getting started

  1. server/ -- run the FastAPI server first (Docker Compose, points at your Immich instance). See server/README.md.
  2. firmware/ -- build and flash the ESP32-C6, then scan the QR codes it draws on first boot to provision it. See firmware/README.md.

Repo layout

firmware/   ESP-IDF project for the ESP32-C6
server/     FastAPI server: Immich -> crop/dither/pack -> the frame
docs/       Wiring and architecture notes

License

MIT -- see LICENSE. A few small pieces of vendored third-party code (a QR code generator, a bitmap font table) keep their own permissive licenses; see LICENSE for details.


Built with substantial assistance from Claude Code.

S
Description
No description provided
Readme MIT
17 MiB
v1.5.0
Latest
2026-08-04 19:27:00 -04:00
Languages
Python 62.9%
C 19.2%
JavaScript 7.4%
HTML 5.6%
CSS 1.7%
Other 3.2%