Kubernetes and `docker stop` send SIGTERM and then SIGKILL once the grace
period expires; previously oott ignored it and was always force-killed.
Add a shutdown module that watches for SIGTERM (and SIGINT/Ctrl-C) and
cancels a CancellationToken shared by every long-running task. Each scanner,
the retention cleaner, and the notification delivery loop now select on the
token and stop at their next safe point (abandoning in-flight probes and
skipping inter-scan sleeps), the web server drains in-flight requests via
axum's with_graceful_shutdown, and main checkpoints the WAL via db::close()
once all tasks have stopped.
No internal deadline is added: the orchestrator's grace period already bounds
shutdown, and tasks stop on iteration boundaries so there is no half-written
DB state.
Refs #7
Tier-1 dependency refresh (lockfiles only, no manifest/version-range
changes):
- frontend/pubspec.lock: dio, go_router, shared_preferences and others
to their latest in-range versions.
- backend/Cargo.lock: tokio 1.49->1.52.3, clap 4.5->4.6, tower-http,
serde_json and a batch of transitive crates.
All frontend (152) and backend (165) tests pass.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Backend (Rust):
- push_tokens migration, model (PushToken/PushPlatform), and db layer
(upsert/list/delete/delete_many)
- PUT/DELETE /api/push_tokens endpoints wired into the router + OpenAPI
- "push" notification method: relay sender (reqwest) that forwards only the
sanitized title/body and prunes dead tokens, plus settings with a default
relay_url
- 164 tests pass, clippy clean
Relay (push_relay/, TypeScript Firebase Cloud Function):
- POST /v1/push (firebase-admin sendEach + per-token status mapping),
GET /healthz, payload validation, per-IP Firestore rate limiting
- Jest tests + README documenting the manual project-owned setup
Frontend (Flutter):
- oott_api_push.dart (register/unregister), push_service.dart behind a
PushService abstraction, and a per-device push toggle in settings
- firebase_core/firebase_messaging/flutter_local_notifications deps
- 145 tests pass, dart analyze clean
Dev shell:
- add nodejs_22 to the Nix dev shell so the relay tests/build run locally
Remaining (manual, project-owned): create the Firebase project, deploy the
relay and set the real default_relay_url, add native Firebase config, and test
on real devices.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Introduce a sixth scanner that periodically queries an SNMP agent
(typically the router/firewall) for its ARP/neighbour cache via
SNMPv2c and feeds discovered devices into the shared devices, events
and notifications pipeline. Unlike the ARP scanner it generates no
traffic on the local segment and can surface devices across all
subnets the agent routes.
Scope is intentionally minimal: SNMPv2c only, a single target, and the
ipNetToMediaTable (ARP) only. SNMPv3 and switch MAC/forwarding-table
polling are left as follow-ups in TODO.md.
- backend: csnmp dependency; SnmpScanner config (opt-in, off unless a
[snmp_scanner] section is present); DeviceEventScanner::Snmp;
scanners/snmp/{finder,scanner,status}; main.rs wiring; status API
endpoint wired into OpenAPI
- frontend: SNMP scanner status model, card, API method, status screen
and summary card rows, and device-event label
- docs/config: sample TOML, README options, NixOS module option, and
setup notes for enabling SNMP on pfSense/OPNsense
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Introduce a second discovery module that passively listens for mDNS
multicast announcements (224.0.0.251:5353) and feeds discovered devices
into the existing devices/events/notifications pipeline, running in its
own task alongside the ARP scanner.
Since mDNS carries an IP and hostname but no MAC (the device key), the
module resolves IP->MAC via the OS ARP cache with a targeted ARP-probe
fallback. The advertised hostname is stored in a new optional `name`
column on devices (blank for ARP-only devices); the single `update`
writes `name` only when set so ARP rescans never clobber it. Device
names are included in event/notification messages.
Adds a GET /api/mdns_scanner/status endpoint (is_listening, devices_seen,
last_device_seen_seconds_ago) wired into OpenAPI, an optional
[mdns_scanner] config section, and the corresponding Nix module option.
Also aligns the Nix module's stale `timings` section with the current
`arp_scanner` schema.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Annotates all API handlers and model structs with Utoipa macros to generate
an OpenAPI 3.0 spec at runtime. Serves an interactive Swagger UI at /api/docs
and the raw JSON spec at /api/docs/openapi.json, both publicly accessible
outside the auth middleware.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>