Skip to content

fix: keep LocalStats on channel encryption by default - #11246

Open
RCGV1 wants to merge 3 commits into
meshtastic:developfrom
RCGV1:codex/localstats-channel-encryption
Open

fix: keep LocalStats on channel encryption by default#11246
RCGV1 wants to merge 3 commits into
meshtastic:developfrom
RCGV1:codex/localstats-channel-encryption

Conversation

@RCGV1

@RCGV1 RCGV1 commented Jul 27, 2026

Copy link
Copy Markdown
Member

Summary

  • Keep only Telemetry.local_stats on normal shared-channel encryption by default; other telemetry variants keep their existing PKI behavior.
  • Preserve PKI when a LocalStats packet is explicitly marked for PKI, which the forthcoming restricted policy needs.
  • Add regression coverage for default LocalStats, explicit PKI LocalStats, and DeviceMetrics scope isolation.

Why

Clients construct ordinary LocalStats requests on the node's shared channel. The router was auto-upgrading those packets to PKI whenever destination identity keys were known. This preserves the expected shared-channel behavior without making packets plaintext and without weakening other telemetry.

Validation

  • trunk fmt src/mesh/Router.cpp test/test_admin_session_repro/test_main.cpp
  • platformio test -e coverage -v -f test_admin_session_repro in the project Docker test image: 26 cases passed.

Follow-up

protobufs#1023 proposes the device-owned LocalStats request policy. Firmware enforcement will require explicit PKI from configured remote-admin keys, set the reply PKI flag, and silently reject unauthorized requests; it is tracked in firmware#11247.

Summary by CodeRabbit

  • Bug Fixes
    • Local statistics telemetry now uses shared-channel encryption by default instead of PKC encryption.
    • Explicitly configured PKC encryption remains supported for local statistics telemetry.
    • Other telemetry message types continue to follow their existing encryption behavior.

@coderabbitai

coderabbitai Bot commented Jul 27, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

Updates Router::wouldEncryptWithPKC so LocalStats telemetry uses shared-channel encryption by default, while explicitly PKC-marked packets remain eligible. Adds a Unity regression test covering LocalStats and other telemetry.

Changes

Telemetry encryption behavior

Layer / File(s) Summary
LocalStats PKC eligibility and regression coverage
src/mesh/Router.cpp, test/test_admin_session_repro/test_main.cpp
Adds LocalStats payload detection, updates PKC eligibility, and tests default, explicit, and non-LocalStats telemetry behavior.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related issues

Possibly related PRs

Suggested labels: bugfix, needs-review

Suggested reviewers: thebentern, jp-bennett, caveman99

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly summarizes the main change: LocalStats stays on shared-channel encryption by default.
Description check ✅ Passed The description covers summary, why, validation, and follow-up, but it omits the template's attestation checklist.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Jul 27, 2026

Copy link
Copy Markdown
Contributor

⚡ Try this PR in the Web Flasher

Flash this PR in the Web Flasher

firmware commit boards expires

Warning

This is an automated, unreviewed CI test build. Back up your device configuration
before flashing, and only flash devices you are able to recover.

Supported boards built by this PR (31)
Device Board Platform
Crowpanel Adv 3.5 TFT elecrow-adv-35-tft esp32-s3
Heltec HT62 heltec-ht62-esp32c3-sx1262 esp32-c3
Heltec Mesh Node 096 heltec-mesh-node-t096 nrf52840
Heltec Mesh Node T1 heltec-mesh-node-t1 nrf52840
Heltec Mesh Node T114 heltec-mesh-node-t114 nrf52840
Heltec V3 heltec-v3 esp32-s3
Heltec V4 heltec-v4 esp32-s3
Meshnology W10 meshnology_w10 esp32-s3
Meshnology W12 meshnology_w12 esp32-s3
Raspberry Pi Pico pico rp2040
Raspberry Pi Pico W picow rp2040
RAK WisMesh Pocket V3 rak_wismesh_pocket nrf52840
RAK WisMesh Pod rak_wismesh_pod nrf52840
RAK WisMesh Repeater Mini V2 rak_wismesh_repeater_mini nrf52840
RAK WisMesh Tag rak_wismeshtag nrf52840
RAK WisBlock 11200 rak11200 esp32
RAK WisBlock 11310 rak11310 rp2040
RAK3312 rak3312 esp32-s3
RAK WisBlock 4631 rak4631 nrf52840
Seeed SenseCAP Mesh-Tracker-X1 seeed_mesh_tracker_X1 nrf52840
Seeed Wio Tracker L1 seeed_wio_tracker_L1 nrf52840
Seeed Xiao NRF52840 Kit seeed_xiao_nrf52840_kit nrf52840
Seeed Xiao ESP32-S3 seeed-xiao-s3 esp32-s3
Station G2 station-g2 esp32-s3
Station G3 station-g3 esp32-s3
LILYGO T-Deck t-deck-tft esp32-s3
LILYGO T-Echo t-echo nrf52840
LILYGO T-Echo Plus t-echo-plus nrf52840
LILYGO T-Impulse Plus t-impulse-plus nrf52840
LilyGo T3-C6 tlora-c6 esp32-c6
Seeed SenseCAP T1000-E tracker-t1000-e nrf52840

Build artifacts expire on 2026-08-26. Updated for f5f0259.

@RCGV1 RCGV1 changed the title fix: keep telemetry on channel encryption by default fix: keep LocalStats on channel encryption by default Jul 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant