Repository navigation
feat: Add AMT Local Time Synchronization Support - #2912
sinchubhat wants to merge 1 commit into
Conversation
be5c7b7 to
e67c62b
Compare
e67c62b to
7726a14
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Bump the dependency for EnableLocalTimeSync and add coverage for failed AMT responses.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (2)
What changed in this PR
Adds LMS-aware AMT local time synchronization while preserving the legacy fallback flow. The dependency update and failure-path test remain required before approval.
Changes:
- Uses
EnableLocalTimeSyncwhen LMS is available. - Propagates
lmsAvailablethrough maintenance events. - Adds LMS synchronization success and retry coverage.
| File | Summary |
|---|---|
src/stateMachines/maintenance/syncTime.ts |
Adds LMS synchronization flow. |
src/stateMachines/maintenance/syncTime.test.ts |
Tests LMS success and retry behavior. |
src/models/RCS.Config.ts |
Adds the LMS availability payload field. |
src/DataProcessor.ts |
Propagates LMS availability. |
src/dataProcessor.test.ts |
Verifies event propagation. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
7726a14 to
bbfb3d6
Compare
|
Nice work on this, One change before it lands: please read lmsInstalled instead of lmsAvailable. rpc-go already sends lmsInstalled in every payload (via utils.DetectLMS, the same TCP probe), so we're closing rpc-go#1560. // RCS.Config.ts
lmsInstalled?: boolean
// DataProcessor.ts
mEvent = { type: SyncTimeEventType, clientId, lmsAvailable: payload.lmsInstalled === true }rpc-go omits the field when LMS is absent, and older rpc-go builds never send it. In both cases this falls back to the legacy flow, which is what we want. The event and state-machine naming can stay as is. Please update the dataProcessor.test.ts fixture to send lmsInstalled as well |
Hi, @rsdmike thank you so much for reviewing the PRs, I have updated the PRs:
|
|
@sinchubhat Validated the PR on AMT21 with and without LMS. user@localhost:~/rpc-go$ sudo ./rpc configure sync-clock -u wss:///activate --password <AMT_Password> --log-level=debug -n time="2026-09-25T06:47:07Z" level=info msg="TLS is enforced on local ports" time="2026-09-25T06:47:07Z" level=warning msg=------------------------------------------------------------------- time="2026-09-25T06:47:07Z" level=warning msg="SECURITY WARNING: Credentials passed via CLI flags (--password)" time="2026-09-25T06:47:07Z" level=warning msg="These are visible in process listings and may be captured in system logs." time="2026-09-25T06:47:07Z" level=warning msg="Use environment variables instead:" time="2026-09-25T06:47:07Z" level=warning msg=" AMT_PASSWORD=" time="2026-09-25T06:47:07Z" level=warning msg=------------------------------------------------------------------- time="2026-09-25T06:47:07Z" level=info msg="Using configuration file: config.yaml (flag values may originate from this file)" time="2026-09-25T06:47:07Z" level=debug msg="sending lmsInstalled=true in initial payload to RPS" time="2026-09-25T06:47:07Z" level=debug msg="connecting to lms (tls port, plain tcp; RPS handles TLS)..." time="2026-09-25T06:47:07Z" level=debug msg="connected to lms" time="2026-09-25T06:47:07Z" level=debug msg="closing connection to lms" time="2026-09-25T06:47:07Z" level=info msg="connecting to wss:///activate" time="2026-09-25T06:47:07Z" level=info msg="wss:///activate" time="2026-09-25T06:47:07Z" level=info msg="connected to wss:///activate" time="2026-09-25T06:47:07Z" level=debug msg="listening to RPS..." time="2026-09-25T06:47:07Z" level=debug msg="sending activation request to RPS" time="2026-09-25T06:47:07Z" level=debug msg="sending message to RPS" time="2026-09-25T06:47:07Z" level=debug msg="received message from RPS" time="2026-09-25T06:47:07Z" level=debug msg=" <- Method: tls_data, Status: ok" time="2026-09-25T06:47:07Z" level=debug msg="TLS tunnel: passing through 1532 bytes to LMS" time="2026-09-25T06:47:07Z" level=debug msg="RPS sent activation data, processing..." time="2026-09-25T06:47:07Z" level=debug msg="connecting to lms (tls port, plain tcp; RPS handles TLS)..." time="2026-09-25T06:47:07Z" level=debug msg="connected to lms" time="2026-09-25T06:47:07Z" level=debug msg="sending message to LMS" time="2026-09-25T06:47:07Z" level=debug msg="sent message to LMS" time="2026-09-25T06:47:07Z" level=debug msg="listening for lms messages..." time="2026-09-25T06:47:09Z" level=debug msg="Received response from LME/LMS, forwarding to RPS" time="2026-09-25T06:47:09Z" level=debug msg="sending message to RPS" time="2026-09-25T06:47:09Z" level=debug msg="Response sent to RPS, waiting for next RPS message" time="2026-09-25T06:47:24Z" level=debug msg="received message from RPS" time="2026-09-25T06:47:24Z" level=debug msg=" <- Method: tls_data, Status: ok" time="2026-09-25T06:47:24Z" level=debug msg="TLS tunnel: passing through 1532 bytes to LMS" time="2026-09-25T06:47:24Z" level=debug msg="TLS ClientHello detected, closing existing connection for new handshake" time="2026-09-25T06:47:24Z" level=debug msg="closing connection to lms" time="2026-09-25T06:47:24Z" level=debug msg="RPS sent activation data, processing..." time="2026-09-25T06:47:24Z" level=debug msg="connecting to lms (tls port, plain tcp; RPS handles TLS)..." time="2026-09-25T06:47:24Z" level=debug msg="connected to lms" time="2026-09-25T06:47:24Z" level=debug msg="sending message to LMS" time="2026-09-25T06:47:24Z" level=debug msg="sent message to LMS" time="2026-09-25T06:47:24Z" level=debug msg="listening for lms messages..." time="2026-09-25T06:47:26Z" level=debug msg="Received response from LME/LMS, forwarding to RPS" time="2026-09-25T06:47:26Z" level=debug msg="sending message to RPS" time="2026-09-25T06:47:26Z" level=debug msg="Response sent to RPS, waiting for next RPS message" time="2026-09-25T06:47:41Z" level=debug msg="received message from RPS" time="2026-09-25T06:47:41Z" level=debug msg=" <- Method: tls_data, Status: ok" time="2026-09-25T06:47:41Z" level=debug msg="TLS tunnel: passing through 1532 bytes to LMS" time="2026-09-25T06:47:41Z" level=debug msg="TLS ClientHello detected, closing existing connection for new handshake" time="2026-09-25T06:47:41Z" level=debug msg="closing connection to lms" time="2026-09-25T06:47:41Z" level=debug msg="RPS sent activation data, processing..." time="2026-09-25T06:47:41Z" level=debug msg="connecting to lms (tls port, plain tcp; RPS handles TLS)..." time="2026-09-25T06:47:41Z" level=debug msg="connected to lms" time="2026-09-25T06:47:41Z" level=debug msg="sending message to LMS" time="2026-09-25T06:47:41Z" level=debug msg="sent message to LMS" time="2026-09-25T06:47:41Z" level=debug msg="listening for lms messages..." time="2026-09-25T06:47:44Z" level=debug msg="Received response from LME/LMS, forwarding to RPS" time="2026-09-25T06:47:44Z" level=debug msg="sending message to RPS" time="2026-09-25T06:47:44Z" level=debug msg="Response sent to RPS, waiting for next RPS message" time="2026-09-25T06:47:44Z" level=debug msg="received message from RPS" time="2026-09-25T06:47:44Z" level=debug msg=" <- Method: error, Status: failed" time="2026-09-25T06:47:44Z" level=error msg="synctime failed TLSTunnelError: chain does not terminate at any trusted ODCA root (1 root(s) checked, top subject=CN=AMT-localhost C=None ST=None O=None) Unknown error has occured" time="2026-09-25T06:47:44Z" level=debug msg="closing connection to lms" time="2026-09-25T06:47:44Z" level=error msg="rps returned error: synctime failed TLSTunnelError: chain does not terminate at any trusted ODCA root (1 root(s) checked, top subject=CN=AMT-localhost C=None ST=None O=None) Unknown error has occured" |
Thanks a lot @punam20 for testing the PRs: Current temporary workaround is: in .env add below Then recreate RPS: docker compose up -d --force-recreate rps
docker compose logs -f --tail=100 rpsLogs with workaround: |
rsdmike
left a comment
There was a problem hiding this comment.
Looks good, just squash your changes please. thanks!
89d9b4a to
8705aad
Compare
Addressed. Squashed the commits too. Thanks.
|
Nice work adding Time sync during activation is the primary path (it runs automatically for every device), and that flow is untouched by this PR:
This PR only updates Can we extend this fix to |
72aafe0 to
12fc90b
Compare
48f41ab to
92bf353
Compare
LMS available: Remote RPS uses EnableLocalTimeSync; local sync uses the legacy GetLowAccuracyTimeSynch/SetHighAccuracyTimeSynch flow. LMS unavailable: Remote RPS and local sync fall back to the legacy GetLowAccuracyTimeSynch/SetHighAccuracyTimeSynch flow via LME. Addresses #2905
92bf353 to
3a3b223
Compare
Able to do the below now: 0 is default-enabled, 1 is explicitly enabled, and 2 is disabled. Reactivation and remote sync-clock both changed 2 -> 1; deactivation reset it to 0. LMS is active and running
|
|
Activation sends EnableLocalTimeSync(true) when LMS is installed, so even a device whose setting is explicitly disabled (2) has local synchronization re-enabled. The call grants permission; LMS decides when to write the clock. LMS’s decision is primarily based on LocalTimeSyncEnabled and the clock offset, not TimeSource.
Intel LMS does contain an automatic clock-sync service. In the upstream LMS implementation, it:
https://github.com/Ylianst/MeshCommander/blob/master/index.html#L5441-L5455 https://software.intel.com/sites/manageability/AMT_Implementation_and_Reference_Guide/default.htm?turl=WordDocuments%2Fgettimesource.htm |


Addresses #2905
Companion PR:
device-management-toolkit/wsman-messages#1397
#2922
device-management-toolkit/rpc-go#1562
PR Checklist
What are you changing?
Anything the reviewer should know when reviewing this PR?
If the there are associated PRs in other repositories, please link them here (i.e. device-management-toolkit/repo#365 )