Building a deliberately messy synthetic house instantly exposed four real gaps:
- _build_range_name_map: a middle group 0 starts at the same raw address as its
main, so the modulo heuristic let "Вкл/Выкл" clobber "Освещение" and the
main-range rescue silently died. Depth in the range tree decides now.
- a category from a whole-main DPT fallback (e.g. 20.609 -> hvac) was treated as
strong; only an exact (main,sub) table entry is strong now (is_exact_dpt).
- DPT 1.010 start/stop marked soft: ventilation timers use it, not just shutters.
- terms learned: Cyrillic а/с, сплит, вытяжк, яркост (RU only); weather/метео in
sensor, and sensor now outranks hvac so weather-station temperature is a
sensor, not an HVAC actuator.
Real-project noise after the round: Minsk 1 outlier/685 GAs (was 31 pre-P5),
demo 2/239, Razdory 46/3646. Regressions in test_domain_classifier. 13/13 green.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
A 1-bit switch is domain-agnostic, yet DPT 1.001 defaulted to 'lighting', so an
"AC on/off" was classified lighting and tripped downstream checks. The domain is
now a combination: explicit name > strong domain-encoding DPT > main-group name;
a bare 1-bit GA with no signal is honestly 'unknown', never a guessed lighting.
An explicit name contradicting a STRONG DPT yields 'unknown' (a genuine conflict,
shown by explain_ga as contested), not a silent pick. Word-boundary matching so
"ac" no longer fires inside "terrace"; name terms broadened (EN+RU HVAC incl.
ac/a-c/air-conditioner, RGB/colour lighting).
check_policy taxonomy-outlier now flags only misplaced ACTUATORS (lighting/
shutter/hvac); sensors, scene links, thresholds and timeout params are the
cross-cutting GAs they are. HA generator still emits a switch for a now-HVAC
simple on/off, so no device is dropped.
Verified on 3 real projects: every AC on/off is HVAC; outlier noise fell demo
11->2, Minsk 31->6, Razdory 200->57. tests/test_domain_classifier.py (13/13 green).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Matter readiness, the completeness grade and command/status coverage each now
carry a `math` block: numerator, denominator, the exact formula that reproduces
the percentage, and (for Matter) the functions excluded from the denominator
because their category has no Matter cluster — previously a silent skip and the
biggest "why is this number what it is?" gap. Completeness also states its band
thresholds. Report-only, additive; scores unchanged, only now auditable.
Raised by external review. tests/test_explainable_aggregates.py (12/12 green).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
A .knxproj is a user-supplied ZIP-of-XML — untrusted input. New safexml.py
centralises hardened parsing for every place we open an archive or parse XML
ourselves (load_project, check_device_parameters, app-program parser):
XML - dependency-free reject of DOCTYPE/ENTITY (billion-laughs / XXE;
legitimate ETS XML never carries one) + defusedxml parser-level
blocking when installed (added as a dependency).
ZIP - pre-flight against absolute caps (archive size, entry count, per-member
and total decompressed size, compression ratio) rejects zip-bombs;
member names checked for path-traversal / absolute paths; each member
read through a streaming cap so a lying header can't exhaust memory.
Violations return a normal error dict, not a traceback. Still read-only.
Raised by external security review. tests/test_safexml.py (11/11 suite green).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Council #2: the empty GA 2/5/2 spawned missing_status + policy_taxonomy_outlier +
a lighting classification on top of its real defect. An empty name means the
classifier can't be trusted, so detect_missing_status and check_policy now skip
blank-name GAs; the single root cause is empty_name (check_naming). Demo 2/5/2:
3 findings -> 1. tests/test_root_cause.py; full suite green (10 tests).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Three independent reviewers (two external councils + a field integrator) asked for
the same thing: the enriched model mixes ETS facts, DPT structure and name
heuristics, and downstream tools treat it almost as fact. explain_ga makes the
reasoning auditable per GA — evidence per decision with a confidence tier
(authoritative ETS Function > structural DPT > heuristic name), the status-pairing
method, and CONFLICTS (name 'AC' vs DPT 'lighting' -> contested), the silent-
misclassification hotspot. Additive, read-only, no core-model change. Full suite green.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
'Does the function have *a* status' missed a dimmer with on/off status but no
brightness status (demo planted error #3), silently inflating coverage/Matter.
detect_role_completeness flags a brightness/position command (5.001) whose device
has no matching value status (missing_value_status), with a device-identity match
so it doesn't borrow a sibling's status. Demo recall 4/5 -> 5/5. Raised by the
external expert review. Test + demo ground-truth updated. Full suite green.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
External expert review (real run on the demo house) flagged: scenes (18.001)
wrongly marked missing_status + an unsafe DPT-1.011 status repair for them;
'All blinds down' warned while 'All lights off' was correctly INFO; and a Russian
'(статус)' suffix synthesised on an English project. Fixes: scene_no_status INFO
+ no synth status for scenes; broadened central-macro detection (generic 'all
blinds/shutters/...'); language-matched repair suffixes. Demo missing_status
warnings ~7 -> 1 genuine. tests/test_council_fixes.py; full suite green.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Rank findings by significance: config_value (setpoint/hysteresis/time/threshold —
an odd device is usually a real mistake) vs config_flag (mode/type) vs label
(per-room text, often intentional). New focus list surfaces the config-value clear
outliers first. On a real 275-device project this turns 422 raw outliers into a
9-item focus that includes the thermostats whose init-setpoint differs from their
siblings. Multilingual name hints (EN/DE/RU). Test updated.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Validate a project against ITS OWN rules, not a universal standard. With a YAML
profile the declared main-group taxonomy / naming / pairing is authoritative;
with no profile the taxonomy is INFERRED from the project itself and GAs that
deviate from their main group's own majority domain are flagged — never against
an alien standard (a well-organised real 356-GA project drops from 329 false
mismatches vs the default to 31 genuine self-deviations). Answers the recurring
integrator critique that 'your best practices aren't universal'. Example profile
+ test_policy.py included.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
New module param_check.py + MCP tool check_device_parameters: reads per-device
ParameterInstanceRef values from the .knxproj project part (xknxproject does not
expose them), groups identical devices by application program, and flags the odd
one out — clear_outliers (a strong majority with a small minority, e.g. one
thermostat with a different setpoint/hysteresis) and split_configs (balanced
variants → review). Parameter names resolved from the app-program; encrypted
projects skipped honestly. Read-only, no ETS/bus. Validated on real 42-275-device
projects; synthetic test_param_check.py. Answers a community feature request.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add a community-driven roadmap: cross-device parameter consistency check
(feasibility validated by a PoC on real 42-275-device projects — find the odd
thermostat/sensor out; not yet shipped), a Project Policy Profile, and an
honest note that in-ETS GA linking is left to existing add-ins / ETS7 Smart
Linking while we focus on read-only audit + an evidential model.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The nightly HA sync runs via shell_command in the Core container, not the SSH
add-on where install ran. Core has an empty known_hosts, so git push failed
"Host key verification failed" — the commit was made locally but never reached
GitHub. install.sh now seeds a repo-local known_hosts (ssh-keyscan) and pins
git config core.sshCommand so every context (add-on, Core, cron) uses the same
working ssh. Also drops a stray `.git-sync` arg from the pre-commit chmod line.
Records LESSON-06 + a symptom-table row in SKILL.md and SKILL.ru.md; CHANGELOG
Fixed entry. Field-validated on a live Home Assistant.
Circuit 1: real git in /config (deploy key, pre-commit secret scanner,
meaningful commits). Circuit 2: age-encrypted native HA backups in GitHub
Releases with rotation and a mandatory monthly restore drill. Ships
install/sync/scan/offsite/restore scripts, HA automations/snippets,
setup + architecture + incident + runbook references, EN + RU skill docs.
README/README.ru gain an ops-companion bullet in Scenario 3;
CHANGELOG [Unreleased] Added entry (no version bump).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Reframe README.md, README.ru.md and docs/index.html around what you can
do with the server: (1) design a project from a spec into a full
implementation kit, (2) audit/repair/finish an existing .knxproj,
(3) generate the Home Assistant layer — plus the device-library
foundation. Adds anonymised field numbers from real project validation
(~92% structural match on 3,600+ GA; 145 repair proposals on 3,646 GA).
No functional changes, tool count unchanged (25), not a release.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
From validator to repairer: propose concrete fixes, not just flag problems.
- B1 repair-suggestion engine (repair.py) + suggest_repairs MCP tool: infer a
DPT for a missing-DPT GA, correct a suspect sub-DPT, synthesise a status GA in
a free slot, or add an absolute-brightness GA. Suggestions only; accepted new
GAs feed generate_ets_group_addresses; never writes to ETS or the bus.
- A2 relative-only-dimming detector (analyze.py): 3.007 relative dimmer with no
5.001 absolute-brightness GA in its zone -> HA cannot set a level.
- A3 cover invert/travel-time surfacing (generate_ha.py): verify_cover_invert
review note lists actuator-dependent flags absent from the .knxproj and warns
when position lacks a state address.
- A2/A3/B1 regression tests; CHANGELOG + version bump to 0.5.0.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
A1 — sub-DPT sanity linter: when a GA name implies a specific DPT
sub-type (temperature->9.001, power->14.056, brightness/position->5.001),
flag a wrong sub or wrong main. Multilingual, conservative; surfaced as
the subdpt_suspect finding via check_dpt / analyze_all.
A4 — KNX Data Secure posture: secure_posture() + new check_secure MCP
tool. Report-only summary (secured vs plaintext counts, mixed
secure/plaintext middle groups, keyring handover checklist). Reads only
the per-GA Security flag; no key material touched. Handover pack section
5 rewritten to this posture section.
Version bump to 0.4.0; CHANGELOG updated.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Turn the tool from a .knxproj validator into a design aid.
- device_library.py + decompose_device / list_device_recipes MCP tools:
expand a device (order number / type / alias) into its group-address
recipe — command/status/dimming/position/mode objects with DPTs —
across Zennio + ABB families. Generic vendor facts, typical-wired set.
- docs/spec-to-structure.md: the spec→structure methodology, with a
measured account of what a spec reproduces (~90%) vs the per-device
object count it cannot (2–9× per-project parameterisation).
- Ship alongside the Track B generate_handover_pack and the de-noise
refinements accumulated since 0.2.0.
- CHANGELOG 0.3.0; version bump 0.2.0 → 0.3.0; new device-library tests.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Main/middle range names now resolve correctly (e.g. [1] Освещение 1 этаж, [5] Климат)
instead of a middle-group name leaking into the main.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Three false-alarm downgrades derived from validating on a larger multi-vendor
villa, each turning a false positive into an INFO note without hiding any real
defect:
- intent: divider/separator names (punctuation-only or a marker wrapped in it,
e.g. "-----addition------", "---") classify as `scratch`, so a missing DPT on
them is INFO, not a red error.
- analyze: typed GAs wired into Zennio "[LF] ... Data Entry" type-agnostic
logic-function containers surface as INFO `dpt_on_logic_object` instead of a
false `dpt_mismatch_co` warning.
- analyze: all-groups broadcast/central-macro commands surface as INFO
`central_macro_no_status` instead of `missing_status_address`, since a fan-out
broadcast has no single state to read back.
Adds a regression block covering all three; real DPT mismatches and real
missing-status gaps still warn. Unreleased; no version bump.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Lead with colour/climate assembly, noise reduction, and the spec-PDF→96%
case study. Added a dedicated r/knx variant. EN+RU. Posts remain the owner's
to publish from their own accounts.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
A 96% structural match of an auto-designed GA structure vs a professional
reference, from a 42-page spec alone — 662 GA, 0 validation errors, HA package.
No client data/files; reference used only as an anonymous benchmark.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Layer-2 (design-time) row in both READMEs now lists colour/climate assembly and
GA-intent de-noise; site version pill bumped to v0.2.0 to match the release.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Bump version 0.1.2 -> 0.2.0 (pyproject + __init__). Promote the
Unreleased changelog section to [0.2.0] — 2026-06-30. Scrub a client
city label from two test comments (provenance note only, no PII/topology).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Re-captured all 5 live HA dashboard views (consistent 1240px, no PII): overview
now shows the floor-heating climate snapshot, climate shows the 6 floor-heating
thermostats + valve gauges, lighting shows RGBW/RGB/CCT colour lights (the prior
'Ошибка' was a non-existent light-color tile feature, now removed). Site fact
cards + gallery captions + both READMEs updated to describe colour/climate.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Root README + RU now list the Track A/D capabilities: GA-intent classification
(reserve/logic/scratch kept out of error & missing-status checks), colour light
assembly (RGBW/RGB/CCT) and climate entity generation, with the real 685-GA
Zennio validation figure (false errors 29 -> 6).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Regenerate examples/demo-home/generated/ with the current generator:
13 lights now carry RGBW/RGB/CCT colour, 6 climate zones assembled with
HA-doc-verified keys, sensors fold into climate where applicable.
README updated (entity counts, capability note) and records that the real
ETS6-signed round-trip was validated. Report source path sanitized (relative).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Colour control assembled into light entities (RGB 232.600, RGBW 251.600,
xyY 242.600, colour-temp 7.600) with statuses, matched by zone identity.
Climate entities generated from HVAC mode zones (temp 9.001 + target status
+ operation/controller mode 20.102/20.105 + valve command_value 5.001),
emitted only when HA-required keys are present, else routed to review.
B1 fix: a command no longer borrows a sibling's status (identity must nest,
status maps to exactly one entity) — removed all shared-status addresses.
New DPTs 232.600/251.600/242.600/7.600/20.105/1.100. HA keys verified vs docs.
Real files: signed demo 6 climate + 4 colour lights; Zennio 685-GA 7 climate;
zero shared-status; all 10 regression groups pass.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Classify every group address as functional/reserve/logic/scratch (intent.py)
and reclassify intentional non-functional GAs instead of crying wolf:
- reserve spare with no DPT -> INFO reserve_without_dpt (not a missing_dpt error)
- reserve name reused across DPTs -> no duplicate_name / inconsistent_dpt
- logic/virtual + scratch GAs -> excluded from missing-status warnings
dpt_mismatch_co and all real functional findings are untouched.
Driven by a real 685-GA Zennio project: false errors 29 -> 6,
missing-status noise 79 -> 45, all 12 real dpt_mismatch_co catches preserved.
Intent breakdown now exposed via list_group_addresses, report inventory and
the analyze_all summary. New regression test covers the reserve/logic/scratch
patterns and proves real DPT + status problems still surface.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Glama Docker introspection passes (build success, MCP release created).
Satisfies awesome-mcp-servers listing requirement: server is on Glama
and the score badge is now shown in both READMEs.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Builds the stdio MCP server into a slim image (verified: container starts and
responds to initialize + tools/list with all 12 tools). Enables the Glama
(glama.ai) checks required by the awesome-mcp-servers listing bot.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
A professional KNX engineer confirmed ETS rejects the programmatically-authored
demo project on import ('Project file has no valid signature') — ETS signs its own
projects and that can't be forged. Document the real-file path: import the GA
export XML into ETS and export from there.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>