FAT workstation convergence: architecture freeze and canonical shell staging - #296
Conversation
…t-v1 docs: add production engineering contract for AI agents
|
Final code/CI gate for the current FAT convergence head is green. Head: Validated on this exact head:
Field candidate artifact: Remaining gate is physical field validation only. Please test this exact artifact for: first FAT entry with no blank/black host; Engineering -> FAT transition without reconnect/SCL re-import; static DataSet row count without duplication; selected-IED context; live value/quality/timestamp; Value 1/Value 2 capture; Report Preview/export; and repeated Engineering <-> FAT navigation. Do not merge this staging PR until that field gate is confirmed. |
Field-accepted COMTRADE workstation integration from the P1D stack through P1D.7. Includes synchronized Time Signals, Phasor, Harmonics, native six-loop Locus, RMS/PRI-SEC presentation, cursor measurements, first-click fault-record reliability, deterministic analog-before-digital ordering, Clear/Auto state authority, retained/screen-space waveform rendering, synchronous cursor transforms, bounded latest-wins analysis/readout scheduling, and bridge-only packaging. Exact merge-prep head passed Build ARSAS #2571, SV #1576, COMTRADE integration #171, and Windows Installer #893 against current main. The production AGENTS.md from main is preserved. ArdIrec PR #41 was merged first and the ARSAS lock remains pinned to the exact field-tested bridge commit. FAT workstation files/branches are intentionally untouched and remain under their independent field gate.
|
Cross-thread integration note: the field-accepted COMTRADE P1D.7 stack was consolidated and squash-merged to |
|
Cross-thread coordination note added to |
|
Final coordination update from the completed COMTRADE lane: latest |
All exact-head software gates passed. Preserve PR #312 runtime/control/analyzer work and integrate the green ARIEC convergence pin plus corrected physical-trial contract.
Exact-head gates passed: Build #2833, Installer #986, IO #1375, SV #1815, COMTRADE #233. Preserve ARIEC convergence, independent IED process-state authority, and presentation-only analyzer easing.
User approved merge after field validation. Exact-head gates passed: Build #2834, Installer #987, IO #1376, SV #1816, COMTRADE #234.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ed203dd21d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if (result.Succeeded && result.SnapshotFound) | ||
| { | ||
| ReplaceNativeFatEvidenceForIed(cache, iedName, result.EvidenceByRow); | ||
| cache.EvidenceHydrationState = NativeFatEvidenceHydrationState.Resolved; |
There was a problem hiding this comment.
Merge loaded evidence instead of replacing live edits
When this auto-load overlaps an operator edit or a Start FAT capture, ReplaceNativeFatEvidenceForIed removes every current row for the IED and replaces it with the older disk snapshot. The Start FAT button remains usable while hydration is running, and the existing hydration path already uses MergeMissing, so a slow load can make newly captured commissioning evidence disappear and a later save can permanently overwrite the disk copy without it. Reuse the existing merge semantics or serialize edits behind the single hydration authority.
AGENTS.md reference: AGENTS.md:L27-L33
Useful? React with 👍 / 👎.
| try | ||
| { | ||
| _nativeFatEvidencePersistenceCoordinator?.DrainAllAsync().GetAwaiter().GetResult(); |
There was a problem hiding this comment.
Do not synchronously drain evidence writes on the UI thread
When the window closes with queued evidence, this Closed handler blocks the dispatcher on DrainAllAsync; the worker always includes a 120 ms delay and may then perform local or redirected-profile filesystem I/O with no timeout. A slow or unavailable profile location can therefore freeze shutdown indefinitely. Make closure asynchronous or detach a bounded final flush rather than synchronously waiting on the UI thread.
AGENTS.md reference: AGENTS.md:L78-L90
Useful? React with 👍 / 👎.
| // COMTRADE source timestamps are expected to be monotonic. If a malformed source violates | ||
| // even the endpoint ordering, degrade safely to the validated common range rather than | ||
| // applying binary search to an invalid domain. | ||
| if (count > 1 && timestamps[0] > timestamps[count - 1]) | ||
| return new ComtradeVisibleSampleRange(0, count); |
There was a problem hiding this comment.
Validate the full timestamp sequence before binary search
For malformed COMTRADE data whose first and last timestamps are ascending but which contains an internal reset or out-of-order sample, this endpoint-only check still runs LowerBound/UpperBound on an unsorted array. For example, [0, 100, 20, 200] can cause the visible-range search to skip the sample at 100, hiding waveform points or digital transitions. Record monotonicity when the track is built and fall back to the full validated range whenever any inversion is present.
AGENTS.md reference: AGENTS.md:L58-L66
Useful? React with 👍 / 👎.
| if (Test-Path $destinationBridge -PathType Leaf) { | ||
| Write-Host "==> Reusing pinned ArdIrec bridge: $destinationBridge" | ||
| Write-Output $destinationBridge | ||
| exit 0 |
There was a problem hiding this comment.
Key the reused native bridge by the locked commit
When publish-windows-portable.ps1 is run again from a working tree whose obj/ardirec-native/<runtime> already contains a DLL, this early exit accepts that DLL without checking the current lock commit or even the supplied source revision. After an ArdIrec lock upgrade, an incremental portable build can therefore embed the previous analysis engine while claiming the new pinned revision. Include the commit in the cache path or persist and verify provenance before reuse.
Useful? React with 👍 / 👎.
Purpose
Protected staging lane for the Engineering-integrated FAT workstation and ARSAS 1.6.36 public-release candidate. This PR remains Draft until the exact combined candidate passes CI and the physical FAT field gate.
Current combined candidate
1.6.36384e2fe67b871a329b07ce5db2aa2916cca5c054mainbaseline integrated:3ad21a631d09a175a8030a0764fd880d0ee77560compare main...HEAD:behind_by=0v1.6.35remains untouchedProtected architecture
ardirec.exe, Qt runtime, or Process.Start fallbackmainremains protectedPre-merge validation already completed
On source head
4fd863322f0bb247911cd241f71c366c015449d4, immediately before merge into this staging branch:ARSAS-1.6.36-win-x64-installerARSAS-win-x64-portable-single-exeExact staging CI — RUNNING
The merge commit itself is being requalified now:
Do not treat the pre-merge green run as a substitute for these exact staging-head checks.
Remaining gate — PHYSICAL FAT FIELD
After all five staging checks are green, test the exact artifact produced from staging head
384e2fe67b871a329b07ce5db2aa2916cca5c054on the real IED/SCL workflow:scl-manual-*shadow case while a genuinely ambiguous duplicate still fails closedOnly after this exact physical field candidate passes should the FAT stack be collapsed/merged to
main; the1.6.36release manifest onmainwill then trigger the release pipeline that rebuilds/tests packages, produces checksums/SBOM/provenance/attestations, and publishes the public stable release.