Commissioning Proxy PR2: Add CP Cluster Server and Unit Tests  (#72625)

* CommissioningProxy: add cluster definition and generated code

* CommissioningProxy: add cluster server, delegate and unit tests

* Remove PythonProxyCommissioner, CHI, add CachedResults

* Adds missing CP auto-gen config

* Cluster Delegate Code Review

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* Updates after CP Gemini code review

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* CommissioningProxy: register cluster XML in ZAP codegen config

Add the generated registration for commissioning-proxy-cluster.xml that
was missing from the codegen config:

- zap_cluster_list.json: add COMMISSIONING_PROXY_CLUSTER (empty server
  dir; server entry deferred to the cluster-impl PR)
- tests.yaml: add the XML to the CI "Validate that xml are parsable" list
- commissioning-proxy-cluster.xml: regenerate header with
  attribute=in-progress; Git provenance now clean (no -dirty)

* Rebuild autogen files

* Removes CP active Python code

* [commissioning-proxy] Address PR2 review feedback

- Cluster owns ScanMaxTime/CacheTimeout storage + change reporting (delegate no longer forwards them).
- Command handlers return std::optional to own their async/sync response.
- Move endpoint id to the constructor; rename State_t -> State; default mock ctor/dtor in header.
- Remove dead CHIP_DEVICE_CONFIG_ENABLE_COMMISSIONING_PROXY test define.
- Rename backwards-compat suite -> codegen-integration and run it via src/BUILD.gn.
- Tests: drop 2 duplicate BgScan cases, add ScanMaxTime/CacheTimeout change-reporting tests.

* [commissioning-proxy] Replace delegate with transport-driver interface + subsystems

The cluster now owns all transport-agnostic bookkeeping via three internal
subsystems (SessionManager, ScanCache, ScanAggregator). Physical transport
work is handled by CommissioningProxyTransport driver objects registered via
RegisterTransport(); GetSupportedTransports() ORs all registered drivers.

CommissioningProxyDelegate.h is removed; NotifyAttributeChanged for writable
attributes (ScanMaxTime, CacheTimeout) is now always the cluster's responsibility.

Tests updated to use CommissioningProxyMockTransport (93 cases).

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* [commissioning-proxy] Fix GN include-checker failure in CommissioningProxyScanCache

CommissioningProxyScanCache.cpp included CommissioningProxyCluster.h, which
is intentionally excluded from the commissioning-proxy-server source_set
(compiled in the consumer's context via app_config_dependent_sources.gni).
GN's include-checker rejected it, failing ESP32, Linux, and ARM cross-compile.

Introduce ScanCacheObserver (three pure-virtual callbacks) in
CommissioningProxyScanCache.h. CommissioningProxyCluster inherits it;
the scan cache stores ScanCacheObserver& instead of CommissioningProxyCluster&.

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* [commissioning-proxy] Fix ASAN stack-use-after-scope in TestProxyMessageRequest_DuplicateRequest_Busy

CommissioningProxyCluster did not override Shutdown(). The explicit
cluster.Shutdown() call in tests only cleared mContext; subsystem teardown
only happened in the destructor. C++ destroys tester (which owns
MockCommandHandler) before cluster, so the destructor's mSessions.Shutdown()
→ delete pm → Handle::Release() reached a dead CommandHandler.

Override Shutdown() to clean up subsystems and transports. The destructor
delegates to it as an idempotent safety net (mTransportCount=0 guards the loop).

* [commissioning-proxy] Fix clang-tidy warnings in TestCommissioningProxyCluster

bugprone-argument-comment: argument comment must match the parameter
name exactly — /*maxSessions=*/ → /*aMaxSessions=*/.

bugprone-unchecked-optional-access: clang-tidy's dataflow analysis does
not see through the ASSERT_TRUE macro, so response-> after
ASSERT_TRUE(response.has_value()) is flagged. Replace with
response.value().field which throws bad_optional_access instead of UB
and is not flagged by the checker.

* [commissioning-proxy] Fix bugprone-unchecked-optional-access in tests

clang-tidy's dataflow analysis does not see through ASSERT_TRUE macros,
so response.value() after ASSERT_TRUE(response.has_value()) is still
flagged. Wrap each access in an explicit if (response.has_value()) block,
which creates visible control flow the checker can follow.

* [commissioning-proxy] Add braces to all bare if/for/while bodies

GCC 14.2 on Tizen raises -Werror=dangling-else when a brace-free
if body is a GTest EXPECT_* macro that expands to if/else internally.
Add explicit braces to all single-statement if/else-if/for/while
bodies across commissioning-proxy-server/ (46 sites in 7 files).

Also fix README: remove unverified spec section number, update
argument-comment names to match Config constructor parameters.

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* [commissioning-proxy] Add shared background-scan fabric registry

Extract the transport-agnostic ProxyBackGroundScan bookkeeping (per-fabric
transport/band records, lifetime timers, Start/Stop overlap arithmetic,
paused/deferred state) into CommissioningProxyBgScanRegistry so the BLE and
PAF transports stop duplicating it; transports supply only hardware
start/stop/clear hooks via HardwareControl. Adds 15 unit tests.

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* [commissioning-proxy] Document background-scan registry, fix build layout

Add CommissioningProxyBgScanRegistry to the README's subsystem and
architecture tables, fix the BgScanStart/BgScanStop signatures in the
driver example, and document its API and HardwareControl contract.

The cluster reads no transport build flags, so move
CommissioningProxyCluster.{h,cpp} into the cluster source_set and out of
app_config_dependent_sources.{gni,cmake}, matching chime-server, and
drop the stale comment naming the deleted CommissioningProxyDelegate.h.

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

* Use WritAttribute and remove redundant comment

- WriteAttribute: use DefaultServerCluster::SetAttributeValue for
  ScanMaxTime and CacheTimeout instead of hand-rolling the
  compare/assign/NotifyAttributeChanged pattern. No behaviour change.
- tests/BUILD.gn: drop the historical backwards-compatibility note from
  the tests-codegen-integration comment

* CodeRabbitAI first checnges fix

Add the smaller fixes identified.

* Inject a TimerDelegate so cluster timer paths are testable

The session manager and scan aggregator called SystemLayer directly, so
tests could not drive expiry or exercise a StartTimer failure.

Both now take a chip::TimerDelegate; the aggregator and each pending
message are TimerContexts, and CodegenIntegration supplies the shared
DefaultTimerDelegate, so the cluster ctor gains a third parameter.
Adds CommissioningProxyMockTimer (multi-context with failure injection)
and 3 tests for the rollback paths, each confirmed to fail without them.

* Add new tests to use TimerDelegate

Adds 7 timer unit tests tests for bgscan lifetime expiry and
timer-arm failure, independent per-fabric lifetimes, cache TTL expiry,
rediscovery resetting the TTL, sweep re-arming, and the watchdog ending
a stalled aggregation. Each confirmed to fail against broken code.

* Make a rejected background-scan start leave nothing behind

BgScanRegistry::Start mutated the fabric table before the hardware start
and lifetime timer could fail, so a failed refresh destroyed a working
registration and cancelled its timer. Both fallible steps now run first
and the record is only replaced on success.

ProxyBackGroundScanStartRequest returned the first error while leaving
already-started transports scanning; those are now stopped on failure.

* Make background-scan records per fabric

Spec says "keep per fabric records", recording the sender's NodeID only to
authorise the matching Stop. Keying on the pair grew the table with fabrics
x nodes. The NodeID now sits in the record, Stop rejects a non-owner, and a
start from another node on the same fabric takes ownership.

* Tidy unsued #include and small tweaks

* Trim comments.

* Scan the union of each fabric's background-scan requests

Each node keeps its own request (a Stop is identified by NodeID and FabricID);
the fabric scans their union under one timer at the latest deadline, recomputed
on Stop, capped at 4 requests. Clearing is band-scoped: ClearCachedResults(bands).

* Give the CommissioningProxy cluster bounded, fabric-aware state

Added removed fabric's sessions, connect and background scans. MaxSessions and
MaxCachedResults now come from CHIPConfig.h, sizing the heap-free storage that
replaces std::map and raw new.

* Clear fabric request slot on re-arm failure

Add new tests and update REAME.md

* Fix CommissioningProxy lifecycle and validation gaps from review

Release a background-scan fabric whose lifetime timer cannot be re-armed
so a failed refresh cannot leave its requests scanning unbounded. Reject
reserved Transport bits in ProxyConnectRequest with InvalidCommand, as
the scan commands already does. Cancel the scan cache's sweep timer
from its destructor. Leave the mock transport's unanswered message
pending so the response timer is what resolves it.

* Consolidate CommissioningProxy unit tests

Merge or drop tests that re-asserted a covered path, table the read-only and
min-1 attribute checks, and give the registry tests a fixture. Add a
cross-command reserved-Transport-bit test; note why MaxSessions stays above 1.

* CP: Make MAX_SESSIONS default=1

* Add compile-time bounds on the three CP config macros

* Address PR review feedback on the Commissioning Proxy cluster server

Drop the unused CodegenIntegration Instance wrapper, its test target and the
mock_ember carve-out it needed. Type the transport interface's seconds params
as System::Clock::Seconds16, rename the session lookups, tidy the registry.

* [pre-commit.ci] auto fixes from pre-commit.com hooks

for more information, see https://pre-commit.ci

---------

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
28 files changed
tree: 852b8ad9f307e49e65080d3f83c36e89930f1bfb
  1. .agents/
  2. .claude/
  3. .devcontainer/
  4. .gemini/
  5. .githooks/
  6. .github/
  7. .vscode/
  8. build/
  9. build_overrides/
  10. config/
  11. credentials/
  12. data_model/
  13. docs/
  14. examples/
  15. integrations/
  16. scripts/
  17. src/
  18. third_party/
  19. zzz_generated/
  20. .actrc
  21. .clang-format
  22. .clang-tidy
  23. .default-version.min
  24. .dir-locals.el
  25. .editorconfig
  26. .gitattributes
  27. .gitignore
  28. .gitmodules
  29. .gn
  30. .matterlint
  31. .mergify.yml
  32. .pre-commit-config.yaml
  33. .prettierrc.json
  34. .pullapprove.yml
  35. .restyled.yaml
  36. .shellcheck_tree
  37. .spellcheck.yml
  38. AGENTS.md
  39. BUILD.gn
  40. CODE_OF_CONDUCT.md
  41. CODEOWNERS
  42. CONTRIBUTING.md
  43. GEMINI.md
  44. gn_build.sh
  45. iwyu.imp
  46. kotlin-detect-config.yaml
  47. lgtm.yml
  48. LICENSE
  49. NOTICE
  50. pigweed.json
  51. pyproject.toml
  52. README.md
  53. REVIEWERS.md
  54. SECURITY.md
  55. SPECIFICATION_VERSION
README.md

Documentation links

Matter

Builds

Builds

Android Ameba ASR BouffaloLab Darwin TI CC26X2X7 TI CC32XX EFR32 ESP32 Infineon i.MX Linux NXP FreeRTOS/Zephyr Linux ARM Linux Standalone nRF Connect SDK QPG STM32 Telink Tizen

Tests

Tests-Master Tests-LTS Unit / Integration Tests Cirque QEMU Nightly Run

Tools

ZAP Templates

Documentation

Documentation Build

About

Matter (formerly Project CHIP) creates more connections between more objects, simplifying development for manufacturers and increasing compatibility for consumers, guided by the Connectivity Standards Alliance.

What is Matter?

Matter is a unified, open-source application-layer connectivity standard built to enable developers and device manufacturers to connect and build reliable, and secure ecosystems and increase compatibility among connected home devices. It is built with market-proven technologies using Internet Protocol (IP) and is compatible with Thread and Wi-Fi network transports. Matter was developed by a Working Group within the Connectivity Standards Alliance (Alliance). This Working Group develops and promotes the adoption of the Matter standard, a royalty-free connectivity standard to increase compatibility among smart home products, with security as a fundamental design tenet. The vision that led major industry players to come together to build Matter is that smart connectivity should be simple, reliable, and interoperable.

Matter simplifies development for manufacturers and increases compatibility for consumers.

The standard was built around a shared belief that smart home devices should be secure, reliable, and seamless to use. By building upon Internet Protocol (IP), Matter enables communication across smart home devices, mobile apps, and cloud services and defines a specific set of IP-based networking technologies for device certification.

The Matter specification details everything necessary to implement a Matter application and transport layer stack. It is intended to be used by implementers as a complete specification.

The Alliance officially opened the Matter Working Group on January 17, 2020, and the specification is available for adoption now.

Visit buildwithmatter.com to learn more and read the latest news and updates about the project.

Project Overview

Development Goals

Matter is developed with the following goals and principles in mind:

Unifying: Matter is built with and on top of market-tested, existing technologies.

Interoperable: The specification permits communication between any Matter-certified device, subject to users’ permission.

Secure: The specification leverages modern security practices and protocols.

User Control: The end user controls authorization for interaction with devices.

Federated: No single entity serves as a throttle or a single point of failure for root of trust.

Robust: The set of protocols specifies a complete lifecycle of a device — starting with the seamless out-of-box experience, through operational protocols, to device and system management specifications required for proper function in the presence of change.

Low Overhead: The protocols are practically implementable on low compute-resource devices, such as MCUs.

Pervasive: The protocols are broadly deployable and accessible, by leveraging IP and being implementable on low-capability devices.

Ecosystem-Flexible: The protocol is flexible enough to accommodate deployment in ecosystems with differing policies.

Easy to Use: The protocol provides smooth, cohesive, integrated provisioning and out-of-box experience.

Open: The Project’s design and technical processes are open and transparent to the general public, including non-members wherever possible.

Architecture Overview

Matter aims to build a universal IPv6-based communication protocol for smart home devices. The protocol defines the application layer that will be deployed on devices and the different link layers to help maintain interoperability. The following diagram illustrates the normal operational mode of the stack: Matter Architecture Overview

The architecture is divided into layers to help separate the different responsibilities and introduce a good level of encapsulation among the various pieces of the protocol stack. The vast majority of interactions flow through the stack captured in the following Figure:

Matter Stack Architecture

  1. Application: High-order business logic of a device. For example, an application that is focused on lighting might contain logic to handle turning on/off the bulb as well as its color characteristics.
  1. Data Model: The data layer corresponds to the data and verb elements that help support the functionality of the application. The Application operates on these data structures when there is an intent to interact with the device.
  1. Interaction Model: The Interaction Model layer defines a set of interactions that can be performed between a client and server device. For example, reading or writing attributes on a server device would correspond to application behavior on the device. These interactions operate on the elements defined at the data model layer.
  1. Action Framing: Once an action is constructed using the Interaction Model, it is serialized into a prescribed packed binary format to encode for network transmission.
  1. Security: An encoded action frame is then sent down to the Security Layer to encrypt and sign the payload to ensure that data is secured and authenticated by both sender and receiver of a packet.

  2. Message Framing & Routing: With an interaction encrypted and signed, the Message Layer constructs the payload format with required and optional header fields; which specify the message's properties and some routing information.

  1. IP Framing & Transport Management: After the final payload has been constructed, it is sent to the underlying transport protocol for IP management of the data.

Current Status of Matter

Matter’s design and technical processes are intended to be open and transparent to the general public, including to Working Group non-members wherever possible. The availability of this GitHub repository and its source code under an Apache v2 license is an important and demonstrable step to achieving this commitment. Matter endeavors to bring together the best aspects of market-tested technologies and redeploy them as a unified and cohesive whole-system solution. The overall goal of this approach is to bring the benefits of Matter to consumers and manufacturers as quickly as possible. As a result, what you observe in this repository is an implementation-first approach to the technical specification, vetting integrations in practice. The Matter repository is growing and evolving to implement the overall architecture. The repository currently contains the security foundations, message framing and dispatch, and an implementation of the interaction model and data model. The code examples show simple interactions, and are supported on multiple transports -- Wi-Fi and Thread -- starting with resource-constrained (i.e., memory, processing) silicon platforms to help ensure Matter’s scalability.

Note: The applications under examples/ are reference implementations intended for development and testing. They are not production-ready and are not intended to be shipped as-is in a commercial product.

How to Contribute

We welcome your contributions to Matter. Read our contribution guidelines here.

Building and Developing in Matter

Instructions about how to build Matter can be found here .

Directory Structure

The Matter repository is structured as follows:

File/FolderContent
buildBuild system support content and built output directories
build_overridesBuild system parameter customization for different platforms
configProject configurations
credentialsDevelopment and test credentials
docsDocumentation, including guides. Visit the Matter SDK documentation page to read it.
examplesExample firmware applications that demonstrate use of Matter (not production-ready)
integrations3rd party integrations
scriptsScripts needed to work with the Matter repository
srcImplementation of Matter
third_party3rd party code used by Matter
zzz_generatedZAP generated template code - Revolving around cluster information
BUILD.gnBuild file for the GN build system
CODE_OF_CONDUCT.mdCode of conduct for Matter and contribution to it
CONTRIBUTING.mdGuidelines for contributing to Matter
LICENSEMatter license file
REVIEWERS.mdPR reviewers
gn_build.shBuild script for specific projects such as Android, EFR32, etc.
README.mdThis file

License

Matter is released under the Apache 2.0 license.