v0.4.0
What changed
Take this one if you run UniFi Access. Its notifications socket moved, and
earlier builds cannot find it — which means no live door events, silently.
A minor rather than a patch because alerts can now carry a sentence they never
carried before, and there is a new panel on the Health tab to go with it.
Added
-
Alerts can say whether they arrived alone or in a crowd, and the Health
tab shows what the crowd is.The motivating case is a wireless jammer before a break-in: several devices
going quiet at once, none of them decisive on its own. Not caught as
unusual silence — a site that is normally silent at 3am has no signal to
lose — but as the disconnect burst the jamming causes, which is many devices
at once and is what the measurement watches for.Spread carries the verdict and volume never does alone. Fifty events
from one flapping camera is not a surge and must never read as one; nine
devices producing one each is the shape that matters. Events that rules
silenced are counted, because a site whose motion is suppressed is still a
site with motion in it, and those are exactly the events a jammer removes.Decoration only. It cannot move a severity or a ladder: a statistical
signal nudging a real alarm up a tier is how a firmware rollout becomes a
phone call at 3am.The baseline is learned per hour, weekday and weekend apart, over eight
weeks, and is not quoted until it has been earned — fourteen days, and
twenty-four comparable stretches for the hour in question. Until then the
panel states the count and says what it is waiting for.It stays quiet in two states where a sentence would be worse than none:
under ten minutes of uptime, and while any source is not reporting. The
panel says which, because "nothing unusual" and "we are not watching all of
it" look identical on a screen and are opposite facts.At 144 stretches a day for 56 days the history is 8,064 rows for any site,
busy or quiet, pruned as it is written.
Fixed
-
The Access notifications socket moved, and this build now finds it. On
an ENVR running current Access,/proxy/access/api/v1/developer/devices/notifications
answers 404 to a key whoseintegrationREST paths return 28 doors — and
the same path under the REST base connects and delivers. Captured by the
probe on real hardware, which is why this is a fact rather than a guess.Both paths are tried, current firmware first, and the one that connects is
remembered so a reconnect never pays the 404 twice. The older path is kept
because the only two door-state message shapes this build knows were
captured there, and a site on that firmware must not lose its socket to a
fix for another. -
A keepalive is no longer evidence that the stream is unintelligible.
That console sends a bare string six times a minute, plus an informational
event about its own log depth. Counted as frames nobody could read, fifty of
them raise a high incident saying door-forced detection is degraded — on
a console whose socket is working perfectly, because nobody has opened a
door yet. Which is most sites at 3am.Protocol noise is now counted apart from failures to understand. The alarm
still fires for what it was built for: door state arriving in a shape this
build cannot read.
Changed
-
A Network device going offline now raises
low, nothigh. On the
default laddershighwakes somebody — for an access point rebooting, a PoE
port cycling, or a switch that was unplugged on purpose. Most of what
polling a controller produces is operational noise, and an operator woken by
it either stops trusting the product or turns the source off.What makes one of these serious is the company it keeps: the same outage
taking a camera or a door controller with it. The Network source polls one
API and knows nothing about Protect or Access, so deciding that there would
be a guess dressed as a severity. A site that knows which switch carries the
door hardware raises that one with a rule.
Fixed
-
"The only way Network events exist at all" was wrong, and read as
"Network needs webhooks". A console with an API key andnetworkin its
sources already reports switches and access points going offline, derived
from polling, with no rule involved. Alarm Manager rules are for the alarms
no API carries — WAN outages, threat detections, PoE faults, and Protect's
own hardware alarms.Corrected in the README, in the setup guide, in the checklist's own
reasoning, and on the Webhooks screen, which now says plainly that none of
it is needed to watch a console.
Verifying this release
Every binary is signed. Verification instructions, including how to
rebuild from source and compare hashes, are in
docs/RELEASING.md.
Linux / macOS — cosign (keyless, no key to trust in advance):
cosign verify-blob notifymatrix-linux-amd64 \
--bundle notifymatrix-linux-amd64.sigstore.json \
--certificate-identity-regexp '^https://github\.com/suburbazine/Unifi-Notification-Matrix/' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
Download the .sigstore.json next to the binary; it carries the
signature, the certificate and the transparency-log proof. Keep
--certificate-identity-regexp — without it cosign verifies a
signature from anyone.
Build provenance (any platform):
gh attestation verify notifymatrix-linux-amd64 --repo suburbazine/Unifi-Notification-Matrix
Windows: the .exe is Authenticode-signed and timestamped.
Right-click → Properties → Digital Signatures, or:
Get-AuthenticodeSignature .\notifymatrix-windows-amd64.exe
This is source-available software under the
PolyForm Noncommercial License 1.0.0. Commercial use
requires a licence: licensing@xtremission.com
Full Changelog: v0.3.9...v0.4.0