fix/audit-battery-secu #6

Merged
faicel merged 11 commits from fix/audit-battery-secu into dev 2026-09-22 06:55:26 +00:00
Owner
No description provided.
and
  `latest`, plus an additive `sensor_battery` SQLite migration.
- Commit last rest/load voltages before writing timestamped InfluxDB
  battery
  history; reject orphan rows and prevent older receptions rolling back
  latest values.
- Cover migration, upsert, cascading deletion and failed historical
  writes.
Split sensors::battery into mod/model/repository/error with a directory
test module, mirroring the crate's domain conventions:

- BatteryService now implements the Service trait (constructing it
  requires the trait in scope, documented on the impl) and delegates to
  a crate-internal BatteryRepository fronting both stores: SQLite
  statements keep returning CommonError through the single
  sqlx-to-common conversion point, history failures map to
  BatteryError::HistoryWrite, and the InfluxDB line formatter moves
  alongside them.
- Public surface is unchanged in behavior: BatteryReading, BatteryError,
  the Result alias stay re-exported from sensors::battery.
- Tests move to battery/tests/mod.rs with corrected migration paths,
  construct the service through a crate-internal parts constructor
  reserved for private-pool test isolation, and keep their assertions.
The three battery tests hand-rolled the same one-shot HTTP fake inline;
tests/support.rs now owns the listener once (reads the request up to the
body, replies with a configurable status, returns the received body) and
setup() rewires to it, with test names and assertions unchanged.
Add one battery test exercising the real production construction path: the
migration runner creates the fresh database, a parent sensor is created via
SensorService, and BatteryService is built through Service::new. A temporary
config under ConfigFileGuard points the history client at a local fake
answering HTTP 500, so record deterministically surfaces
BatteryError::HistoryWrite while the SQLite latest value stays readable
through latest.
List the battery migration in the migrations README Files table and state
the battery line-protocol formatter's integer-only inputs invariant above
history_line: any future string tag or field must be escaped per InfluxDB
line-protocol rules, as the contact repository's private renderer does.
The HTTP client frames Content-Length itself from the exact-size
String body, so the manual header insertion only duplicated the
derived value on every history write.
Add a kept-simplification comment on the awaited history write in
BatteryRepository::record: caller latency couples to the InfluxDB
round-trip (bounded by the 30 s request timeout); detach or batch
writes if battery reporting frequency grows. Documentation only, no
behavior change; CHANGELOG bullet added under [0.4.4].
The battery wiring test wrote its pid-predictable temporary configuration
path with plain fs::write, which follows a pre-planted symlink. Pre-clean
a stale file left by a crashed prior run, then create the file with
exclusive semantics (O_CREAT|O_EXCL): exclusive creation never follows a
symlink, so nothing pre-existing at that path can be clobbered, and a
concurrent name collision just fails the test (AlreadyExists) instead of
overwriting a foreign file. Test-only hardening; no production path
changes.
docs(config): document user-only permissions for the token-bearing config file
All checks were successful
Run checks on feature branches / rust-crate-checks (push) Successful in 4m22s
Run checks on feature branches / checks (push) Successful in 0s
Validate branch flow / validate-flow (pull_request_target) Successful in 3s
Validate branch flow / validate (pull_request_target) Successful in 0s
2f07291006
Merge branch 'dev' into fix/audit-battery-secu
All checks were successful
Run checks on feature branches / rust-crate-checks (push) Successful in 3m39s
Run checks on feature branches / checks (push) Successful in 0s
Validate branch flow / validate-flow (pull_request_target) Successful in 3s
Validate branch flow / validate (pull_request_target) Successful in 0s
6090b46cbe
faicel deleted branch fix/audit-battery-secu 2026-09-22 06:55:27 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
homeiot/db_handler!6
No description provided.