A .knxproj is a user-supplied ZIP-of-XML — untrusted input. New safexml.py
centralises hardened parsing for every place we open an archive or parse XML
ourselves (load_project, check_device_parameters, app-program parser):
XML - dependency-free reject of DOCTYPE/ENTITY (billion-laughs / XXE;
legitimate ETS XML never carries one) + defusedxml parser-level
blocking when installed (added as a dependency).
ZIP - pre-flight against absolute caps (archive size, entry count, per-member
and total decompressed size, compression ratio) rejects zip-bombs;
member names checked for path-traversal / absolute paths; each member
read through a streaming cap so a lying header can't exhaust memory.
Violations return a normal error dict, not a traceback. Still read-only.
Raised by external security review. tests/test_safexml.py (11/11 suite green).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Three independent reviewers (two external councils + a field integrator) asked for
the same thing: the enriched model mixes ETS facts, DPT structure and name
heuristics, and downstream tools treat it almost as fact. explain_ga makes the
reasoning auditable per GA — evidence per decision with a confidence tier
(authoritative ETS Function > structural DPT > heuristic name), the status-pairing
method, and CONFLICTS (name 'AC' vs DPT 'lighting' -> contested), the silent-
misclassification hotspot. Additive, read-only, no core-model change. Full suite green.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Validate a project against ITS OWN rules, not a universal standard. With a YAML
profile the declared main-group taxonomy / naming / pairing is authoritative;
with no profile the taxonomy is INFERRED from the project itself and GAs that
deviate from their main group's own majority domain are flagged — never against
an alien standard (a well-organised real 356-GA project drops from 329 false
mismatches vs the default to 31 genuine self-deviations). Answers the recurring
integrator critique that 'your best practices aren't universal'. Example profile
+ test_policy.py included.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
New module param_check.py + MCP tool check_device_parameters: reads per-device
ParameterInstanceRef values from the .knxproj project part (xknxproject does not
expose them), groups identical devices by application program, and flags the odd
one out — clear_outliers (a strong majority with a small minority, e.g. one
thermostat with a different setpoint/hysteresis) and split_configs (balanced
variants → review). Parameter names resolved from the app-program; encrypted
projects skipped honestly. Read-only, no ETS/bus. Validated on real 42-275-device
projects; synthetic test_param_check.py. Answers a community feature request.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add a community-driven roadmap: cross-device parameter consistency check
(feasibility validated by a PoC on real 42-275-device projects — find the odd
thermostat/sensor out; not yet shipped), a Project Policy Profile, and an
honest note that in-ETS GA linking is left to existing add-ins / ETS7 Smart
Linking while we focus on read-only audit + an evidential model.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Circuit 1: real git in /config (deploy key, pre-commit secret scanner,
meaningful commits). Circuit 2: age-encrypted native HA backups in GitHub
Releases with rotation and a mandatory monthly restore drill. Ships
install/sync/scan/offsite/restore scripts, HA automations/snippets,
setup + architecture + incident + runbook references, EN + RU skill docs.
README/README.ru gain an ops-companion bullet in Scenario 3;
CHANGELOG [Unreleased] Added entry (no version bump).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Reframe README.md, README.ru.md and docs/index.html around what you can
do with the server: (1) design a project from a spec into a full
implementation kit, (2) audit/repair/finish an existing .knxproj,
(3) generate the Home Assistant layer — plus the device-library
foundation. Adds anonymised field numbers from real project validation
(~92% structural match on 3,600+ GA; 145 repair proposals on 3,646 GA).
No functional changes, tool count unchanged (25), not a release.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
A 96% structural match of an auto-designed GA structure vs a professional
reference, from a 42-page spec alone — 662 GA, 0 validation errors, HA package.
No client data/files; reference used only as an anonymous benchmark.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Layer-2 (design-time) row in both READMEs now lists colour/climate assembly and
GA-intent de-noise; site version pill bumped to v0.2.0 to match the release.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Re-captured all 5 live HA dashboard views (consistent 1240px, no PII): overview
now shows the floor-heating climate snapshot, climate shows the 6 floor-heating
thermostats + valve gauges, lighting shows RGBW/RGB/CCT colour lights (the prior
'Ошибка' was a non-existent light-color tile feature, now removed). Site fact
cards + gallery captions + both READMEs updated to describe colour/climate.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Root README + RU now list the Track A/D capabilities: GA-intent classification
(reserve/logic/scratch kept out of error & missing-status checks), colour light
assembly (RGBW/RGB/CCT) and climate entity generation, with the real 685-GA
Zennio validation figure (false errors 29 -> 6).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Glama Docker introspection passes (build success, MCP release created).
Satisfies awesome-mcp-servers listing requirement: server is on Glama
and the score badge is now shown in both READMEs.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Discussions badge + call-to-action linking to Discussion #1, plus a nav 'Discuss'
link and a CTA button on the landing site.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Five real screenshots of the live Demo House dashboard (overview/climate/lighting/
energy/presence). The site now leads with a real screenshot gallery (interactive
mock kept below), and both READMEs gain a live-dashboard gallery section.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add a linked SVG hero banner (docs/assets/banner.svg), a 'live demo' badge, a
heading link and a callout pointing to the GitHub Pages site and the demo house,
in both README.md and README.ru.md.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Design-time MCP server that reads .knxproj (read-only), validates naming/DPT/status,
and generates Home Assistant KNX YAML + ETS-importable group addresses (XML/CSV).
No live bus access — confined-workspace writes only.
Includes: 12 MCP tools, end-to-end smoke test, MIT license, English-first README
(+ Russian), CONTRIBUTING with a real-project test call, SECURITY policy, CHANGELOG,
GitHub Actions CI (Python 3.10–3.12), and issue/PR templates.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>