diff --git a/v2/crates/homecore-server/src/hap.rs b/v2/crates/homecore-server/src/hap.rs index 61df950e..9da6217c 100644 --- a/v2/crates/homecore-server/src/hap.rs +++ b/v2/crates/homecore-server/src/hap.rs @@ -11,6 +11,7 @@ use homecore::HomeCore; pub(crate) struct HapRuntimeConfig { pub bind_addr: Option, pub device_id: Option, + pub setup_code: Option, pub advertise_addr: Option, pub hostname: String, pub instance_name: String, @@ -84,7 +85,24 @@ pub(crate) async fn start(hc: &HomeCore, config: HapRuntimeConfig) -> Result, + /// HAP setup code in `XXX-XX-XXX` form. Required only when creating a + /// pairing store for the first time and never persisted in plaintext. + #[arg(long, env = "HOMECORE_HAP_SETUP_CODE", hide_env_values = true)] + hap_setup_code: Option, + /// LAN address published in the HAP mDNS record. Required when HAP is enabled. #[arg(long, env = "HOMECORE_HAP_ADVERTISE_ADDR")] hap_advertise_addr: Option, @@ -177,7 +182,7 @@ struct Cli { #[tokio::main] async fn main() -> Result<()> { init_tracing(); - let cli = Cli::parse(); + let mut cli = Cli::parse(); let has_tokens = std::env::var("HOMECORE_TOKENS") .map(|value| !value.trim().is_empty()) .unwrap_or(false); @@ -325,6 +330,7 @@ async fn main() -> Result<()> { hap::HapRuntimeConfig { bind_addr: cli.hap_bind, device_id: cli.hap_device_id.clone(), + setup_code: cli.hap_setup_code.take(), advertise_addr: cli.hap_advertise_addr, hostname: cli.hap_hostname.clone(), instance_name: cli.hap_instance_name.clone(), diff --git a/v2/docs/homecore-capabilities.md b/v2/docs/homecore-capabilities.md index 84abde27..cd19d524 100644 --- a/v2/docs/homecore-capabilities.md +++ b/v2/docs/homecore-capabilities.md @@ -68,11 +68,12 @@ registry currently returns a valid empty list. native plugins must be linked into the binary and registered in code. - HAP is disabled by default. Enabling it requires an explicit bind address, stable six-octet device identifier, advertised LAN address, hostname, and - durable pairing-store path. -- The HAP listener fails closed for cryptographic phases that are unavailable - in the selected build. Do not claim Apple Home interoperability unless the - Pair-Setup, Pair-Verify, and encrypted transport conformance tests for that - build pass. + durable pairing-store path. First provisioning also requires an explicit + non-trivial `XXX-XX-XXX` setup code; only its SRP verifier is persisted. +- The HAP listener implements SRP-6a Pair-Setup, X25519/Ed25519 Pair-Verify, + ChaCha20-Poly1305 HAP IP records, controller administration, and paired-state + mDNS updates. Internal protocol/tamper/replay tests pass; external Apple Home + certification is not claimed. - STT and TTS are provider contracts; a deployment must supply real providers. The built-in disabled providers return typed errors rather than fabricated speech results.