Post-fix hardening from an LLM-council review of 0198ae3, with a gate-1 audit pass:
- _is_shutter_control rejects a bare 1.007/1.010 whose tokens are a foreign domain
(light/dim/socket/HVAC) or a central macro (Alle/Zentral) — a 'stop' is an operation
signal, not a domain one, so a lighting 'Licht Stopp' or a house-wide 'Alle Stopp' can
no longer be mis-paired/stolen as a cover's step/stop.
- _rank gains a stable address tiebreak -> deterministic pick across parses on a full tie.
- gate-1 caught 'master' wrongly excluding Master-zone covers; removed. Vent words kept
admissible (roof-window/flap openers are covers).
- tests groups E/F/G pin the foreign-stop, central-steal, and Master-zone cases.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Second pass on issue #11, grounded in Kris1166's real ETS-6 field dump (groups A/B/C),
after the first fix (dd8ecac) proved partial. Three levers:
- project.py: ETS Function role (MoveUpDown/StopStepUpDown) authoritatively promotes a
GA to category=shutter — rescues bare DPT 1.007 step/stops the name classifier left
'unknown' (group A: 26/33 covers were dropped). Guarded to DPT 1.x/5.x; role strings
from Kris's real dump, not invented.
- generate_ha.py: cover builder now gathers candidates and picks the BEST per role
(same-function > name-token overlap > nearest sub) instead of first-match, so a
function-less roller takes its own step/stop, not an awning's sharing the zone token
(group C). Bare 1.007/1.010 admitted only with a shutter name signal, so a foreign
lighting step can't be stolen (audit finding).
- tests: test_cover_pairing.py rebuilt from the real A/B/C structures + a group-D guard
for the foreign-1.007 case. Fails without the fix, passes with it.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
generate_ha_package cross-wired move_short_address across unrelated ETS
Functions sharing a zone token (a window and an awning both 'Room A'), and
could leave a cover with no step/stop. Pair siblings by ETS Function
membership (authoritative); a sibling owned by a different function is never
borrowed. Falls back to the existing name-token logic only when the move GA
has no function, so projects without ETS Functions are unchanged.
Adds tests/test_cover_pairing.py (reproduces the field case from #11, fails
without the fix) and wires it into CI.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>