Skip to content

FAT workstation convergence: architecture freeze and canonical shell staging - #296

Merged
masarray merged 322 commits into
feat/native-fat-workspacefrom
fix/fat-workstation-convergence
Sep 16, 2026
Merged

masarray merged 322 commits into
feat/native-fat-workspacefrom
fix/fat-workstation-convergence

Conversation

@masarray

@masarray masarray commented Sep 9, 2026 •

Copy link
Copy Markdown
Owner

Purpose

Protected staging lane for the Engineering-integrated FAT workstation and ARSAS 1.6.36 public-release candidate. This PR remains Draft until the exact combined candidate passes CI and the physical FAT field gate.

Current combined candidate

  • version: 1.6.36
  • staging head: 384e2fe67b871a329b07ce5db2aa2916cca5c054
  • current main baseline integrated: 3ad21a631d09a175a8030a0764fd880d0ee77560
  • compare main...HEAD: behind_by=0
  • PR M1: make COMTRADE open native-only #305 (native-only COMTRADE + FAT persistence/release hardening) merged into this staging lane
  • public v1.6.35 remains untouched

Protected architecture

  • Engineering remains the authoritative parsed SCL/live-value workspace; FAT is an evidence/session projection
  • canonical Engineering shell keeps the permanent FAT destination
  • static DataSet FAT must not enable Hybrid/cyclic MMS polling or restart the shared Engineering acquisition session
  • duplicate live-reference preflight fails closed unless a generated manual shadow is proven to resolve to the same authoritative live leaf
  • FAT capture requires a real initialized live IEC 61850 observation
  • FAT persistence uses durable SCL/endpoint identity, collision-safe evidence paths, and non-destructive corrupt-state recovery
  • COMTRADE Open is strictly ARSAS in-process via the pinned ArdIrec native bridge; no external ardirec.exe, Qt runtime, or Process.Start fallback
  • field-accepted Time Signals / Phasor / Harmonics / six-loop Locus behavior from current main remains protected

Pre-merge validation already completed

On source head 4fd863322f0bb247911cd241f71c366c015449d4, immediately before merge into this staging branch:

  • Build ARSAS #2768: success
  • full application regression suite: success
  • Validate IO List Testing #1321: success
  • Validate SV evidence bundles #1752: success
  • Validate COMTRADE viewer integration Reduce P1 workspace noise and progressive GOOSE disclosure #205: success
  • Validate ARSAS Windows installer #929: success
  • portable single-EXE publish + smoke: success
  • installer build + silent install/runtime smoke: success
  • exact-head installer artifact: ARSAS-1.6.36-win-x64-installer
  • exact-head portable artifact: ARSAS-win-x64-portable-single-exe

Exact staging CI — RUNNING

The merge commit itself is being requalified now:

Do not treat the pre-merge green run as a substitute for these exact staging-head checks.

Remaining gate — PHYSICAL FAT FIELD

After all five staging checks are green, test the exact artifact produced from staging head 384e2fe67b871a329b07ce5db2aa2916cca5c054 on the real IED/SCL workflow:

  • Start FAT succeeds for the previously failing generated scl-manual-* shadow case while a genuinely ambiguous duplicate still fails closed
  • first and repeated FAT entry do not show blank/black host and latency remains acceptable
  • Engineering -> FAT does not reconnect, enable Hybrid, or start cyclic MMS polling
  • static DataSet row count has no duplication
  • selected IED context remains correct
  • live value, IEC 61850 quality and relay/device timestamp are correct
  • Value 1 / Value 2 capture records real live evidence
  • repeated IED selection / app restart preserves evidence using durable identity without cross-device collision
  • Report Preview/export remains correct
  • repeated Engineering <-> FAT navigation remains stable
  • COMTRADE Open stays inside ARSAS and Time Signals/Phasor/Harmonics/Locus remain functional

Only after this exact physical field candidate passes should the FAT stack be collapsed/merged to main; the 1.6.36 release manifest on main will then trigger the release pipeline that rebuilds/tests packages, produces checksums/SBOM/provenance/attestations, and publishes the public stable release.

Copy link
Copy Markdown
Owner Author

Final code/CI gate for the current FAT convergence head is green.

Head: 3b49206bfebaaeac6a84a3dcae63f3925d0e0bc7

Validated on this exact head:

  • Build ARSAS #2570: success
  • Full regression suite: 928 passed, 0 failed
  • Validate IO List Testing #1127: success
  • Validate SV evidence bundles #1575: success
  • portable win-x64 single-EXE publish: success
  • portable EXE smoke test: success
  • no open PR review threads

Field candidate artifact: ARSAS-win-x64-portable-single-exe from workflow run #2570 (contains ARSAS-1.6.35-win-x64-portable.exe).

Remaining gate is physical field validation only. Please test this exact artifact for: first FAT entry with no blank/black host; Engineering -> FAT transition without reconnect/SCL re-import; static DataSet row count without duplication; selected-IED context; live value/quality/timestamp; Value 1/Value 2 capture; Report Preview/export; and repeated Engineering <-> FAT navigation. Do not merge this staging PR until that field gate is confirmed.

Field-accepted COMTRADE workstation integration from the P1D stack through P1D.7.

Includes synchronized Time Signals, Phasor, Harmonics, native six-loop Locus, RMS/PRI-SEC presentation, cursor measurements, first-click fault-record reliability, deterministic analog-before-digital ordering, Clear/Auto state authority, retained/screen-space waveform rendering, synchronous cursor transforms, bounded latest-wins analysis/readout scheduling, and bridge-only packaging.

Exact merge-prep head passed Build ARSAS #2571, SV #1576, COMTRADE integration #171, and Windows Installer #893 against current main. The production AGENTS.md from main is preserved. ArdIrec PR #41 was merged first and the ARSAS lock remains pinned to the exact field-tested bridge commit. FAT workstation files/branches are intentionally untouched and remain under their independent field gate.

Copy link
Copy Markdown
Owner Author

Cross-thread integration note: the field-accepted COMTRADE P1D.7 stack was consolidated and squash-merged to main as c3e2ac3ef6e6a3a49f47c5155a0ba4a7c00bcb6b. File-overlap audit found no FAT runtime/source overlap with the COMTRADE integration. This FAT PR remains intentionally unmerged pending its own field gate. Before final FAT integration, update/rebase against the new main and rerun its exact-head CI rather than merging the older base blindly.

Copy link
Copy Markdown
Owner Author

Cross-thread coordination note added to main: docs/WORKSTREAM_COORDINATION.md (commit b0ec4828755272c3331680098d0c95d9f467d84b). COMTRADE P1D.7 is already integrated in main via PR #300. Before FAT final landing, integrate the latest main, preserve the COMTRADE no-regression boundary documented there, rerun exact-head CI on the combined codebase, and repeat the FAT field gate. Do not merge this FAT stack from a stale pre-P1D.7 base.

Copy link
Copy Markdown
Owner Author

Final coordination update from the completed COMTRADE lane: latest main is now 3ad21a631d09a175a8030a0764fd880d0ee77560 (runtime COMTRADE integration at c3e2ac3e... plus durable coordination/lock cleanup). Before FAT final landing, integrate this main or newer, read root AGENTS.md §17 and docs/WORKSTREAM_COORDINATION.md, preserve accepted COMTRADE behavior, then rerun exact combined-head CI + the FAT field gate. Do not merge this stale stacked head directly over current main.

masarray and others added 27 commits September 15, 2026 11:52
All exact-head software gates passed. Preserve PR #312 runtime/control/analyzer work and integrate the green ARIEC convergence pin plus corrected physical-trial contract.
Exact-head gates passed: Build #2833, Installer #986, IO #1375, SV #1815, COMTRADE #233. Preserve ARIEC convergence, independent IED process-state authority, and presentation-only analyzer easing.
User approved merge after field validation. Exact-head gates passed: Build #2834, Installer #987, IO #1376, SV #1816, COMTRADE #234.
@masarray
masarray marked this pull request as ready for review September 16, 2026 08:14

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ed203dd21d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +240 to +243
if (result.Succeeded && result.SnapshotFound)
{
ReplaceNativeFatEvidenceForIed(cache, iedName, result.EvidenceByRow);
cache.EvidenceHydrationState = NativeFatEvidenceHydrationState.Resolved;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Merge loaded evidence instead of replacing live edits

When this auto-load overlaps an operator edit or a Start FAT capture, ReplaceNativeFatEvidenceForIed removes every current row for the IED and replaces it with the older disk snapshot. The Start FAT button remains usable while hydration is running, and the existing hydration path already uses MergeMissing, so a slow load can make newly captured commissioning evidence disappear and a later save can permanently overwrite the disk copy without it. Reuse the existing merge semantics or serialize edits behind the single hydration authority.

AGENTS.md reference: AGENTS.md:L27-L33

Useful? React with 👍 / 👎.

Comment on lines +313 to +315
try
{
_nativeFatEvidencePersistenceCoordinator?.DrainAllAsync().GetAwaiter().GetResult();

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Do not synchronously drain evidence writes on the UI thread

When the window closes with queued evidence, this Closed handler blocks the dispatcher on DrainAllAsync; the worker always includes a 120 ms delay and may then perform local or redirected-profile filesystem I/O with no timeout. A slow or unavailable profile location can therefore freeze shutdown indefinitely. Make closure asynchronous or detach a bounded final flush rather than synchronously waiting on the UI thread.

AGENTS.md reference: AGENTS.md:L78-L90

Useful? React with 👍 / 👎.

Comment on lines +29 to +33
// COMTRADE source timestamps are expected to be monotonic. If a malformed source violates
// even the endpoint ordering, degrade safely to the validated common range rather than
// applying binary search to an invalid domain.
if (count > 1 && timestamps[0] > timestamps[count - 1])
return new ComtradeVisibleSampleRange(0, count);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Validate the full timestamp sequence before binary search

For malformed COMTRADE data whose first and last timestamps are ascending but which contains an internal reset or out-of-order sample, this endpoint-only check still runs LowerBound/UpperBound on an unsorted array. For example, [0, 100, 20, 200] can cause the visible-range search to skip the sample at 100, hiding waveform points or digital transitions. Record monotonicity when the track is built and fall back to the full validated range whenever any inversion is present.

AGENTS.md reference: AGENTS.md:L58-L66

Useful? React with 👍 / 👎.

Comment on lines +35 to +38
if (Test-Path $destinationBridge -PathType Leaf) {
Write-Host "==> Reusing pinned ArdIrec bridge: $destinationBridge"
Write-Output $destinationBridge
exit 0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Key the reused native bridge by the locked commit

When publish-windows-portable.ps1 is run again from a working tree whose obj/ardirec-native/<runtime> already contains a DLL, this early exit accepts that DLL without checking the current lock commit or even the supplied source revision. After an ArdIrec lock upgrade, an incremental portable build can therefore embed the previous analysis engine while claiming the new pinned revision. Include the commit in the cache path or persist and verify provenance before reuse.

Useful? React with 👍 / 👎.

@masarray
masarray merged commit ae5cdc0 into feat/native-fat-workspace Sep 16, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant