Skip to content

ingestor: accept client RX coverage only from configured MQTT sources #265

Description

@dborup

Problem

The ingestor accepts mobile client RX coverage (meshcore/client/{PUBLIC_KEY}/packets, gated by clientRxCoverage.enabled) from every configured MQTT source. Trust in that topic rests on the broker binding the topic pubkey to the publisher's identity (see docs/client-rx-coverage.md, "Trust").

An instance can have several sources: a device-auth broker that binds the topic to a signed per-device token, and a legacy username/password broker where many accounts may write meshcore/#. On such a deployment, any account on the legacy broker could publish coverage under any companion pubkey once the feature is enabled.

Proposal

Add an optional allowlist of sources for the client namespace:

"clientRxCoverage": { "enabled": true, "sources": ["<source name>"] }
  • If sources is set and non-empty, the ingestor handles meshcore/client/... only when the message arrived on a listed mqttSources[].name. Messages from other sources are dropped, with a throttled, bounded log line. They still never fall through to the observer path.
  • If sources is absent or empty, behaviour is unchanged: all sources are accepted, as today. This keeps upstream-compatible defaults.
  • An unknown name in sources (one that matches no configured source) is logged once at startup.

Acceptance

  • A client packet from a listed source is ingested. The same packet from an unlisted source writes nothing to client_receptions or client_observers, and creates no observer row.
  • With sources absent or empty, behaviour is unchanged (existing tests stay green).
  • The blacklist check and the "client namespace always returns" rule stay in force, whatever the source.
  • docs/client-rx-coverage.md and the configuration docs describe the option, and why it matters on mixed-broker deployments.
  • Unit tests use the real handleMessage path with the source tag, and a mutant (source check removed) fails.
  • cmd/server is untouched, or read-only if touched; no new map[string]interface{}.

Activity

  1. added a commit that references this issue on Oct 5, 2026
  2. dborup commented on Oct 5, 2026

    @dborup
    OwnerAuthor

    Fixed by #274 (merged as 2e8deaed). Review nits are tracked in a follow-up issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions