| Age | Commit message (Collapse) | Author | Files | Lines |
|
logLevel to warn
- timezone optional -> host system zone (jiff, macOS + Linux)
- storagePath optional -> platform data dir (/var/lib on Linux, ~/Library/Application Support on macOS)
- config file optional at the default path; explicit --config must still exist
- default logLevel changed from info to warn
- new output field (text|json) sets the default rendering so -j isn't needed per call
|
|
|
|
- Rename crate, binary, and repo from mattertimesync to mattertimectl
- Change default fabricLabel to "Matter Time Controller"
- Point README at src.nth.io as the main repo, GitHub as the mirror
|
|
The registry (device names) and service-state (sync results) were two
JSON files keyed the same way, split only for a TypeScript-compatibility
that is moot now that the fabric identity cannot migrate between
implementations. Merge them into one devices.json with a DeviceRecord per
node, which also removes the parallel-map join in status and collapses the
per-command load/store pairs. identity.json stays separate as a write-once
secret.
Also, from a reduction/immutability review:
- Fix with_timeout passing a literal "{what}" instead of the error context
- Drop needless mut: CompactDuration and parse_wall_clock become immutable
expressions; run_status filters with a predicate instead of a mutator;
sync_one extracts write_zone_and_dst; InspectOutcome gains Default plus a
failed() constructor
- Share a join_ids helper and a devices_path helper; add IdentityReport
From; minor combinator tidy-ups
35 unit tests, clippy clean.
|
|
controller.rs had grown to ~1400 lines gluing the one-shot stack harness
and persistent-identity lifecycle to the four on-wire operations. Move the
operations (commission, sync, inspect, decommission, plus connect and the
timeout helper) into controller/ops.rs; the harness, identity/fabric
bootstrap, KV store, and locking stay in controller/mod.rs. ops.rs sees the
parent module private items via use super::*, so no visibility changes were
needed, and pub use ops::* keeps the existing controller::* paths.
No behavior change. 36 unit tests, clippy clean.
|
|
Security:
- SNTP replies must echo a random nonce in their originate timestamp, and
unsynchronized (LI=3) or invalid-stratum servers are rejected, so an
off-path spoofer cannot defeat the clock-trust gate
- The storage directory is created 0700 but an existing one is tightened
only when it is provably ours (holds our artifacts or is empty); a
misconfigured path like /tmp under root is left alone with a warning
- Device-supplied vendor/product names are stripped of control characters
at ingestion so a device cannot inject terminal escapes
Cleanup:
- ensure_fabric splits into decision logic plus bootstrap_fabric
- read_device_names merges the two name readers; a From impl replaces the
hand-mapped IdentityReport; run_sync uses map/transpose with an extracted
manual_instant; pick_interface runs once; print_json escapes its fallback;
device_name dedups the vendor/product join; identity_status ignores
leftover .tmp blobs; dead parameters and repeated random-id code removed
36 unit tests, clippy clean.
|
|
Security:
- Epoch conversions no longer panic on out-of-range values: a device may
report any u64 as its clock, so to_timestamp is fallible (rendered
labeled-raw), from_timestamp clamps a pre-epoch host clock to zero (a
Pi with no RTC reads 1970 early after boot), and delta arithmetic
saturates. Fixes crashes in inspect and status
- Identity Debug redacts the root CA private key so no stray {:?} leaks it
- fsync the temp file before rename, so a power loss cannot surface an
empty identity.json
- Document in the README that device attestation is not verified, the NTP
servers contacted, and the at-rest key
Cleanup:
- A MatterCtx extension trait replaces the repeated map_err/anyhow closure
at every rs-matter call site with .ctx("what")
- SyncOutcome::failed/skipped constructors collapse two large literals
- read_our_fabric_entry shares the fabric-filtered read across the label,
decommission, and inspect paths
36 unit tests, clippy clean.
|
|
A standalone CLI Matter controller that joins Matter devices as a
secondary administrator (multi-admin) and sets their clocks via the
standard Time Synchronization cluster. Built on rs-matter 0.2.0, the
official CSA Rust Matter stack: its PASE/CASE initiators, Commissioner
flow, builtin mDNS, and generated cluster clients. One-shot runs from a
systemd timer; there is no daemon.
Hardware-validated end to end (commission, inspect, sync, decommission)
against an IKEA ALPSTUGA air quality monitor over Thread, commissioned
alongside Apple Home. Design and operation are documented in the
README. 34 unit tests, clippy clean.
|