Skip to content

v0.5.2

Choose a tag to compare

@github-actions github-actions released this 30 Sep 08:47
· 11 commits to main since this release

What changed

Take this one if you acknowledge alerts from ntfy. The Acknowledge button
did not acknowledge anything — and made it look as though it had.

Fixed

  • ntfy's Acknowledge button acknowledged nothing, then cleared the
    notification.
    The button is a background request: ntfy sends it and shows
    nobody the answer. It sent a GET, and the acknowledgement link answers a GET
    with an "are you sure?" page — on purpose, because mail scanners open links,
    and a link that acknowledged on a GET would let one acknowledge an alarm
    nobody saw. So the page was rendered to nobody, nothing was acknowledged,
    and the notification then disappeared from the phone. The operator believed
    the alarm was dealt with while it went on escalating.

    The button now POSTs, which acknowledges in one tap — a tapped button is a
    person, not a prefetcher. The acknowledgement is recorded as coming through
    ntfy. If the phone cannot reach the acknowledgement address, ntfy keeps the
    notification and shows the error, rather than clearing it.

    Alerts sent before you upgrade still carry the old button. Acknowledge those
    from the incident board, or by opening the link and confirming.

Added

  • Each paired product has its own silence window. It was sixteen minutes
    for every peer. When a Sentry update left a site's Sentry dead, those were
    sixteen minutes in which nothing watched the doors: while Sentry holds
    Access, this product's own Access ingest stands down, and it only took the
    doors back when the window ran out.

    Set silent_after under a product in config.yaml — 2m for Sentry, say —
    and it applies within seconds, no restart. After that long without contact
    the product is reported silent and, if it holds a capability, loses it at
    the same moment, so this product's own source takes over in two minutes
    instead of sixteen. Blank keeps sixteen minutes; the window is kept between
    a minute and a day, and a value outside that is used at the nearest limit
    with a warning rather than refusing to start.

    The product is told how often to heartbeat to meet its window — a third of
    it — in every reply, so a change reaches it at its next contact. Sentry
    1.6.15, Lightspeed Rewards and LSProtect follow it; an older release keeps
    heartbeating every five minutes, and the Peer link page now warns when a
    product is going longer between contacts than its window
    , before its
    silence alarm fires for a product that is fine.

    Shortening a window never pages anybody about a healthy product: it learns
    its new rate at its next contact, and until then it is held to the window it
    was last told. After this product restarts, a product not yet heard from is
    given at least six minutes — the slowest rate it might still be on, and a
    minute — before it can be reported silent.

Verifying this release

Every binary is signed. Verification instructions, including how to
rebuild from source and compare hashes, are in
docs/RELEASING.md.

Linux / macOS — cosign (keyless, no key to trust in advance):

cosign verify-blob notifymatrix-linux-amd64 \
  --bundle notifymatrix-linux-amd64.sigstore.json \
  --certificate-identity-regexp '^https://github\.com/suburbazine/Unifi-Notification-Matrix/' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

Download the .sigstore.json next to the binary; it carries the
signature, the certificate and the transparency-log proof. Keep
--certificate-identity-regexp — without it cosign verifies a
signature from anyone.

Build provenance (any platform):

gh attestation verify notifymatrix-linux-amd64 --repo suburbazine/Unifi-Notification-Matrix

Windows: the .exe is Authenticode-signed and timestamped.
Right-click → Properties → Digital Signatures, or:

Get-AuthenticodeSignature .\notifymatrix-windows-amd64.exe

This is source-available software under the
PolyForm Noncommercial License 1.0.0. Commercial use
requires a licence: licensing@xtremission.com

Full Changelog: v0.5.1...v0.5.2