Skip to content

ingestor: assign explicit, collision-resistant MQTT client IDs #118

Description

@dborup

Problem

At fork audit ref 1bdf088e, MQTTSource has no clientId field and buildMQTTOpts() never calls Paho SetClientID. Each ingestor therefore connects with a zero-length client ID and CleanSession=true; assignment, rejection, and collision behavior is broker-dependent. Multiple CoreScope instances can consequently be rejected or take over each other's broker session.

Upstream reference: Kpa-clawbot/CoreScope#2016. Adapt it to this fork's multi-source, reconnect-watchdog, legacy Mosquitto, and device-auth setup.

Acceptance criteria

  • Add optional mqttSources[].clientId; a configured value is used verbatim and documented as needing to be unique among concurrent clients.
  • When omitted, generate a non-empty collision-resistant ID from a sanitized source name, falling back to broker hostname and then corescope, plus randomness from crypto/rand.
  • Generate the default once per source/client construction: stable across Paho auto-reconnect and watchdog force-reconnect, but unique across unconfigured sources/processes.
  • Log the selected client ID on successful connect without logging credentials or tokens.
  • Do not add a literal default ID to config.example.json; copied deployments must not collide.
  • Preserve topics, credentials, clean-session, TLS, and watchdog behavior.

Tests

Cover sanitization, host/empty-host fallbacks, configured IDs, uniqueness, stable reconnect identity, mutation cases, and a disposable loopback broker. Document legacy MQTT 3.1 length constraints.

Non-goals

No config-secret or broker ACL changes, device reconnects, live broker tests, deploy, release, or publish.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions