Skip to content

Harden ARSAS 1.6.19 P0 safety, tests, and release provenance - #107

Merged
masarray merged 28 commits into
mainfrom
agent/p0-hardening-1-6-19
Jul 28, 2026
Merged

masarray merged 28 commits into
mainfrom
agent/p0-hardening-1-6-19

Conversation

@masarray

@masarray masarray commented Jul 28, 2026 •

Copy link
Copy Markdown
Owner

Purpose

Close the P0 gaps found after the two-cycle Sampled Values snapshot was merged, and establish a repeatable application-level validation baseline for ARSAS 1.6.19.

P0 fixes

  • make SmvSnapshotResult.IsCleanProof intrinsically reject publisher restarts
  • apply the restart-aware verdict consistently to badge, summary, continuity evidence, and status text
  • show restart, gap, missing-sample, duplicate, and out-of-order evidence explicitly
  • lock the selected stream while a snapshot is active
  • capture an immutable stream identity and reject a completed result if selection ownership changed
  • replace the temporary engine-branch dependency with an immutable merged ARIEC61850/main commit lock
  • ensure manual release dispatch from main honors the requested version before the stable manifest path

Application regression tests

Adds tests/ARSAS.Tests with deterministic coverage for:

  • complete and incomplete two-cycle windows
  • gap, duplicate, out-of-order, and restart classification
  • canonical restart-aware clean-proof result
  • restart-aware summary verdict correction
  • continuity evidence text
  • normalized immutable stream identity
  • rejection of a different selected stream

The Windows build and installer workflows restore and build the full solution, run the application tests, and only then publish packages.

Version and provenance

  • development version advanced to 1.6.19
  • canonical version metadata added through Directory.Build.props
  • VERSION, project metadata, packaging, changelog, and CI are aligned
  • engine provenance is stored in engines/ARIEC61850.lock.json
  • engine commit: 0f8453182957900bc6d91287fb8177c8d9762188
  • source engine PR: masarray/ARIEC61850#45
  • build, installer validation, and release packaging all fetch the exact engine commit detached
  • release artifacts include SPDX SBOM, app/engine provenance JSON, checksums, and attestations

Final automated validation at head 0ddf817e2f2cbca60ea673fe8b4b119416bb3098

  • Build ARSAS run 692 — success
    • source, license, premium UX, GOOSE, SMV, SAS, and version invariants
    • immutable engine checkout and API checks
    • complete solution restore and Release build
    • ARSAS application regression tests
    • TRX evidence upload
    • portable Windows package publication
  • Installer validation run 63 — success
    • immutable engine checkout
    • solution build and regression tests
    • installer compilation
    • silent install/uninstall smoke test
    • checksum generation and artifact upload
  • Adoption and field-proof run 42 — success
  • Codex review findings addressed and both review threads resolved

Generated candidate artifacts

  • ARSAS-win-x64 portable artifact
  • ARSAS-1.6.19-win-x64-installer artifact
  • ARSAS-test-evidence TRX artifact
  • source snapshot artifact

Release boundary

The currently published stable release remains 1.6.18. This PR prepares and validates 1.6.19 source and packages; it does not overwrite or silently rebuild the 1.6.18 release.

Live MU, PCAP replay, 50/60 Hz capture, and deliberate counter-error field tests remain acceptance evidence before calibrated, formal-conformance, or universal-interoperability claims.

@masarray
masarray marked this pull request as ready for review July 28, 2026 04:06

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 2365e140bf

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread SmvViewerWindow.P0Hardening.cs
Comment thread .github/workflows/release-windows.yml
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant