|
Security:
- Epoch conversions no longer panic on out-of-range values: a device may
report any u64 as its clock, so to_timestamp is fallible (rendered
labeled-raw), from_timestamp clamps a pre-epoch host clock to zero (a
Pi with no RTC reads 1970 early after boot), and delta arithmetic
saturates. Fixes crashes in inspect and status
- Identity Debug redacts the root CA private key so no stray {:?} leaks it
- fsync the temp file before rename, so a power loss cannot surface an
empty identity.json
- Document in the README that device attestation is not verified, the NTP
servers contacted, and the at-rest key
Cleanup:
- A MatterCtx extension trait replaces the repeated map_err/anyhow closure
at every rs-matter call site with .ctx("what")
- SyncOutcome::failed/skipped constructors collapse two large literals
- read_our_fabric_entry shares the fabric-filtered read across the label,
decommission, and inspect paths
36 unit tests, clippy clean.
|
|
A standalone CLI Matter controller that joins Matter devices as a
secondary administrator (multi-admin) and sets their clocks via the
standard Time Synchronization cluster. Built on rs-matter 0.2.0, the
official CSA Rust Matter stack: its PASE/CASE initiators, Commissioner
flow, builtin mDNS, and generated cluster clients. One-shot runs from a
systemd timer; there is no daemon.
Hardware-validated end to end (commission, inspect, sync, decommission)
against an IKEA ALPSTUGA air quality monitor over Thread, commissioned
alongside Apple Home. Design and operation are documented in the
README. 34 unit tests, clippy clean.
|