Skip to content

Trial: trusted-SCL golden-wire runtime on ARSAS 1.6.36 - #310

Merged
masarray merged 31 commits into
fix/fat-workstation-convergencefrom
trial/scl-golden-wire-v1636
Sep 16, 2026
Merged

masarray merged 31 commits into
fix/fat-workstation-convergencefrom
trial/scl-golden-wire-v1636

Conversation

@masarray

@masarray masarray commented Sep 15, 2026 •

Copy link
Copy Markdown
Owner

Purpose

Canonical ARSAS 1.6.36 physical field-trial lane for the trusted-SCL golden-wire runtime. This lane starts from exact ARSAS 1.6.36 staging baseline 384e2fe67b871a329b07ce5db2aa2916cca5c054 and remains Draft until exact-head software gates and physical IEC 61850 evidence are both reviewed.

Exact engine authority

ARSAS pins ARIEC61850 e1d51e52d0f5ae8118afb54e7b76595ff96755c6 from the SCL convergence evidence lane. The lock is immutable at build time and preserves trusted-SCL DataSet/RCB authority, ldName, ReportControl indexed semantics, quoted Edition-1/vendor OSI-AP-Title compatibility, Domain/VMD reconciliation, and bounded sequential initial FC-root Reads.

Trusted-SCL Play path

When a device has trusted SCL authority, normal Play fails closed through:

  1. exact SCL source SHA-256 verification;
  2. SCL-derived COTP/session/presentation/ACSE/MMS association;
  3. Domain/VMD reconciliation;
  4. bounded sequential FC-root Reads (<=10 references, one outstanding);
  5. no hidden full-discovery or cached-association fallback.

Cached-live-model behavior remains separate for devices without trusted SCL authority. Reconnect re-selects the same authority and cannot silently downgrade a trusted-SCL session to generic cached discovery.

Trusted static reporting

Trusted-SCL Static DataSet mode uses the SCL-derived ordered DataSet directory and SCL RCB inventory already held in memory. It does not perform network DataSet-directory discovery and does not create/delete dynamic DataSets.

Normal Play now delegates to ARIEC StartStaticSclReportMonitorAsync with triggerGeneralInterrogation: true so each trusted static RCB receives one explicit startup GI after the InformationReport receiver is registered and the RCB is armed.

Primary wire contract:

  • receiver is installed before any RCB write;
  • BRCB: whole-RCB Read -> RptEna=true -> verification readbacks -> one explicit GI=true; ResvTms remains retry-only after a real direct-RptEna rejection;
  • URCB: whole-RCB Read -> Resv=true when exposed -> RptEna=true -> verification readbacks -> one explicit GI=true;
  • no cyclic MMS process polling is introduced;
  • no dynamic DataSet mutation;
  • no network DataSet-directory browse in trusted-SCL mode.

This fixes the physical failure where Digital/BRCB obtained data but Analog/URCB stayed Unknown because normal Play armed reporting without requesting the initial GI image.

Safe trial remains read-only

--scl-safe-trial and --scl-safe-trial-single remain association/read validation tools only. They keep readOnly=true, writesAllowed=false, reportEnableAllowed=false, and never enter the normal trusted static report activation path. The GI change therefore applies only to normal Play/monitor startup.

Physical acceptance target

The next physical retest must use the same SCL and IED as the golden reference client comparison. Expected evidence is:

  • Buffer01: RptEna accepted, one startup GI accepted, matching Digital InformationReport;
  • Unbuffer01: Resv accepted when exposed, RptEna accepted, one startup GI accepted, matching Analog InformationReport;
  • all 58/58 selected static DataSet members receive an initial value without waiting for a process change and without cyclic MMS polling.

Merge rule

Keep Draft. Do not merge until the exact PR head passes Windows build/regression/package/smoke gates and the physical Diagnostic Export + PCAP confirm the expected RCB/GI/report sequence.

Copy link
Copy Markdown
Owner Author

CI evidence update for physical trial gate:

  • Exact ARSAS head: 8e9edbbd4e63dd80b09f7c929d10f32007361a50
  • Exact ARIEC lock: e41def0a2676efb8a143905798155f6bccc6f047
  • Build ARSAS run 34930836037 completed SUCCESS.
  • Build solution: success.
  • ARSAS regression tests: success.
  • Portable single-EXE publish: success.
  • Portable smoke test: success.
  • Portable artifact upload: success.
  • Portable artifact: ARSAS-win-x64-portable-single-exe, artifact id 10381861642, digest sha256:de6a462b75d9d02ecd6c3999922eede8fd31da0b76a11b675b6794da7d83f177.
  • Windows installer run 34930836036 completed SUCCESS including build/test, silent install and field-runtime smoke test.
  • Installer artifact: ARSAS-1.6.36-win-x64-installer, artifact id 10382060697, digest sha256:7314d7e7a26cd47b63f20e547142551a0e10db50c4a0749ad72cef65b91a061d.

Physical validation remains pending. First IED test should use the read-only --scl-safe-trial path with a simultaneous TCP/102 capture. Do not treat CI success as physical IEC 61850 interoperability proof.

All exact-head software gates passed. Preserve PR #312 runtime/control/analyzer work and integrate the green ARIEC convergence pin plus corrected physical-trial contract.
Exact-head gates passed: Build #2833, Installer #986, IO #1375, SV #1815, COMTRADE #233. Preserve ARIEC convergence, independent IED process-state authority, and presentation-only analyzer easing.
@masarray
masarray marked this pull request as ready for review September 16, 2026 08:04

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4f5c2742f9

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +500 to +502
return leaf.Length > 0 && !char.IsDigit(leaf[^1])
? normalized + "01"
: normalized;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Append the instance suffix to digit-ending indexed RCB names

When an SCL declaration has indexed=true and its base ReportControl name already ends in a digit (for example, BRCB1), this condition incorrectly treats the declaration as a concrete instance and returns BRCB1. The first server-side instance is formed by adding the index suffix (BRCB101 in this example), so the trusted-SCL path attempts to arm a nonexistent RCB and leaves its report-only points unavailable. Use the explicit indexed metadata rather than the last character of the configured name to determine whether an instance suffix is required.

AGENTS.md reference: AGENTS.md:L153-L153

Useful? React with 👍 / 👎.

Comment on lines +63 to +66
_smoothedVoltageVectors = SmoothVectors(_smoothedVoltageVectors, voltageVectors, elapsedMilliseconds);
_smoothedCurrentVectors = SmoothVectors(_smoothedCurrentVectors, currentVectors, elapsedMilliseconds);
_voltagePanel = PreparePanel(_smoothedVoltageVectors);
_currentPanel = PreparePanel(_smoothedCurrentVectors);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Snap the analyzer to the final scrub target

Each ShowPhasors call advances the eased values only once, and the final scrub request is rendered through the same interpolation with no subsequent timer or exact-target commit. If the user releases the cursor shortly after the preceding frame, the displayed magnitude and angle remain permanently between the old and final engineering values until another interaction occurs; the harmonic view has the same one-shot behavior in ShowSpectra. The final request needs to snap to the target or schedule bounded continuation frames that end with the exact value.

AGENTS.md reference: AGENTS.md:L96-L106

Useful? React with 👍 / 👎.

Comment on lines +130 to +131
var client = new NativeIec61850Client();
result = await client.ConnectUsingSclAsync(

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Dispose the safe-trial MMS client before returning

After a successful safe trial, this client owns an active MMS association but is never disposed. RunAsync returns and App.OnStartup then shows a modal result dialog, so the IED association can remain open nondeterministically until GC or process shutdown rather than closing when the read-only trial completes; this can also consume a limited IED association slot while the dialog is open. Create the client with await using so cleanup finishes before evidence is returned.

AGENTS.md reference: AGENTS.md:L139-L141

Useful? React with 👍 / 👎.

return false;
}

var sclPath = Path.GetFullPath(args[1]);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Convert malformed trial paths into parse failures

For malformed user-supplied paths, such as a value containing an embedded NUL, Path.GetFullPath throws instead of letting this TryParse method return false. Because RunAsync invokes TryParse before entering its exception boundary, the exception escapes through the synchronous startup call and the safe-trial process terminates without its structured failure result or evidence file. Catch path-normalization failures and return the parse error contract for both the SCL and optional evidence paths.

AGENTS.md reference: AGENTS.md:L58-L68

Useful? React with 👍 / 👎.

@masarray
masarray merged commit ed203dd into fix/fat-workstation-convergence Sep 16, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant