Skip to content

G2.6 P1: Q0 target-locked automatic command-bound A3 dchg proof - #231

Merged
masarray merged 37 commits into
g2.6-smart-dynamic-rcbfrom
g2.6-p1-deterministic-a3
Aug 24, 2026
Merged

masarray merged 37 commits into
g2.6-smart-dynamic-rcbfrom
g2.6-p1-deterministic-a3

Conversation

@masarray

@masarray masarray commented Aug 24, 2026 •

Copy link
Copy Markdown
Owner

Goal

Close the physical G2.6-P1 A3 proof deterministically on the already-proven field control path:

AA1C1F08R4Q0/CSWI1.Pos one-shot OPEN -> qualified Q0 MMS status transition -> Dynamic URCB InformationReport(reason=data-change) on the same exact DataSet index -> cleanup

This PR remains a commissioning-only P1 step. It does not mark the IED ProductionEligible and does not enable production automatic dynamic reporting.

Field finding that changed P1

The latest physical run proved the A3 dchg report path could arm and clean up correctly, but the generic command-focus recovery had selected the first eight alphabetically ordered command-status members (DSQZ/ESQZ) and therefore excluded the intended Q0 status. The manual READY -> operator click flow also timed out without a command being captured.

P1 now removes both ambiguities instead of widening the safety boundary.

Exact Q0 field lock

The automatic A3 coordinator is deliberately hard-bound to:

  • stable identity: ied:AA1C1F08R4
  • model fingerprint: sha256:50c691318c6d6a16b68b121ac48627c26e6e32b937836d559dca1b9eb559f0d9
  • control object: AA1C1F08R4Q0/CSWI1.Pos
  • exact control status: AA1C1F08R4Q0/CSWI1.Pos.stVal
  • automatic stimulus: Open only
  • interlock check: ON
  • synchrocheck: OFF
  • test mode: OFF

The target must resolve through the existing ARSAS control inspector, be operationally ready, and read exactly Closed. Open/intermediate/unknown state blocks dispatch. There is no automatic CLOSE, toggle, opposite command, restore command, or retry.

Target-scoped transactional recovery

If the current InformationReportProven profile does not contain the exact Q0 command-focus status chain, P1 automatically runs the existing transactional recovery, but on a private target-scoped clone of the discovered signal model:

  • live SignalDefinition objects are never modified
  • non-Q0 ControlStatusReference values are suppressed only on private clones
  • identity-significant fields remain unchanged and the stable identity/model fingerprint are recomputed and required to match exactly
  • recovery therefore qualifies Q0 first rather than exhausting the eight-member G2.4 envelope on unrelated control objects
  • exact direct MMS-read validation is retained
  • dynamic NamedVariableList qualification runs in a private staging profile store
  • existing G2.4 V2 proves one-URCB activation + actual InformationReport in staging
  • existing G2.4-C proves fresh-association RCB/DataSet cleanup closure
  • optimistic concurrency prevents overwrite of newer live evidence
  • only after every stage passes may the live profile be atomically replaced InformationReportProven -> InformationReportProven
  • any failure before final replacement leaves the old live profile authoritative
  • recovery issues ZERO control commands and cannot produce ProductionEligible

One-shot automatic stimulus

Ctrl+Shift+A is now the explicit commissioning action for this field-bounded P1 flow. The successful path has no arm/recovery/manual-command dialog.

The existing DynamicReportCommandBoundDataChangeCommissioningService remains authoritative for the dchg-only report/witness transaction. It still does not execute control. After the exact URCB is armed and the final read-only qualified-member baseline is captured, its READY marker is intercepted synchronously by the new Q0 coordinator.

At that exact handoff the coordinator performs a final control inspection. Only if Q0 is still exactly operationally ready and Closed does it construct one normal Iec61850ControlCommandRequest and call the already-existing:

Iec61850MonitorRuntime.ExecuteControlAsync(...)

No separate SBO/SBOw/Operate implementation is introduced. The runtime's existing Control execution requested: diagnostic is emitted before native ARIEC control execution and is consumed by the already-armed A3 witness exactly as before.

Automatic dispatch is one-shot:

  • maximum automatic dispatch count: 1
  • requested value: Open
  • retry: false
  • automatic CLOSE: false
  • toggle/opposite command: false
  • automatic restore: false

If the final READY-time gate fails before dispatch, A3 is cancelled fail-closed and zero commands are sent. If a physical command was already dispatched but later returns ambiguous/error evidence, P1 never retries it; native wire evidence plus physical transition/report evidence remain authoritative.

Deterministic A3 PASS contract

PASS still requires all of the following in the same bounded armed window:

  1. exact InformationReport-proven dchg-only activation
  2. exact runtime request for AA1C1F08R4Q0/CSWI1.Pos -> Open captured after the final read-only baseline
  3. post-command transition on a qualified Q0 command-focus member
  4. valid spontaneous InformationReport with reason-for-inclusion data-change
  5. at least one same exact DataSet index between the command-bound transition and report
  6. report monitor cleanup PASS
  7. temporary TrgOps/OptFlds restore PASS
  8. fresh-association cleanup closure PASS

The core remains strict dchg-only: GI=false, integrity=false, qchg=false, dupd=false, with reason-for-inclusion + DataSet-name evidence.

Safety boundaries

  • exact field identity/fingerprint only
  • exact Q0 control/status only
  • automatic OPEN only from exact Closed
  • no retry / CLOSE / toggle / restore
  • target recovery sends zero control commands
  • core A3 remains an observer and never calls ExecuteControlAsync
  • no MarkProductionEligible in recovery, auto coordinator, or core A3
  • persisted field state remains at most InformationReportProven
  • production automatic dynamic reporting remains OFF

Validation — current head 4eedc1449b15ddc24f048040805cef4e508a6dd9

  • immutable ARIEC61850 engine lock: main @ aa2ddfb47af5f3b806858553568792fbc21a64f1
  • Build ARSAS #1419: PASS
    • source/license/invariant checks PASS
    • full solution build PASS, 0 errors
    • ARSAS regression suite: 582/582 PASS, 0 failed, 0 skipped
    • real portable single EXE publish PASS
    • portable smoke test PASS
    • artifact upload PASS
  • Windows installer site: trace reviewed field evidence to exact ARSAS releases #369: PASS
    • restore/build/test PASS
    • 582/582 tests PASS
    • installer compile PASS
    • silent current-user install/uninstall smoke test PASS
    • checksum + artifact upload PASS
  • IO List Testing site: align technical review reliability metadata #362: PASS
  • SV evidence validation #531: PASS
  • Windows installer SHA256: 9B72E0FDB99F0FC3480F3666A9204363BBB7E7D3BBEC957A6BFE564D6FBB110A

A physical Q0 automatic A3 PASS is intentionally not claimed by CI. This PR remains unmerged until the field run proves the exact Q0 one-shot command, qualified transition, spontaneous dchg InformationReport on the same DataSet index, and complete cleanup. Shadow verification and the remaining G2.6 acceptance gates are still required before any later ProductionEligible transition.

@masarray
masarray marked this pull request as ready for review August 24, 2026 07:38

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5fb20acedf

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread Services/DynamicReportCommandBoundDataChangeCommissioningService.cs
Comment thread Services/DynamicReportCommandBoundDataChangeCommissioningService.cs Outdated
@masarray masarray changed the title G2.6 P1: deterministic command-bound A3 dchg proof G2.6 P1: Q0 target-locked automatic command-bound A3 dchg proof Aug 24, 2026

masarray commented Aug 24, 2026 •

Copy link
Copy Markdown
Owner Author

Pre-merge hardening completed on current head d9a8f83b06b025b954c486ad467581df2347a387.

Both P1 correctness blockers are now closed:

  1. the selected valid dchg frame preserves ReceivedAt, and A3 requires the accepted report timestamp to be strictly after the captured command timestamp;
  2. Control execution requested: is intent only; A3 additionally requires a later successful native-control/wire diagnostic from the existing runtime control path. Rejected/NotSent/no-response cases fail closed.

No second control implementation was added. Q0 remains one-shot OPEN only, no retry/CLOSE/toggle/restore, profile remains InformationReportProven, and ProductionEligible stays OFF.

Current-head validation: Build ARSAS #1422 PASS, 583/583 tests; Windows installer #372 PASS; IO #365 PASS; SV #534 PASS.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Aug 24, 2026 •

Copy link
Copy Markdown

Resolved manually in PR #231 because the repository Codex environment was not configured for the bot. The two requested correctness fixes were implemented, regression-tested, and both inline review threads are now resolved.

@masarray
masarray merged commit 57cc3cd into g2.6-smart-dynamic-rcb Aug 24, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant