Skip to content

feat: Add AMT Local Time Synchronization Support - #2912

Open
sinchubhat wants to merge 1 commit into
mainfrom
issue2905-rps
Open

sinchubhat wants to merge 1 commit into
mainfrom
issue2905-rps

Conversation

@sinchubhat

@sinchubhat sinchubhat commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor
  • LMS available: Remote RPS uses EnableLocalTimeSync; local sync uses the legacy GetLowAccuracyTimeSynch/SetHighAccuracyTimeSynch flow.
  • LMS unavailable: Both remote RPS and local sync fall back to the legacy GetLowAccuracyTimeSynch/SetHighAccuracyTimeSynch flow via LME.

Addresses #2905

Companion PR:
device-management-toolkit/wsman-messages#1397
#2922
device-management-toolkit/rpc-go#1562

PR Checklist

  • Unit Tests have been added for new changes
  • API tests have been updated if applicable
  • All commented code has been removed
  • If you've added a dependency, you've ensured license is compatible with Apache 2.0 and clearly outlined the added dependency.

What are you changing?

Anything the reviewer should know when reviewing this PR?

If the there are associated PRs in other repositories, please link them here (i.e. device-management-toolkit/repo#365 )

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Bump the dependency for EnableLocalTimeSync and add coverage for failed AMT responses.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 High severity · 1 Low severity

Open (2)
What changed in this PR

Adds LMS-aware AMT local time synchronization while preserving the legacy fallback flow. The dependency update and failure-path test remain required before approval.

Changes:

  • Uses EnableLocalTimeSync when LMS is available.
  • Propagates lmsAvailable through maintenance events.
  • Adds LMS synchronization success and retry coverage.
File Summary
src/​stateMachines/​maintenance/​syncTime.ts Adds LMS synchronization flow.
src/​stateMachines/​maintenance/​syncTime.test.ts Tests LMS success and retry behavior.
src/​models/​RCS.Config.ts Adds the LMS availability payload field.
src/​DataProcessor.ts Propagates LMS availability.
src/​dataProcessor.test.ts Verifies event propagation.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/stateMachines/maintenance/syncTime.ts
Comment thread src/stateMachines/maintenance/syncTime.ts
@rsdmike

rsdmike commented Sep 23, 2026

Copy link
Copy Markdown
Member

Nice work on this, One change before it lands: please read lmsInstalled instead of lmsAvailable. rpc-go already sends lmsInstalled in every payload (via utils.DetectLMS, the same TCP probe), so we're closing rpc-go#1560.

// RCS.Config.ts
lmsInstalled?: boolean

// DataProcessor.ts
mEvent = { type: SyncTimeEventType, clientId, lmsAvailable: payload.lmsInstalled === true }

rpc-go omits the field when LMS is absent, and older rpc-go builds never send it. In both cases this falls back to the legacy flow, which is what we want. The event and state-machine naming can stay as is.

Please update the dataProcessor.test.ts fixture to send lmsInstalled as well

@rsdmike rsdmike left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

see comment

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No blocking issues were identified; only a minor test-coverage nit remains.

Review effort: Lite
Findings: None

Resolved since last review (2)

@sinchubhat
sinchubhat marked this pull request as ready for review September 24, 2026 05:11
@sinchubhat

Copy link
Copy Markdown
Contributor Author

Nice work on this, One change before it lands: please read lmsInstalled instead of lmsAvailable. rpc-go already sends lmsInstalled in every payload (via utils.DetectLMS, the same TCP probe), so we're closing rpc-go#1560.

// RCS.Config.ts
lmsInstalled?: boolean

// DataProcessor.ts
mEvent = { type: SyncTimeEventType, clientId, lmsAvailable: payload.lmsInstalled === true }

rpc-go omits the field when LMS is absent, and older rpc-go builds never send it. In both cases this falls back to the legacy flow, which is what we want. The event and state-machine naming can stay as is.

Please update the dataProcessor.test.ts fixture to send lmsInstalled as well

Hi, @rsdmike thank you so much for reviewing the PRs, I have updated the PRs:

@punam20

punam20 commented Sep 25, 2026

Copy link
Copy Markdown

@sinchubhat Validated the PR on AMT21 with and without LMS.
Issue observed :

user@localhost:~/rpc-go$ sudo ./rpc configure sync-clock -u wss:///activate --password <AMT_Password> --log-level=debug -n

time="2026-09-25T06:47:07Z" level=info msg="TLS is enforced on local ports"

time="2026-09-25T06:47:07Z" level=warning msg=-------------------------------------------------------------------

time="2026-09-25T06:47:07Z" level=warning msg="SECURITY WARNING: Credentials passed via CLI flags (--password)"

time="2026-09-25T06:47:07Z" level=warning msg="These are visible in process listings and may be captured in system logs."

time="2026-09-25T06:47:07Z" level=warning msg="Use environment variables instead:"

time="2026-09-25T06:47:07Z" level=warning msg=" AMT_PASSWORD="

time="2026-09-25T06:47:07Z" level=warning msg=-------------------------------------------------------------------

time="2026-09-25T06:47:07Z" level=info msg="Using configuration file: config.yaml (flag values may originate from this file)"

time="2026-09-25T06:47:07Z" level=debug msg="sending lmsInstalled=true in initial payload to RPS"

time="2026-09-25T06:47:07Z" level=debug msg="connecting to lms (tls port, plain tcp; RPS handles TLS)..."

time="2026-09-25T06:47:07Z" level=debug msg="connected to lms"

time="2026-09-25T06:47:07Z" level=debug msg="closing connection to lms"

time="2026-09-25T06:47:07Z" level=info msg="connecting to wss:///activate"

time="2026-09-25T06:47:07Z" level=info msg="wss:///activate"

time="2026-09-25T06:47:07Z" level=info msg="connected to wss:///activate"

time="2026-09-25T06:47:07Z" level=debug msg="listening to RPS..."

time="2026-09-25T06:47:07Z" level=debug msg="sending activation request to RPS"

time="2026-09-25T06:47:07Z" level=debug msg="sending message to RPS"

time="2026-09-25T06:47:07Z" level=debug msg="received message from RPS"

time="2026-09-25T06:47:07Z" level=debug msg=" <- Method: tls_data, Status: ok"

time="2026-09-25T06:47:07Z" level=debug msg="TLS tunnel: passing through 1532 bytes to LMS"

time="2026-09-25T06:47:07Z" level=debug msg="RPS sent activation data, processing..."

time="2026-09-25T06:47:07Z" level=debug msg="connecting to lms (tls port, plain tcp; RPS handles TLS)..."

time="2026-09-25T06:47:07Z" level=debug msg="connected to lms"

time="2026-09-25T06:47:07Z" level=debug msg="sending message to LMS"

time="2026-09-25T06:47:07Z" level=debug msg="sent message to LMS"

time="2026-09-25T06:47:07Z" level=debug msg="listening for lms messages..."

time="2026-09-25T06:47:09Z" level=debug msg="Received response from LME/LMS, forwarding to RPS"

time="2026-09-25T06:47:09Z" level=debug msg="sending message to RPS"

time="2026-09-25T06:47:09Z" level=debug msg="Response sent to RPS, waiting for next RPS message"

time="2026-09-25T06:47:24Z" level=debug msg="received message from RPS"

time="2026-09-25T06:47:24Z" level=debug msg=" <- Method: tls_data, Status: ok"

time="2026-09-25T06:47:24Z" level=debug msg="TLS tunnel: passing through 1532 bytes to LMS"

time="2026-09-25T06:47:24Z" level=debug msg="TLS ClientHello detected, closing existing connection for new handshake"

time="2026-09-25T06:47:24Z" level=debug msg="closing connection to lms"

time="2026-09-25T06:47:24Z" level=debug msg="RPS sent activation data, processing..."

time="2026-09-25T06:47:24Z" level=debug msg="connecting to lms (tls port, plain tcp; RPS handles TLS)..."

time="2026-09-25T06:47:24Z" level=debug msg="connected to lms"

time="2026-09-25T06:47:24Z" level=debug msg="sending message to LMS"

time="2026-09-25T06:47:24Z" level=debug msg="sent message to LMS"

time="2026-09-25T06:47:24Z" level=debug msg="listening for lms messages..."

time="2026-09-25T06:47:26Z" level=debug msg="Received response from LME/LMS, forwarding to RPS"

time="2026-09-25T06:47:26Z" level=debug msg="sending message to RPS"

time="2026-09-25T06:47:26Z" level=debug msg="Response sent to RPS, waiting for next RPS message"

time="2026-09-25T06:47:41Z" level=debug msg="received message from RPS"

time="2026-09-25T06:47:41Z" level=debug msg=" <- Method: tls_data, Status: ok"

time="2026-09-25T06:47:41Z" level=debug msg="TLS tunnel: passing through 1532 bytes to LMS"

time="2026-09-25T06:47:41Z" level=debug msg="TLS ClientHello detected, closing existing connection for new handshake"

time="2026-09-25T06:47:41Z" level=debug msg="closing connection to lms"

time="2026-09-25T06:47:41Z" level=debug msg="RPS sent activation data, processing..."

time="2026-09-25T06:47:41Z" level=debug msg="connecting to lms (tls port, plain tcp; RPS handles TLS)..."

time="2026-09-25T06:47:41Z" level=debug msg="connected to lms"

time="2026-09-25T06:47:41Z" level=debug msg="sending message to LMS"

time="2026-09-25T06:47:41Z" level=debug msg="sent message to LMS"

time="2026-09-25T06:47:41Z" level=debug msg="listening for lms messages..."

time="2026-09-25T06:47:44Z" level=debug msg="Received response from LME/LMS, forwarding to RPS"

time="2026-09-25T06:47:44Z" level=debug msg="sending message to RPS"

time="2026-09-25T06:47:44Z" level=debug msg="Response sent to RPS, waiting for next RPS message"

time="2026-09-25T06:47:44Z" level=debug msg="received message from RPS"

time="2026-09-25T06:47:44Z" level=debug msg=" <- Method: error, Status: failed"

time="2026-09-25T06:47:44Z" level=error msg="synctime failed TLSTunnelError: chain does not terminate at any trusted ODCA root (1 root(s) checked, top subject=CN=AMT-localhost C=None ST=None O=None) Unknown error has occured"

time="2026-09-25T06:47:44Z" level=debug msg="closing connection to lms"

time="2026-09-25T06:47:44Z" level=error msg="rps returned error: synctime failed TLSTunnelError: chain does not terminate at any trusted ODCA root (1 root(s) checked, top subject=CN=AMT-localhost C=None ST=None O=None) Unknown error has occured"

@sinchubhat

Copy link
Copy Markdown
Contributor Author

@sinchubhat Validated the PR on AMT21 with and without LMS. Issue observed :

user@localhost:~/rpc-go$ sudo ./rpc configure sync-clock -u wss:///activate --password <AMT_Password> --log-level=debug -n

time="2026-09-25T06:47:07Z" level=info msg="TLS is enforced on local ports"

time="2026-09-25T06:47:07Z" level=warning msg=-------------------------------------------------------------------

time="2026-09-25T06:47:07Z" level=warning msg="SECURITY WARNING: Credentials passed via CLI flags (--password)"

time="2026-09-25T06:47:07Z" level=warning msg="These are visible in process listings and may be captured in system logs."

time="2026-09-25T06:47:07Z" level=warning msg="Use environment variables instead:"

time="2026-09-25T06:47:07Z" level=warning msg=" AMT_PASSWORD="

time="2026-09-25T06:47:07Z" level=warning msg=-------------------------------------------------------------------

time="2026-09-25T06:47:07Z" level=info msg="Using configuration file: config.yaml (flag values may originate from this file)"

time="2026-09-25T06:47:07Z" level=debug msg="sending lmsInstalled=true in initial payload to RPS"

time="2026-09-25T06:47:07Z" level=debug msg="connecting to lms (tls port, plain tcp; RPS handles TLS)..."

time="2026-09-25T06:47:07Z" level=debug msg="connected to lms"

time="2026-09-25T06:47:07Z" level=debug msg="closing connection to lms"

time="2026-09-25T06:47:07Z" level=info msg="connecting to wss:///activate"

time="2026-09-25T06:47:07Z" level=info msg="wss:///activate"

time="2026-09-25T06:47:07Z" level=info msg="connected to wss:///activate"

time="2026-09-25T06:47:07Z" level=debug msg="listening to RPS..."

time="2026-09-25T06:47:07Z" level=debug msg="sending activation request to RPS"

time="2026-09-25T06:47:07Z" level=debug msg="sending message to RPS"

time="2026-09-25T06:47:07Z" level=debug msg="received message from RPS"

time="2026-09-25T06:47:07Z" level=debug msg=" <- Method: tls_data, Status: ok"

time="2026-09-25T06:47:07Z" level=debug msg="TLS tunnel: passing through 1532 bytes to LMS"

time="2026-09-25T06:47:07Z" level=debug msg="RPS sent activation data, processing..."

time="2026-09-25T06:47:07Z" level=debug msg="connecting to lms (tls port, plain tcp; RPS handles TLS)..."

time="2026-09-25T06:47:07Z" level=debug msg="connected to lms"

time="2026-09-25T06:47:07Z" level=debug msg="sending message to LMS"

time="2026-09-25T06:47:07Z" level=debug msg="sent message to LMS"

time="2026-09-25T06:47:07Z" level=debug msg="listening for lms messages..."

time="2026-09-25T06:47:09Z" level=debug msg="Received response from LME/LMS, forwarding to RPS"

time="2026-09-25T06:47:09Z" level=debug msg="sending message to RPS"

time="2026-09-25T06:47:09Z" level=debug msg="Response sent to RPS, waiting for next RPS message"

time="2026-09-25T06:47:24Z" level=debug msg="received message from RPS"

time="2026-09-25T06:47:24Z" level=debug msg=" <- Method: tls_data, Status: ok"

time="2026-09-25T06:47:24Z" level=debug msg="TLS tunnel: passing through 1532 bytes to LMS"

time="2026-09-25T06:47:24Z" level=debug msg="TLS ClientHello detected, closing existing connection for new handshake"

time="2026-09-25T06:47:24Z" level=debug msg="closing connection to lms"

time="2026-09-25T06:47:24Z" level=debug msg="RPS sent activation data, processing..."

time="2026-09-25T06:47:24Z" level=debug msg="connecting to lms (tls port, plain tcp; RPS handles TLS)..."

time="2026-09-25T06:47:24Z" level=debug msg="connected to lms"

time="2026-09-25T06:47:24Z" level=debug msg="sending message to LMS"

time="2026-09-25T06:47:24Z" level=debug msg="sent message to LMS"

time="2026-09-25T06:47:24Z" level=debug msg="listening for lms messages..."

time="2026-09-25T06:47:26Z" level=debug msg="Received response from LME/LMS, forwarding to RPS"

time="2026-09-25T06:47:26Z" level=debug msg="sending message to RPS"

time="2026-09-25T06:47:26Z" level=debug msg="Response sent to RPS, waiting for next RPS message"

time="2026-09-25T06:47:41Z" level=debug msg="received message from RPS"

time="2026-09-25T06:47:41Z" level=debug msg=" <- Method: tls_data, Status: ok"

time="2026-09-25T06:47:41Z" level=debug msg="TLS tunnel: passing through 1532 bytes to LMS"

time="2026-09-25T06:47:41Z" level=debug msg="TLS ClientHello detected, closing existing connection for new handshake"

time="2026-09-25T06:47:41Z" level=debug msg="closing connection to lms"

time="2026-09-25T06:47:41Z" level=debug msg="RPS sent activation data, processing..."

time="2026-09-25T06:47:41Z" level=debug msg="connecting to lms (tls port, plain tcp; RPS handles TLS)..."

time="2026-09-25T06:47:41Z" level=debug msg="connected to lms"

time="2026-09-25T06:47:41Z" level=debug msg="sending message to LMS"

time="2026-09-25T06:47:41Z" level=debug msg="sent message to LMS"

time="2026-09-25T06:47:41Z" level=debug msg="listening for lms messages..."

time="2026-09-25T06:47:44Z" level=debug msg="Received response from LME/LMS, forwarding to RPS"

time="2026-09-25T06:47:44Z" level=debug msg="sending message to RPS"

time="2026-09-25T06:47:44Z" level=debug msg="Response sent to RPS, waiting for next RPS message"

time="2026-09-25T06:47:44Z" level=debug msg="received message from RPS"

time="2026-09-25T06:47:44Z" level=debug msg=" <- Method: error, Status: failed"

time="2026-09-25T06:47:44Z" level=error msg="synctime failed TLSTunnelError: chain does not terminate at any trusted ODCA root (1 root(s) checked, top subject=CN=AMT-localhost C=None ST=None O=None) Unknown error has occured"

time="2026-09-25T06:47:44Z" level=debug msg="closing connection to lms"

time="2026-09-25T06:47:44Z" level=error msg="rps returned error: synctime failed TLSTunnelError: chain does not terminate at any trusted ODCA root (1 root(s) checked, top subject=CN=AMT-localhost C=None ST=None O=None) Unknown error has occured"

Thanks a lot @punam20 for testing the PRs:
I have created a new issue for this device-management-toolkit/rpc-go#1575 as the issue is w.r.t tls tunnel and not with the code from this PR

Current temporary workaround is:

in .env add below

RPS_LOG_LEVEL=debug
RPS_AMT_POST_TLS_REJECT=false

Then recreate RPS:

docker compose up -d --force-recreate rps
docker compose logs -f --tail=100 rps

Logs with workaround:

sudo ./rpc configure sync-clock -u wss://<host_ip_addr>/activate -n --skip-amt-cert-check --password '<AMT_Password>'  --log-level=debug
time="2026-09-25T07:32:31Z" level=info msg="TLS is enforced on local ports"
time="2026-09-25T07:32:31Z" level=warning msg=-------------------------------------------------------------------
time="2026-09-25T07:32:31Z" level=warning msg="SECURITY WARNING: Credentials passed via CLI flags (--password)"
time="2026-09-25T07:32:31Z" level=warning msg="These are visible in process listings and may be captured in system logs."
time="2026-09-25T07:32:31Z" level=warning msg="Use environment variables instead:"
time="2026-09-25T07:32:31Z" level=warning msg="  AMT_PASSWORD=<value>"
time="2026-09-25T07:32:31Z" level=warning msg=-------------------------------------------------------------------
time="2026-09-25T07:32:31Z" level=debug msg="sending lmsInstalled=true in initial payload to RPS"
time="2026-09-25T07:32:31Z" level=debug msg="connecting to lms (tls port, plain tcp; RPS handles TLS)..."
time="2026-09-25T07:32:31Z" level=debug msg="connected to lms"
time="2026-09-25T07:32:31Z" level=debug msg="closing connection to lms"
time="2026-09-25T07:32:31Z" level=info msg="connecting to wss://<host_ip_addr>/activate"
time="2026-09-25T07:32:31Z" level=info msg="wss://<host_ip_addr>/activate"
time="2026-09-25T07:32:31Z" level=info msg="connected to wss://<host_ip_addr>/activate"
time="2026-09-25T07:32:31Z" level=debug msg="listening to RPS..."
time="2026-09-25T07:32:31Z" level=debug msg="sending activation request to RPS"
time="2026-09-25T07:32:31Z" level=debug msg="sending message to RPS"
time="2026-09-25T07:32:31Z" level=debug msg="received message from RPS"
time="2026-09-25T07:32:31Z" level=debug msg="  <- Method: tls_data, Status: ok"
time="2026-09-25T07:32:31Z" level=debug msg="TLS tunnel: passing through 1532 bytes to LMS"
time="2026-09-25T07:32:31Z" level=debug msg="RPS sent activation data, processing..."
time="2026-09-25T07:32:31Z" level=debug msg="connecting to lms (tls port, plain tcp; RPS handles TLS)..."
time="2026-09-25T07:32:31Z" level=debug msg="connected to lms"
time="2026-09-25T07:32:31Z" level=debug msg="sending message to LMS"
time="2026-09-25T07:32:31Z" level=debug msg="sent message to LMS"
time="2026-09-25T07:32:31Z" level=debug msg="listening for lms messages..."
time="2026-09-25T07:32:33Z" level=debug msg="Received response from LME/LMS, forwarding to RPS"
time="2026-09-25T07:32:34Z" level=debug msg="sending message to RPS"
time="2026-09-25T07:32:34Z" level=debug msg="Response sent to RPS, waiting for next RPS message"
time="2026-09-25T07:32:34Z" level=debug msg="received message from RPS"
time="2026-09-25T07:32:34Z" level=debug msg="  <- Method: tls_data, Status: ok"
time="2026-09-25T07:32:34Z" level=debug msg="TLS tunnel: passing through 80 bytes to LMS"
time="2026-09-25T07:32:34Z" level=debug msg="RPS sent activation data, processing..."
time="2026-09-25T07:32:34Z" level=debug msg="sending message to LMS"
time="2026-09-25T07:32:34Z" level=debug msg="sent message to LMS"
time="2026-09-25T07:32:34Z" level=debug msg="listening for lms messages..."
time="2026-09-25T07:32:36Z" level=debug msg="received message from RPS"
time="2026-09-25T07:32:36Z" level=debug msg="  <- Method: tls_data, Status: ok"
time="2026-09-25T07:32:36Z" level=debug msg="TLS tunnel: passing through 1076 bytes to LMS"
time="2026-09-25T07:32:36Z" level=debug msg="RPS sent activation data, processing..."
time="2026-09-25T07:32:36Z" level=debug msg="sending message to LMS"
time="2026-09-25T07:32:36Z" level=debug msg="sent message to LMS"
time="2026-09-25T07:32:36Z" level=debug msg="listening for lms messages..."
time="2026-09-25T07:32:36Z" level=debug msg="Received response from LME/LMS, forwarding to RPS"
time="2026-09-25T07:32:36Z" level=debug msg="sending message to RPS"
time="2026-09-25T07:32:36Z" level=debug msg="Response sent to RPS, waiting for next RPS message"
time="2026-09-25T07:32:36Z" level=debug msg="received message from RPS"
time="2026-09-25T07:32:36Z" level=debug msg="  <- Method: tls_data, Status: ok"
time="2026-09-25T07:32:36Z" level=debug msg="TLS tunnel: passing through 1532 bytes to LMS"
time="2026-09-25T07:32:36Z" level=debug msg="TLS ClientHello detected, closing existing connection for new handshake"
time="2026-09-25T07:32:36Z" level=debug msg="closing connection to lms"
time="2026-09-25T07:32:36Z" level=debug msg="RPS sent activation data, processing..."
time="2026-09-25T07:32:36Z" level=debug msg="connecting to lms (tls port, plain tcp; RPS handles TLS)..."
time="2026-09-25T07:32:36Z" level=debug msg="connected to lms"
time="2026-09-25T07:32:36Z" level=debug msg="sending message to LMS"
time="2026-09-25T07:32:36Z" level=debug msg="sent message to LMS"
time="2026-09-25T07:32:36Z" level=debug msg="listening for lms messages..."
time="2026-09-25T07:32:38Z" level=debug msg="Received response from LME/LMS, forwarding to RPS"
time="2026-09-25T07:32:38Z" level=debug msg="sending message to RPS"
time="2026-09-25T07:32:38Z" level=debug msg="Response sent to RPS, waiting for next RPS message"
time="2026-09-25T07:32:38Z" level=debug msg="received message from RPS"
time="2026-09-25T07:32:38Z" level=debug msg="  <- Method: tls_data, Status: ok"
time="2026-09-25T07:32:38Z" level=debug msg="TLS tunnel: passing through 80 bytes to LMS"
time="2026-09-25T07:32:38Z" level=debug msg="RPS sent activation data, processing..."
time="2026-09-25T07:32:38Z" level=debug msg="sending message to LMS"
time="2026-09-25T07:32:38Z" level=debug msg="sent message to LMS"
time="2026-09-25T07:32:38Z" level=debug msg="listening for lms messages..."
time="2026-09-25T07:32:40Z" level=debug msg="received message from RPS"
time="2026-09-25T07:32:40Z" level=debug msg="  <- Method: tls_data, Status: ok"
time="2026-09-25T07:32:40Z" level=debug msg="TLS tunnel: passing through 1302 bytes to LMS"
time="2026-09-25T07:32:40Z" level=debug msg="RPS sent activation data, processing..."
time="2026-09-25T07:32:40Z" level=debug msg="sending message to LMS"
time="2026-09-25T07:32:40Z" level=debug msg="listening for lms messages..."
time="2026-09-25T07:32:40Z" level=debug msg="sent message to LMS"
time="2026-09-25T07:32:42Z" level=debug msg="Received response from LME/LMS, forwarding to RPS"
time="2026-09-25T07:32:42Z" level=debug msg="sending message to RPS"
time="2026-09-25T07:32:42Z" level=debug msg="Response sent to RPS, waiting for next RPS message"
time="2026-09-25T07:32:42Z" level=debug msg="received message from RPS"
time="2026-09-25T07:32:42Z" level=debug msg="  <- Method: success, Status: success"
time="2026-09-25T07:32:42Z" level=info msg="Status: synctime completed succesfully"
time="2026-09-25T07:32:42Z" level=info msg="Network: "
time="2026-09-25T07:32:42Z" level=info msg="CIRA: "
time="2026-09-25T07:32:42Z" level=info msg="TLS: "
time="2026-09-25T07:32:42Z" level=info msg="RPS sent terminal message (success/error), ending activation flow"
time="2026-09-25T07:32:42Z" level=debug msg="closing connection to lms"

@rsdmike rsdmike left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good, just squash your changes please. thanks!

@sinchubhat
sinchubhat force-pushed the issue2905-rps branch 2 times, most recently from 89d9b4a to 8705aad Compare September 26, 2026 07:26
@sinchubhat
sinchubhat dismissed rsdmike’s stale review September 26, 2026 07:30

Addressed. Squashed the commits too. Thanks.

@graikhel-intel

Copy link
Copy Markdown
Contributor

Nice work adding EnableLocalTimeSync support -- but I think this only covers the secondary path.

Time sync during activation is the primary path (it runs automatically for every device), and that flow is untouched by this PR:

  • activation.ts invokes the tls state machine → tls.ts's SYNC_TIME state
  • That unconditionally does sendTo('time-machine', { type: 'TIMETRAVEL' }), delegating to timeMachine.ts, which still hard-codes the legacy GetLowAccuracyTimeSynch → SetHighAccuracyTimeSynch flow with no lmsInstalled/lmsAvailable check at all

This PR only updates src/stateMachines/maintenance/syncTime.ts, which is reached solely via the on-demand synctime maintenance task (DataProcessor.ts case 'synctime') -- something a user has to trigger manually after activation.

Can we extend this fix to tls.ts / timeMachine.ts as well, so the primary (activation) path is covered too?

@sinchubhat
sinchubhat force-pushed the issue2905-rps branch 2 times, most recently from 72aafe0 to 12fc90b Compare September 30, 2026 05:47
@sinchubhat
sinchubhat force-pushed the issue2905-rps branch 2 times, most recently from 48f41ab to 92bf353 Compare October 5, 2026 03:57
@sinchubhat
sinchubhat requested a lite review from Copilot October 5, 2026 04:03

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved LMS availability mapping, activation failure propagation, and local-sync flow issues remain.

Review effort: Lite
Findings: 1 High severity

Open (1)

Comment thread src/stateMachines/activation.ts Outdated
LMS available: Remote RPS uses EnableLocalTimeSync; local sync uses the
legacy GetLowAccuracyTimeSynch/SetHighAccuracyTimeSynch flow.

LMS unavailable: Remote RPS and local sync fall back to the legacy
GetLowAccuracyTimeSynch/SetHighAccuracyTimeSynch flow via LME.

Addresses #2905
@sinchubhat

Copy link
Copy Markdown
Contributor Author

Nice work adding EnableLocalTimeSync support -- but I think this only covers the secondary path.

Time sync during activation is the primary path (it runs automatically for every device), and that flow is untouched by this PR:

  • activation.ts invokes the tls state machine → tls.ts's SYNC_TIME state
  • That unconditionally does sendTo('time-machine', { type: 'TIMETRAVEL' }), delegating to timeMachine.ts, which still hard-codes the legacy GetLowAccuracyTimeSynch → SetHighAccuracyTimeSynch flow with no lmsInstalled/lmsAvailable check at all

This PR only updates src/stateMachines/maintenance/syncTime.ts, which is reached solely via the on-demand synctime maintenance task (DataProcessor.ts case 'synctime') -- something a user has to trigger manually after activation.

Can we extend this fix to tls.ts / timeMachine.ts as well, so the primary (activation) path is covered too?

Able to do the below now:

0 is default-enabled, 1 is explicitly enabled, and 2 is disabled. Reactivation and remote sync-clock both changed 2 -> 1; deactivation reset it to 0.

LMS is active and running

State LocalTimeSyncEnabled Operation State LocalTimeSyncEnabled
Pre-provisioning state 0 Activate ACM 1
ACM 1 manually disable_local_time_sync ACM 2
ACM 2 Run activation again ACM 1
ACM 1 manually disable_local_time_sync ACM 2
ACM 2 Run configure sync-clock cmd (PR1562 rpc-go) ACM 1
ACM 1 Deactivate Pre-provisioning state 0

@sinchubhat

Copy link
Copy Markdown
Contributor Author

@sudhir-intc @graikhel-intel

Activation sends EnableLocalTimeSync(true) when LMS is installed, so even a device whose setting is explicitly disabled (2) has local synchronization re-enabled. The call grants permission; LMS decides when to write the clock.

LMS’s decision is primarily based on LocalTimeSyncEnabled and the clock offset, not TimeSource.

  • TimeSource is read-only; there is no “set TimeSource to 1” property call.
  • Setting AMT’s clock through GetLowAccuracyTimeSynch -> SetHighAccuracyTimeSynch can make it 1
  • EnableLocalTimeSync(true) changes the permission, not TimeSource.

Intel LMS does contain an automatic clock-sync service. In the upstream LMS implementation, it:
https://github.com/intel/lms/blob/master/UNS/TimeSyncService/TimeSyncService.cpp

  • Accepts LocalTimeSyncEnabled=0(default enabled) or 1(explicitly enabled); skips sync at 2(disabled).
  • Checks AMT time against host UTC at service startup, then every 24 hours in a release build.
  • Calls SetHighAccuracyTimeSynch only when the difference is greater than 30 seconds.

https://github.com/Ylianst/MeshCommander/blob/master/index.html#L5441-L5455
MeshCommander’s “Synchronize Intel AMT clock with this computer” button uses the legacy Get/Set flow, not EnableLocalTimeSync. Its click handler calls GetLowAccuracyTimeSynch, obtains the computer’s Unix time, calls SetHighAccuracyTimeSynch(Ta0, Tm1, Tm1), then reads AMT time again. Merely viewing Date & Time performs a read; clicking Synchronize performs the write. Intel defines TimeSource=1 as AMT time having been set to UTC by configuration software, so the value after that click is expected. It does not identify which software set it.

https://software.intel.com/sites/manageability/AMT_Implementation_and_Reference_Guide/default.htm?turl=WordDocuments%2Fgettimesource.htm
For reference, Intel’s Get Time Source definition says CONFIGURED means the firmware time was set to UTC by UNS or other configuration software. That is why TimeSource=1 alone cannot attribute the write to LMS.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add AMT Local Time Synchronization Support

5 participants