Problem
At fork audit ref 1bdf088e, MQTTSource has no clientId field and buildMQTTOpts() never calls Paho SetClientID. Each ingestor therefore connects with a zero-length client ID and CleanSession=true; assignment, rejection, and collision behavior is broker-dependent. Multiple CoreScope instances can consequently be rejected or take over each other's broker session.
Upstream reference: Kpa-clawbot/CoreScope#2016. Adapt it to this fork's multi-source, reconnect-watchdog, legacy Mosquitto, and device-auth setup.
Acceptance criteria
- Add optional
mqttSources[].clientId; a configured value is used verbatim and documented as needing to be unique among concurrent clients.
- When omitted, generate a non-empty collision-resistant ID from a sanitized source name, falling back to broker hostname and then
corescope, plus randomness from crypto/rand.
- Generate the default once per source/client construction: stable across Paho auto-reconnect and watchdog force-reconnect, but unique across unconfigured sources/processes.
- Log the selected client ID on successful connect without logging credentials or tokens.
- Do not add a literal default ID to
config.example.json; copied deployments must not collide.
- Preserve topics, credentials, clean-session, TLS, and watchdog behavior.
Tests
Cover sanitization, host/empty-host fallbacks, configured IDs, uniqueness, stable reconnect identity, mutation cases, and a disposable loopback broker. Document legacy MQTT 3.1 length constraints.
Non-goals
No config-secret or broker ACL changes, device reconnects, live broker tests, deploy, release, or publish.
Problem
At fork audit ref
1bdf088e,MQTTSourcehas noclientIdfield andbuildMQTTOpts()never calls PahoSetClientID. Each ingestor therefore connects with a zero-length client ID andCleanSession=true; assignment, rejection, and collision behavior is broker-dependent. Multiple CoreScope instances can consequently be rejected or take over each other's broker session.Upstream reference: Kpa-clawbot/CoreScope#2016. Adapt it to this fork's multi-source, reconnect-watchdog, legacy Mosquitto, and device-auth setup.
Acceptance criteria
mqttSources[].clientId; a configured value is used verbatim and documented as needing to be unique among concurrent clients.corescope, plus randomness fromcrypto/rand.config.example.json; copied deployments must not collide.Tests
Cover sanitization, host/empty-host fallbacks, configured IDs, uniqueness, stable reconnect identity, mutation cases, and a disposable loopback broker. Document legacy MQTT 3.1 length constraints.
Non-goals
No config-secret or broker ACL changes, device reconnects, live broker tests, deploy, release, or publish.