Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
59 changes: 47 additions & 12 deletions docs/SCL_GOLDEN_WIRE_PHYSICAL_TRIAL.md
Original file line number Diff line number Diff line change
@@ -1,16 +1,21 @@
# Trusted SCL golden-wire physical trial

This document freezes the first field-test contract for the protocol-only ARSAS 1.6.36 trial lane.
This document freezes the physical qualification contract for the ARSAS 1.6.36 trusted-SCL reporting lane after ARIEC reporting/bootstrap convergence.

## Immutable engine authority

- ARSAS branch: `trial/scl-golden-wire-v1636`
- ARIEC61850 engine: `e41def0a2676efb8a143905798155f6bccc6f047`
- Field-proven reporting/control baseline preserved by the engine lock: `11ab2304482600c19ba979f4fc9021ddb46b9af9`
- Canonical ARSAS field-trial base: `trial/scl-golden-wire-v1636`
- Qualification branch: `integration/ariec-convergence-0023ef9-v1636`
- ARIEC61850 convergence engine: `0023ef9a4373855497464ed3979e359c4041c95d`
- ARIEC source PR: `#132`
- ARIEC exact-head .NET CI: `#603` PASS
- Field-proven reporting/control baseline retained by the engine lock: `11ab2304482600c19ba979f4fc9021ddb46b9af9`

The engine lock is the build-time authority. Do not substitute another ARIEC checkout while collecting qualification evidence.

## Gate 1 — read-only safe trial

Run the portable application with Wireshark capturing TCP port 102.
Run the exact portable candidate with Wireshark capturing TCP port 102.

```powershell
ARSAS-1.6.36-win-x64-portable.exe --scl-safe-trial "C:\path\IED.cid" "IEDNAME" "AP1" "192.168.x.x" 102
Expand All @@ -32,13 +37,43 @@ Only after Gate 1 association/read behavior is understood, open the same verifie

Trusted-SCL Play verifies the imported source SHA-256 before socket activity, keeps the SCL IED/AccessPoint association identity, performs Domain/VMD validation and bounded initial Reads, and does not silently fall back to cached association or full discovery.

For Static DataSet report-only mode, ordered DataSet membership and RCB identity remain SCL-authoritative in memory. The trusted path does not perform a network DataSet-directory browse or create/delete a dynamic DataSet.
For Static DataSet report-only mode, ordered DataSet membership and RCB identity remain SCL-authoritative in memory. The trusted path does not perform a network DataSet-directory browse and does not create/delete a dynamic DataSet.

The InformationReport receiver must be registered before any report-control write. The expected startup sequence is:

- BRCB: whole-RCB Read -> `RptEna=true` -> whole-RCB Read -> whole-RCB Read -> one explicit `GI=true`.
- URCB: whole-RCB Read -> `Resv=true` when exposed -> `RptEna=true` -> whole-RCB Read -> whole-RCB Read -> one explicit `GI=true`.
- BRCB `ResvTms` is retry-only after a real direct-`RptEna` rejection; it is not the primary startup path.
- `GI=true` is a one-shot startup bootstrap only and is sent only after report routing is registered and activation/readback succeeds.
- GI rejection is a startup failure: unregister the monitor, disable `RptEna`, release any reservation touched by this client, and report failure instead of presenting an active monitor with unknown initial values.
- No network DataSet-directory browse, dynamic DataSet mutation, cyclic GI, or cyclic MMS process polling is allowed on the trusted-SCL report path.

For the AA1E1F06R4 qualification target used by the golden comparison, expected evidence is:

- BRCB family `Buffer`: a concrete live indexed instance is enabled without pre-reserving it; startup GI is accepted; Digital report data arrives.
- URCB family `Unbuffer`: a concrete live indexed instance is reserved when `Resv` is exposed, enabled, startup GI is accepted; Analog report data arrives.
- All 58 selected static DataSet members receive an initial value without waiting for a process change.
- Structured members such as total power factor remain schema/semantic projected rather than silently falling back to an unrelated scalar.

## Gate 3 — steady state and cleanup

After the startup initial image:

- values must continue from InformationReport traffic/event updates;
- no periodic MMS process polling or repeated GI may be introduced;
- buffered backlog is applied in receive order so the canonical current-state plane retains the latest supplied value per signal while quality/timestamp-only updates do not erase the previous primary value;
- Stop/Close must disable every report enabled by this client;
- URCB reservation must be released when this client touched it;
- BRCB reservation must be released only when the compatibility fallback actually touched it;
- association disposal must happen after best-effort report cleanup, not instead of cleanup.

## Evidence required for PASS

Primary activation expectation:
Physical success is not claimed by CI alone. Preserve the exact candidate SHA/artifact identity and collect:

- BRCB: whole-RCB Read -> `RptEna=true` -> whole-RCB Read -> whole-RCB Read.
- URCB: whole-RCB Read -> `Resv=true` when exposed -> `RptEna=true` -> two whole-RCB readbacks.
- BRCB `ResvTms` is retry-only after a real direct-`RptEna` rejection.
- GI is not sent implicitly.
1. ARSAS Diagnostic Export covering trusted-SCL association, RCB selection/activation, explicit startup GI, InformationReport reception and cleanup.
2. Matching Wireshark PCAP/PCAPNG for TCP port 102.
3. Screenshot or exported monitor evidence showing complete initial state and later event-driven updates.
4. Stop/Close evidence showing deterministic RCB release.

Physical success is not claimed by CI. JSON evidence plus Wireshark capture from the real IED are the acceptance evidence.
A PASS requires the software gates and the physical evidence to agree. If the wire capture contradicts UI/status text, the wire evidence is authoritative and the candidate remains blocked.
11 changes: 8 additions & 3 deletions engines/ARIEC61850.lock.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,14 @@
"schemaVersion": 1,
"repository": "masarray/ARIEC61850",
"ref": "main",
"commit": "d50e5bcb9fd428fe3d80ac72f8d4015a575cfda5",
"sourcePullRequest": 125,
"purpose": "Canonical protocol-only golden-wire SCL-assisted physical-trial pin. This exact SHA is built from the immutable ARSAS field-proven engine baseline recorded below and passed the dedicated convergence CI. It adds SCL-derived association identity, Domain/VMD reconciliation, bounded sequential initial FC-root Reads, trusted static-report activation without hidden full discovery or network DataSet-directory browsing, accepts quoted Edition-1/vendor OSI-AP-Title lexical forms such as \"1,1,1,999,1\" while preserving the raw SCL parameter for diagnostics, and preserves scoped DataSet/RCB authority including ReportControl indexed semantics for trusted-SCL live monitoring. For normal Play, ARSAS explicitly requests one startup GI only after the InformationReport receiver is registered, RCB activation succeeds, and two whole-RCB readbacks complete; BRCB direct RptEna remains primary with ResvTms retry-only, while URCB Resv precedes RptEna when exposed. Explicit GI acceptance is a startup success gate: rejection unregisters the monitor, disables RptEna, releases any touched reservation, and returns failure instead of a misleading active monitor with Unknown initial values. Safe-trial keeps GI disabled and performs no RCB writes. PR #125 is an evidence/trial lane and is not a merge authority for ARIEC main; ARSAS checks out this immutable SHA directly.",
"commit": "0023ef9a4373855497464ed3979e359c4041c95d",
"sourcePullRequest": 132,
"purpose": "Temporary ARSAS 1.6.36 integration pin for the exact green ARIEC convergence head. ARIEC .NET CI #603 passed on this SHA, including provenance/source/license verification, restore, build, tests, and diagnostics. The convergence preserves the trusted-SCL golden-wire contracts used by ARSAS: SCL-authoritative DataSet/RCB identity, LDevice ldName and ReportControl indexed semantics, quoted Edition-1/vendor OSI-AP-Title compatibility, Domain/VMD reconciliation, bounded sequential initial FC-root Reads, receiver-before-write report registration, URCB Resv -> RptEna, BRCB direct RptEna with ResvTms retry-only, two whole-RCB verification reads, one-shot GI after routing is registered, GI fail-closed cleanup, no cyclic process polling, no network DataSet-directory browse, and no dynamic DataSet mutation on the trusted-SCL path. The same convergence also locks buffered BRCB latest-state semantics through the canonical runtime value plane and preserves SCL RptEnabled@max only as diagnostics metadata; it is never authority to synthesize concrete runtime RCB names.",
"previousTrialPin": {
"commit": "d50e5bcb9fd428fe3d80ac72f8d4015a575cfda5",
"sourcePullRequest": 125,
"purpose": "Previous ARSAS 1.6.36 trusted-SCL golden-wire trial pin retained for explicit ancestry."
},
"fieldProvenBaseline": {
"commit": "11ab2304482600c19ba979f4fc9021ddb46b9af9",
"sourcePullRequest": 111,
Expand Down
Loading