diff --git a/docs/SCL_GOLDEN_WIRE_PHYSICAL_TRIAL.md b/docs/SCL_GOLDEN_WIRE_PHYSICAL_TRIAL.md index 73c8bc511..671bc2f77 100644 --- a/docs/SCL_GOLDEN_WIRE_PHYSICAL_TRIAL.md +++ b/docs/SCL_GOLDEN_WIRE_PHYSICAL_TRIAL.md @@ -1,16 +1,21 @@ # Trusted SCL golden-wire physical trial -This document freezes the first field-test contract for the protocol-only ARSAS 1.6.36 trial lane. +This document freezes the physical qualification contract for the ARSAS 1.6.36 trusted-SCL reporting lane after ARIEC reporting/bootstrap convergence. ## Immutable engine authority -- ARSAS branch: `trial/scl-golden-wire-v1636` -- ARIEC61850 engine: `e41def0a2676efb8a143905798155f6bccc6f047` -- Field-proven reporting/control baseline preserved by the engine lock: `11ab2304482600c19ba979f4fc9021ddb46b9af9` +- Canonical ARSAS field-trial base: `trial/scl-golden-wire-v1636` +- Qualification branch: `integration/ariec-convergence-0023ef9-v1636` +- ARIEC61850 convergence engine: `0023ef9a4373855497464ed3979e359c4041c95d` +- ARIEC source PR: `#132` +- ARIEC exact-head .NET CI: `#603` PASS +- Field-proven reporting/control baseline retained by the engine lock: `11ab2304482600c19ba979f4fc9021ddb46b9af9` + +The engine lock is the build-time authority. Do not substitute another ARIEC checkout while collecting qualification evidence. ## Gate 1 — read-only safe trial -Run the portable application with Wireshark capturing TCP port 102. +Run the exact portable candidate with Wireshark capturing TCP port 102. ```powershell ARSAS-1.6.36-win-x64-portable.exe --scl-safe-trial "C:\path\IED.cid" "IEDNAME" "AP1" "192.168.x.x" 102 @@ -32,13 +37,43 @@ Only after Gate 1 association/read behavior is understood, open the same verifie Trusted-SCL Play verifies the imported source SHA-256 before socket activity, keeps the SCL IED/AccessPoint association identity, performs Domain/VMD validation and bounded initial Reads, and does not silently fall back to cached association or full discovery. -For Static DataSet report-only mode, ordered DataSet membership and RCB identity remain SCL-authoritative in memory. The trusted path does not perform a network DataSet-directory browse or create/delete a dynamic DataSet. +For Static DataSet report-only mode, ordered DataSet membership and RCB identity remain SCL-authoritative in memory. The trusted path does not perform a network DataSet-directory browse and does not create/delete a dynamic DataSet. + +The InformationReport receiver must be registered before any report-control write. The expected startup sequence is: + +- BRCB: whole-RCB Read -> `RptEna=true` -> whole-RCB Read -> whole-RCB Read -> one explicit `GI=true`. +- URCB: whole-RCB Read -> `Resv=true` when exposed -> `RptEna=true` -> whole-RCB Read -> whole-RCB Read -> one explicit `GI=true`. +- BRCB `ResvTms` is retry-only after a real direct-`RptEna` rejection; it is not the primary startup path. +- `GI=true` is a one-shot startup bootstrap only and is sent only after report routing is registered and activation/readback succeeds. +- GI rejection is a startup failure: unregister the monitor, disable `RptEna`, release any reservation touched by this client, and report failure instead of presenting an active monitor with unknown initial values. +- No network DataSet-directory browse, dynamic DataSet mutation, cyclic GI, or cyclic MMS process polling is allowed on the trusted-SCL report path. + +For the AA1E1F06R4 qualification target used by the golden comparison, expected evidence is: + +- BRCB family `Buffer`: a concrete live indexed instance is enabled without pre-reserving it; startup GI is accepted; Digital report data arrives. +- URCB family `Unbuffer`: a concrete live indexed instance is reserved when `Resv` is exposed, enabled, startup GI is accepted; Analog report data arrives. +- All 58 selected static DataSet members receive an initial value without waiting for a process change. +- Structured members such as total power factor remain schema/semantic projected rather than silently falling back to an unrelated scalar. + +## Gate 3 — steady state and cleanup + +After the startup initial image: + +- values must continue from InformationReport traffic/event updates; +- no periodic MMS process polling or repeated GI may be introduced; +- buffered backlog is applied in receive order so the canonical current-state plane retains the latest supplied value per signal while quality/timestamp-only updates do not erase the previous primary value; +- Stop/Close must disable every report enabled by this client; +- URCB reservation must be released when this client touched it; +- BRCB reservation must be released only when the compatibility fallback actually touched it; +- association disposal must happen after best-effort report cleanup, not instead of cleanup. + +## Evidence required for PASS -Primary activation expectation: +Physical success is not claimed by CI alone. Preserve the exact candidate SHA/artifact identity and collect: -- BRCB: whole-RCB Read -> `RptEna=true` -> whole-RCB Read -> whole-RCB Read. -- URCB: whole-RCB Read -> `Resv=true` when exposed -> `RptEna=true` -> two whole-RCB readbacks. -- BRCB `ResvTms` is retry-only after a real direct-`RptEna` rejection. -- GI is not sent implicitly. +1. ARSAS Diagnostic Export covering trusted-SCL association, RCB selection/activation, explicit startup GI, InformationReport reception and cleanup. +2. Matching Wireshark PCAP/PCAPNG for TCP port 102. +3. Screenshot or exported monitor evidence showing complete initial state and later event-driven updates. +4. Stop/Close evidence showing deterministic RCB release. -Physical success is not claimed by CI. JSON evidence plus Wireshark capture from the real IED are the acceptance evidence. +A PASS requires the software gates and the physical evidence to agree. If the wire capture contradicts UI/status text, the wire evidence is authoritative and the candidate remains blocked. diff --git a/engines/ARIEC61850.lock.json b/engines/ARIEC61850.lock.json index 07268d069..b5a25f5af 100644 --- a/engines/ARIEC61850.lock.json +++ b/engines/ARIEC61850.lock.json @@ -2,9 +2,14 @@ "schemaVersion": 1, "repository": "masarray/ARIEC61850", "ref": "main", - "commit": "d50e5bcb9fd428fe3d80ac72f8d4015a575cfda5", - "sourcePullRequest": 125, - "purpose": "Canonical protocol-only golden-wire SCL-assisted physical-trial pin. This exact SHA is built from the immutable ARSAS field-proven engine baseline recorded below and passed the dedicated convergence CI. It adds SCL-derived association identity, Domain/VMD reconciliation, bounded sequential initial FC-root Reads, trusted static-report activation without hidden full discovery or network DataSet-directory browsing, accepts quoted Edition-1/vendor OSI-AP-Title lexical forms such as \"1,1,1,999,1\" while preserving the raw SCL parameter for diagnostics, and preserves scoped DataSet/RCB authority including ReportControl indexed semantics for trusted-SCL live monitoring. For normal Play, ARSAS explicitly requests one startup GI only after the InformationReport receiver is registered, RCB activation succeeds, and two whole-RCB readbacks complete; BRCB direct RptEna remains primary with ResvTms retry-only, while URCB Resv precedes RptEna when exposed. Explicit GI acceptance is a startup success gate: rejection unregisters the monitor, disables RptEna, releases any touched reservation, and returns failure instead of a misleading active monitor with Unknown initial values. Safe-trial keeps GI disabled and performs no RCB writes. PR #125 is an evidence/trial lane and is not a merge authority for ARIEC main; ARSAS checks out this immutable SHA directly.", + "commit": "0023ef9a4373855497464ed3979e359c4041c95d", + "sourcePullRequest": 132, + "purpose": "Temporary ARSAS 1.6.36 integration pin for the exact green ARIEC convergence head. ARIEC .NET CI #603 passed on this SHA, including provenance/source/license verification, restore, build, tests, and diagnostics. The convergence preserves the trusted-SCL golden-wire contracts used by ARSAS: SCL-authoritative DataSet/RCB identity, LDevice ldName and ReportControl indexed semantics, quoted Edition-1/vendor OSI-AP-Title compatibility, Domain/VMD reconciliation, bounded sequential initial FC-root Reads, receiver-before-write report registration, URCB Resv -> RptEna, BRCB direct RptEna with ResvTms retry-only, two whole-RCB verification reads, one-shot GI after routing is registered, GI fail-closed cleanup, no cyclic process polling, no network DataSet-directory browse, and no dynamic DataSet mutation on the trusted-SCL path. The same convergence also locks buffered BRCB latest-state semantics through the canonical runtime value plane and preserves SCL RptEnabled@max only as diagnostics metadata; it is never authority to synthesize concrete runtime RCB names.", + "previousTrialPin": { + "commit": "d50e5bcb9fd428fe3d80ac72f8d4015a575cfda5", + "sourcePullRequest": 125, + "purpose": "Previous ARSAS 1.6.36 trusted-SCL golden-wire trial pin retained for explicit ancestry." + }, "fieldProvenBaseline": { "commit": "11ab2304482600c19ba979f4fc9021ddb46b9af9", "sourcePullRequest": 111,