diff --git a/.github/workflows/iedscout-convergence-guard.yml b/.github/workflows/interoperability-convergence-guard.yml
similarity index 94%
rename from .github/workflows/iedscout-convergence-guard.yml
rename to .github/workflows/interoperability-convergence-guard.yml
index 9e977475f..01d86dfef 100644
--- a/.github/workflows/iedscout-convergence-guard.yml
+++ b/.github/workflows/interoperability-convergence-guard.yml
@@ -1,4 +1,4 @@
-name: IEDScout Convergence Guard
+name: Interoperability Convergence Guard
on:
pull_request:
@@ -10,20 +10,20 @@ on:
- "Directory.Build.targets"
- "scripts/enable-smart-discovery-capture.ps1"
- "engines/ARIEC61850.lock.json"
- - "evidence/iedscout-convergence-target.json"
- - "docs/IEDSCOUT_CONVERGENCE.md"
+ - "evidence/interoperability-convergence-target.json"
+ - "docs/INTEROPERABILITY_CONVERGENCE.md"
- "tests/ARSAS.Tests/CanonicalLiveSclExportRegressionTests.cs"
- - ".github/workflows/iedscout-convergence-guard.yml"
+ - ".github/workflows/interoperability-convergence-guard.yml"
- ".github/workflows/scl-interoperability-r7.yml"
workflow_dispatch:
concurrency:
- group: iedscout-convergence-${{ github.event.pull_request.number || github.ref }}
+ group: interoperability-convergence-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
jobs:
- iedscout-convergence-contract:
- name: iedscout-convergence-contract
+ interoperability-convergence-contract:
+ name: interoperability-convergence-contract
runs-on: windows-latest
steps:
@@ -47,7 +47,7 @@ jobs:
shell: pwsh
run: |
$lock = Get-Content .\ARSAS\engines\ARIEC61850.lock.json -Raw | ConvertFrom-Json
- $target = Get-Content .\ARSAS\evidence\iedscout-convergence-target.json -Raw | ConvertFrom-Json
+ $target = Get-Content .\ARSAS\evidence\interoperability-convergence-target.json -Raw | ConvertFrom-Json
if ($target.status -ne 'physical-retest-passed-merge-ready') {
throw "Convergence status changed unexpectedly: $($target.status)"
@@ -69,11 +69,13 @@ jobs:
-not [bool]$target.promotion.physicalRetestPassed) {
throw 'R10 physical-retest/merge gate drifted.'
}
- if ([int]$target.physicalReference.iedScoutCapture.associations -ne 1 -or
- [int]$target.physicalReference.iedScoutCapture.getVariableAccessAttributes -ne 119 -or
+ if ([int]$target.physicalReference.acceptedDiscoveryBudget.associations -ne 1 -or
+ [int]$target.physicalReference.acceptedDiscoveryBudget.maximumConfirmedMmsRequests -ne 417 -or
+ [int]$target.physicalReference.acceptedDiscoveryBudget.maximumGetVariableAccessAttributes -ne 119 -or
+ [int]$target.physicalReference.acceptedDiscoveryBudget.maximumReads -ne 156 -or
[int]$target.physicalReference.rejectedLegacyArsasCapture.associations -ne 2 -or
[int]$target.physicalReference.rejectedLegacyArsasCapture.getVariableAccessAttributes -lt 20000) {
- throw 'Physical IEDScout/legacy regression reference changed unexpectedly.'
+ throw 'Physical interoperability regression budget changed unexpectedly.'
}
@@ -304,7 +306,7 @@ jobs:
$singleFlight -notmatch 'DiscoverSmartSingleFlightAsync' -or
$singleFlight -notmatch 'DiscoverSmartAsync\(options, CancellationToken\.None\)' -or
$smartGva -notmatch 'GetVariableAccessAttributesSmartAsync') {
- throw 'P0 structural discovery freeze regressed away from the accepted IEDScout convergence path.'
+ throw 'P0 structural discovery freeze regressed away from the accepted interoperability convergence path.'
}
if ($lnParts -notmatch 'instanceStart' -or
@@ -322,4 +324,4 @@ jobs:
throw 'Canonical IEC model / SCL semantic authority regressed.'
}
- Write-Host 'IEDScout convergence contract PASS.'
+ Write-Host 'Interoperability convergence contract PASS.'
diff --git a/.github/workflows/release-windows.yml b/.github/workflows/release-windows.yml
index 3a2e1c271..e9f9d89ad 100644
--- a/.github/workflows/release-windows.yml
+++ b/.github/workflows/release-windows.yml
@@ -46,6 +46,12 @@ jobs:
id: release
shell: powershell
run: |
+ if ($env:GITHUB_EVENT_NAME -eq "workflow_dispatch" -and
+ "${{ inputs.publish_release }}" -eq "true" -and
+ $env:GITHUB_REF -ne "refs/heads/main") {
+ throw "Manual publication is allowed only from the main branch."
+ }
+
if ($env:GITHUB_EVENT_NAME -eq "workflow_dispatch") {
$rawVersion = "${{ inputs.version }}"
}
@@ -160,6 +166,10 @@ jobs:
with:
python-version: "3.12"
+ - name: Verify qualified release source authority
+ shell: powershell
+ run: python .\ArIED61850Tester\scripts\verify-qualified-release-source.py
+
- name: Verify source and licensing boundaries
shell: powershell
run: .\ArIED61850Tester\scripts\verify-source-clean.ps1
@@ -426,7 +436,11 @@ jobs:
ArIED61850Tester/dist/ARSAS-Windows-x64-PROVENANCE.json
- name: Create or update GitHub Release
- if: github.ref_type == 'tag' || github.ref == 'refs/heads/main' || inputs.publish_release == true
+ if: >-
+ github.ref_type == 'tag' ||
+ (github.event_name == 'workflow_dispatch' &&
+ inputs.publish_release == true &&
+ github.ref == 'refs/heads/main')
shell: powershell
env:
GH_TOKEN: ${{ github.token }}
@@ -467,7 +481,11 @@ jobs:
if ($LASTEXITCODE -ne 0) { throw "Failed to create GitHub Release." }
- name: Record verified release publication
- if: github.ref_type == 'tag' || github.ref == 'refs/heads/main' || inputs.publish_release == true
+ if: >-
+ github.ref_type == 'tag' ||
+ (github.event_name == 'workflow_dispatch' &&
+ inputs.publish_release == true &&
+ github.ref == 'refs/heads/main')
shell: powershell
env:
GH_TOKEN: ${{ github.token }}
diff --git a/.github/workflows/scl-interoperability-r7.yml b/.github/workflows/scl-interoperability-r7.yml
index 17a436da3..ae92b3c0c 100644
--- a/.github/workflows/scl-interoperability-r7.yml
+++ b/.github/workflows/scl-interoperability-r7.yml
@@ -14,8 +14,8 @@ on:
- "MainWindow.xaml.cs"
- "Services/CanonicalSclReloadValidator.cs"
- "engines/ARIEC61850.lock.json"
- - "evidence/iedscout-convergence-target.json"
- - "docs/IEDSCOUT_CONVERGENCE.md"
+ - "evidence/interoperability-convergence-target.json"
+ - "docs/INTEROPERABILITY_CONVERGENCE.md"
- "tests/ARSAS.Tests/CanonicalLiveSclExportRegressionTests.cs"
- "tests/ARSAS.Tests/CanonicalSclReloadValidatorTests.cs"
- ".github/workflows/scl-interoperability-r7.yml"
@@ -52,7 +52,7 @@ jobs:
shell: pwsh
run: |
$lock = Get-Content .\ARSAS\engines\ARIEC61850.lock.json -Raw | ConvertFrom-Json
- $convergence = Get-Content .\ARSAS\evidence\iedscout-convergence-target.json -Raw | ConvertFrom-Json
+ $convergence = Get-Content .\ARSAS\evidence\interoperability-convergence-target.json -Raw | ConvertFrom-Json
if ($lock.repository -ne 'masarray/ARIEC61850' -or
$lock.commit -notmatch '^[0-9a-f]{40}$') {
throw 'Invalid ARIEC61850 R7 lock.'
@@ -71,7 +71,7 @@ jobs:
[bool]$convergence.promotion.physicalRetestRequired -or
-not [bool]$convergence.promotion.mergeAllowedAfterPhysicalRetest -or
-not [bool]$convergence.promotion.physicalRetestPassed) {
- throw 'IEDScout convergence single-source-of-truth does not match the physically proven merged-engine + ARSAS #324 authority.'
+ throw 'Interoperability convergence authority does not match the physically proven merged-engine + ARSAS #324 authority.'
}
if ([int]$lock.sourcePullRequest -notin @(134, 135)) {
throw "Unexpected R7 engine source PR: $($lock.sourcePullRequest)"
@@ -111,7 +111,7 @@ jobs:
$cdcInference = Get-Content .\ARIEC61850\src\AR.Iec61850\Discovery\CdcInferenceEngine.cs -Raw
$consumer = Get-Content .\ARSAS\Services\NativeIec61850Client.CanonicalModel.cs -Raw
$capture = Get-Content .\ARSAS\Services\NativeIec61850Client.SmartDiscoveryCapture.cs -Raw
- $convergence = Get-Content .\ARSAS\evidence\iedscout-convergence-target.json -Raw | ConvertFrom-Json
+ $convergence = Get-Content .\ARSAS\evidence\interoperability-convergence-target.json -Raw | ConvertFrom-Json
$buildTargets = Get-Content .\ARSAS\Directory.Build.targets -Raw
$lifecycle = Get-Content .\ARSAS\Services\NativeIec61850Client.SmartDiscoveryLifecycle.cs -Raw
$sclClient = Get-Content .\ARSAS\Services\NativeIec61850Client.SclAssisted.cs -Raw
@@ -175,16 +175,16 @@ jobs:
$capture -match 'DiscoverDomainVariableTypeTreeNamesAsync' -or
$capture -match 'AddAdaptiveLogicalNodeSiblingProbeSignalsAsync' -or
$capture -match 'EnrichEngineeringUnitsAsync') {
- throw 'IEDScout convergence source contract regressed: smart structure-first discovery or semantic SCL authority is missing, or a forbidden legacy browse path returned.'
+ throw 'Interoperability convergence source contract regressed: smart structure-first discovery or semantic SCL authority is missing, or a forbidden legacy browse path returned.'
}
- if ([int]$convergence.physicalReference.iedScoutCapture.associations -ne 1 -or
+ if ([int]$convergence.physicalReference.acceptedDiscoveryBudget.associations -ne 1 -or
[int]$convergence.physicalReference.rejectedLegacyArsasCapture.associations -ne 2 -or
-not [bool]$convergence.discoveryAcceptance.exactlyOneAssociation -or
-not [bool]$convergence.discoveryAcceptance.supplementalLegacyAssociationForbidden -or
-not [bool]$convergence.sclAcceptance.reopenInArsasRequired -or
-not [bool]$convergence.sclAcceptance.physicalReconnectRequired) {
- throw 'IEDScout physical acceptance target was weakened.'
+ throw 'Interoperability physical acceptance target was weakened.'
}
if ($consumer -notmatch 'LiveIedCanonicalModelBuilder\.Build\(model, communication, initialRead\)' -or
@@ -276,7 +276,7 @@ jobs:
throw "Portable EXE smoke test failed: $($process.ExitCode)"
}
- $convergencePath = ".\ARSAS\evidence\iedscout-convergence-target.json"
+ $convergencePath = ".\ARSAS\evidence\interoperability-convergence-target.json"
$convergenceHash = (Get-FileHash $convergencePath -Algorithm SHA256).Hash.ToLowerInvariant()
$convergence = Get-Content $convergencePath -Raw | ConvertFrom-Json
@@ -304,8 +304,8 @@ jobs:
path: |
ARSAS\dist\ARSAS-*-win-x64-portable.exe
ARSAS\dist\R7-SCL-INTEROP-BUILD.txt
- ARSAS\evidence\iedscout-convergence-target.json
- ARSAS\docs\IEDSCOUT_CONVERGENCE.md
+ ARSAS\evidence\interoperability-convergence-target.json
+ ARSAS\docs\INTEROPERABILITY_CONVERGENCE.md
ARSAS\TestResults\*.trx
if-no-files-found: error
retention-days: 14
diff --git a/.github/workflows/smart-discovery-mainline-readiness.yml b/.github/workflows/smart-discovery-mainline-readiness.yml
index f0b4f05a4..687e9b672 100644
--- a/.github/workflows/smart-discovery-mainline-readiness.yml
+++ b/.github/workflows/smart-discovery-mainline-readiness.yml
@@ -17,7 +17,7 @@ jobs:
- name: Verify R10 physical convergence authority
shell: powershell
run: |
- $target = Get-Content .\evidence\iedscout-convergence-target.json -Raw | ConvertFrom-Json
+ $target = Get-Content .\evidence\interoperability-convergence-target.json -Raw | ConvertFrom-Json
$lock = Get-Content .\engines\ARIEC61850.lock.json -Raw | ConvertFrom-Json
if ($target.status -ne 'physical-retest-passed-merge-ready' -or
diff --git a/.github/workflows/smart-discovery-post-merge-production.yml b/.github/workflows/smart-discovery-post-merge-production.yml
index b74229e10..e1836ea0e 100644
--- a/.github/workflows/smart-discovery-post-merge-production.yml
+++ b/.github/workflows/smart-discovery-post-merge-production.yml
@@ -19,7 +19,7 @@ jobs:
- name: Verify R10 physical convergence authority
shell: powershell
run: |
- $target = Get-Content .\evidence\iedscout-convergence-target.json -Raw | ConvertFrom-Json
+ $target = Get-Content .\evidence\interoperability-convergence-target.json -Raw | ConvertFrom-Json
$lock = Get-Content .\engines\ARIEC61850.lock.json -Raw | ConvertFrom-Json
if ($target.status -ne 'physical-retest-passed-merge-ready' -or
@@ -86,7 +86,7 @@ jobs:
shell: powershell
run: |
New-Item -ItemType Directory -Force .\TestResults | Out-Null
- $target = Get-Content .\evidence\iedscout-convergence-target.json -Raw | ConvertFrom-Json
+ $target = Get-Content .\evidence\interoperability-convergence-target.json -Raw | ConvertFrom-Json
[ordered]@{
schemaVersion = 1
sourceCommit = $env:GITHUB_SHA
diff --git a/.release/qualified-source.json b/.release/qualified-source.json
new file mode 100644
index 000000000..109bca827
--- /dev/null
+++ b/.release/qualified-source.json
@@ -0,0 +1,22 @@
+{
+ "schemaVersion": 1,
+ "authority": "qualified-runtime-lineage",
+ "qualificationManifest": ".release/qualified-source.json",
+ "fieldQualifiedSource": {
+ "sourcePullRequest": 324,
+ "sourceHeadCommit": "b0f25569a398c7bbdc3a3a34409dbd74ebf49444",
+ "sourceMergeCommit": "2b8e8adfd019bd087dc338dcc32bffefec53370f",
+ "sourceTree": "cccb50607161f8637e597b43d71038ffd4becfdc",
+ "workflowRunId": 35412542175,
+ "artifactId": 10575075419,
+ "portableFileName": "ARSAS-1.6.37-win-x64-portable.exe",
+ "portableSha256": "6805b878f91f3d526cc50f3e81e3eb9a1f72500217dacc8921e50bdc349c5fcc",
+ "portableSizeBytes": 78383289
+ },
+ "currentReleaseCandidate": {
+ "derivation": "Field-qualified runtime with implementation-neutral identifiers and release-governance changes only.",
+ "fingerprintAlgorithm": "sha256-path-null-content-null-v1",
+ "releaseSensitiveFileCount": 506,
+ "releaseSensitiveFingerprint": "b86663f358499f656bcddd52e38dbe08df31b1192fae4136889677572dabada5"
+ }
+}
diff --git a/.release/windows.json b/.release/windows.json
index 4e80cd3c5..4988d0a91 100644
--- a/.release/windows.json
+++ b/.release/windows.json
@@ -2,6 +2,7 @@
"version": "1.6.38",
"channel": "stable",
"platform": "windows-x64",
+ "qualificationManifest": ".release/qualified-source.json",
"primaryAsset": "ARSAS-Windows-x64-Setup.exe",
"publicationRequest": 27
}
diff --git a/CHANGELOG.md b/CHANGELOG.md
index 0b6431853..1309e92f6 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -4,6 +4,24 @@ Notable public changes to ARSAS are recorded here. Application releases must ide
## Unreleased
+## 1.6.38 — 2026-09-19
+
+### Added
+
+- Public stable Windows release for the physically verified R10 discovery/SCL convergence baseline.
+- Release evidence now includes verified installer and portable artifacts, SHA-256 checksums, SPDX 2.3 SBOM, provenance metadata, and artifact attestations.
+
+### Changed
+
+- Trusted-SCL reuse for generated Edition 2 IID and Edition 1 ICD now preserves exact-case value identity with `cacheLoss=0` on both editions.
+- Multi-DO CF hydration uses exact DO-scoped structured Reads instead of cross-DO positional assumptions.
+- Post-merge and mainline CI gates validate the accepted R10 physical authority and immutable engine source tree.
+
+### Fixed
+
+- Both generated editions reopen and reconnect with 32/32 MMS domains, all planned initial Reads successful, `projectionErrors=0`, 58/58 report-backed runtime points, zero final unresolved runtime points, actual InformationReport traffic, and zero cyclic MMS process polling on the accepted path.
+- Release automation now publishes the verified stable package from the exact mainline release commit.
+
## 1.6.37 — 2026-09-16
### Added
diff --git a/ENGINE_COMPATIBILITY.md b/ENGINE_COMPATIBILITY.md
index 5ca1fa149..9e9695b44 100644
--- a/ENGINE_COMPATIBILITY.md
+++ b/ENGINE_COMPATIBILITY.md
@@ -1,10 +1,13 @@
# ARIEC61850 Engine Compatibility
-ARSAS 1.6.19 is an application-only repository. It compiles against the separately maintained ARIEC61850 source projects and uses engine-owned contracts for MMS, reporting, GOOSE, Sampled Values, file services, control, SCL workspace services, discovery, and diagnostics.
+ARSAS **1.6.38** is the Windows application and workflow layer. It compiles
+against the separately maintained ARIEC61850 source projects for MMS, reporting,
+GOOSE, Sampled Values, file services, control, SCL workspace services,
+discovery, diagnostics, and reusable protocol contracts.
## Immutable integration baseline
-The reviewed engine revision used by CI and packaging is stored in:
+The exact engine revision used by CI and stable packaging is stored in:
```text
engines/ARIEC61850.lock.json
@@ -15,24 +18,52 @@ Current baseline:
```text
repository: masarray/ARIEC61850
ref: main
-commit: 0f8453182957900bc6d91287fb8177c8d9762188
-source PR: #45
+merged commit: 648124097621046f5f127ceb1cf853fea54db730
+source PR: #135
+physical-tested commit: 9935d6902d786cc69b299260fe36b835944d5e81
+merged/tested source-tree SHA: 1cf7e08f333f24994625e8fe8416dbd0a16195b1
```
-CI fetches the exact 40-character commit and checks it out detached. A temporary feature branch is not part of the reproducible build identity.
+The physical-tested commit and merged engine authority resolve to the identical
+source tree. ARSAS release packaging therefore consumes the reviewed merged
+engine tree without substituting a different implementation.
+
+## ARSAS 1.6.38 acceptance
+
+The R10 acceptance line requires the engine/application pair to preserve:
+
+- one bounded structural-discovery association;
+- exact LD/LN/DO/SDO/DA/FC identity;
+- exact-case IEC 61850 value identity;
+- DO-scoped CF hydration for multi-DO structures;
+- canonical Edition 2 / Edition 1 SCL round trip;
+- 32/32 trusted-SCL MMS domain reconciliation;
+- zero failed planned initial Reads;
+- `projectionErrors=0`;
+- `cacheLoss=0`;
+- 58/58 report-backed runtime points;
+- zero final unresolved runtime points;
+- actual InformationReport traffic;
+- zero cyclic MMS process polling in the accepted report-backed path.
+
+The detailed physical contract is documented in
+[Interoperability convergence](docs/INTEROPERABILITY_CONVERGENCE.md).
## Required engine areas
-The build verifies the presence of application-consumed contracts for:
+Build and release validation requires the application-consumed contracts for:
- Smart Control and `CommandTermination`;
- SCL workspace comparison and schema-aware export;
- typed DataSet binding and stable member order;
+- report-control discovery and logical/runtime identity projection;
- GOOSE parsing and process-bus supervision;
-- Sampled Values parsing, generic payload inspection, timebase resolution, sample-counter tracking, and Npcap capture;
-- file-service, discovery, reporting, and diagnostic services referenced by the application project.
+- Sampled Values parsing, generic payload inspection, timebase resolution,
+ sample-counter tracking, and Npcap capture;
+- MMS file-service, discovery, reporting, and diagnostic services.
-If a required contract is missing, CI and local builds fail explicitly rather than silently degrading the operator workflow.
+If a required contract is missing, CI and local builds fail explicitly instead
+of silently degrading the engineering workflow.
## Recommended sibling layout
@@ -55,14 +86,24 @@ dotnet build .\ArIED61850Tester.sln -c Release --no-restore
dotnet test .\tests\ARSAS.Tests\ARSAS.Tests.csproj -c Release --no-build --no-restore
```
-Another reviewed engine checkout may be selected with the existing MSBuild properties or environment variables, but release evidence must record the exact commit and must not imply compatibility with an unreviewed moving branch.
+Another reviewed engine checkout may be selected with the existing MSBuild
+properties or environment variables, but release evidence must record the exact
+commit and must not imply compatibility with an unreviewed moving branch.
## Source and package boundary
-ARSAS does not overwrite or vendor the ARIEC61850 source repository. A published Windows package may contain compiled engine assemblies as part of the combined GPL community application, while reusable protocol implementation remains owned and tested in ARIEC61850.
+ARSAS does not copy the ARIEC61850 source tree into this repository. Stable
+Windows packages contain the compiled engine components required by the
+combined GPL community application, while reusable protocol implementation
+continues to be maintained and tested in ARIEC61850.
-Control operations intentionally have no generic MMS-write fallback. The native engine must provide a usable control descriptor and sequence contract before ARSAS enables command dispatch.
+Control operations intentionally have no generic MMS-write fallback. The engine
+must provide a usable control descriptor and sequence contract before ARSAS
+enables command dispatch.
## Claim boundary
-A successful build and regression suite proves compatibility with the pinned software revision. It does not establish formal IEC 61850 conformance, calibrated measurement accuracy, universal device interoperability, switching authority, cybersecurity approval, or functional-safety certification.
+A successful build and regression suite proves compatibility with the pinned
+software revision. It does not establish formal IEC 61850 conformance,
+calibrated measurement accuracy, universal device interoperability, switching
+authority, cybersecurity approval, or functional-safety certification.
diff --git a/MainWindow.Demo.cs b/MainWindow.Demo.cs
index 283c106de..91b3c07a0 100644
--- a/MainWindow.Demo.cs
+++ b/MainWindow.Demo.cs
@@ -198,7 +198,7 @@ private void BuildDemoDevicesAndLivePoints()
{
DeviceId = $"demo-{deviceIndex + 1:00}-{spec.Name.ToLowerInvariant()}",
Name = spec.Name,
- IdentitySource = $"Live MMS discovery • SIPROTEC-class {spec.Description}",
+ IdentitySource = $"Live MMS discovery • protection-IED class {spec.Description}",
LogicalDeviceSummary = spec.ModelSummary,
IpAddress = spec.IpAddress,
Port = 102,
diff --git a/MainWindow.IoTesting.AutoConnect.cs b/MainWindow.IoTesting.AutoConnect.cs
index cc05bd11d..029da5eb7 100644
--- a/MainWindow.IoTesting.AutoConnect.cs
+++ b/MainWindow.IoTesting.AutoConnect.cs
@@ -198,7 +198,7 @@ void ReportProgress(string message)
{
// The imported ARIEC SCL workspace already owns the complete static
// DataSet identity. Connected reconciliation can perform a large exact-read
- // pass and used to hold this SIPROTEC FAT preparation for about one minute.
+ // pass and used to hold this GENERIC_IED FAT preparation for about one minute.
// Explicit Re-scan remains the design-versus-live comparison action.
IoTestReconciliationCache.Invalidate(device);
ReportProgress(reuseSharedSclAcquisition
diff --git a/Models/SignalDefinition.cs b/Models/SignalDefinition.cs
index e37722925..a7f8ca25e 100644
--- a/Models/SignalDefinition.cs
+++ b/Models/SignalDefinition.cs
@@ -812,7 +812,7 @@ public static bool IsCoreScadaSignal(string reference, string logicalNodeClass,
if ((cls is "CSWI" or "XCBR" or "XSWI") && r.EndsWith(".pos.stval"))
return true;
- // Normal measurement groups use cVal. Siemens OperationalValues groups expose
+ // Normal measurement groups use cVal. generic OperationalValues groups expose
// the directly readable instantaneous leaf as instCVal, while cVal can reject
// direct MMS reads even though the parent DO is visible in an engineering tool.
if (cls is "MMXU" or "MMXN")
diff --git a/RAPID_FILTER_FLAT_GRID_UX_AUDIT.md b/RAPID_FILTER_FLAT_GRID_UX_AUDIT.md
index 08ce7c722..e8a3b3ed3 100644
--- a/RAPID_FILTER_FLAT_GRID_UX_AUDIT.md
+++ b/RAPID_FILTER_FLAT_GRID_UX_AUDIT.md
@@ -2,7 +2,7 @@
## Field findings
-The latest OLSF/Siemens-style live test showed that the control behavior is now usable, but dense commissioning workflows still contain avoidable visual and navigation friction:
+The latest OLSF/generic-style live test showed that the control behavior is now usable, but dense commissioning workflows still contain avoidable visual and navigation friction:
- Selection Wizard column filters keep showing `Filter…` while the field has keyboard focus.
- The IEC Command Panel still exposes Details/Technical details affordances that are no longer part of the fast control workflow.
diff --git a/README.md b/README.md
index a1aa9b455..4ab2f3136 100644
--- a/README.md
+++ b/README.md
@@ -7,7 +7,7 @@
**Discover · Monitor · Test IO Lists · Diagnose · Generate SCL · Export Evidence**
-ARSAS is an open-source Windows IEC 61850 engineering workstation for FAT, SAT, commissioning, troubleshooting, and multi-vendor integration. Start from an approved IED endpoint, an SCL file, or an IO List workbook; inspect what the device actually exposes; and preserve the result as attributable engineering evidence.
+ARSAS is an open-source Windows IEC 61850 engineering workstation for FAT, SAT, commissioning, troubleshooting, and multi-device integration. Start from an approved IED endpoint, an SCL file, or an IO List workbook; inspect what the device actually exposes; and preserve the result as attributable engineering evidence.
[](https://github.com/masarray/arsas/actions/workflows/build.yml)
[](https://masarray.github.io/arsas/)
@@ -33,10 +33,19 @@ ARSAS is an open-source Windows IEC 61850 engineering workstation for FAT, SAT,
Choose Engineering for live IEC 61850 discovery or IO List FAT for resumable, reviewable test evidence.
-> **Current ARSAS application version: v1.6.37.** The current source line aligns live RCB instance presentation with concrete runtime slots exposed by the connected IED while preserving canonical source-backed ReportControl identity, and makes in-process COMTRADE Phasor, Harmonics, and distance Locus interaction smoother without changing authoritative native engineering values.
+> **Current ARSAS application version: v1.6.38.** This stable line carries the physically verified R10 discovery/SCL convergence baseline: generated Edition 2 and Edition 1 SCL reopen and reconnect with 32/32 domains, all planned initial Reads successful, `projectionErrors=0`, `cacheLoss=0`, 58/58 report-backed runtime points, actual InformationReport traffic, and zero cyclic MMS process polling on the accepted path.
>
> **Published-package boundary:** download version, file size, SHA-256, SBOM, provenance, and attestation claims remain tied to the latest actually published stable GitHub Release. `main` moving to a newer application version does not by itself advance public binary evidence.
+## What changed in v1.6.38
+
+- **Physically verified R10 convergence** — generated Edition 2 IID and Edition 1 ICD reopen in ARSAS, reconnect through trusted SCL, reconcile 32/32 MMS domains, and complete every planned initial Read.
+- **Lossless trusted-SCL value pipeline** — both editions reach `projectionErrors=0` and `cacheLoss=0`; exact-case IEC 61850 paths remain distinct through projection, caching, canonical evidence, and SCL value targeting.
+- **Report-backed runtime acquisition** — all 58 static DataSet members resolve to 58/58 runtime points, final unresolved points are zero, actual InformationReport traffic is observed, and cyclic MMS process polling remains zero on the accepted path.
+- **Immutable engine authority** — the physical-tested engine head and merged engine commit resolve to the same source tree, preserving the tested behavior after merge.
+- **Verified Windows publication** — portable and installer smoke tests pass; the stable release includes SHA-256 checksums, SPDX SBOM, provenance metadata, and artifact attestations.
+- **Release scope discipline** — later save-enrichment snapshot reuse remains outside this stable release.
+
## What changed in v1.6.37
- **Concrete live RCB instances** — Legacy SAS RCB selection presents concrete instances such as `Buffer01`, `Buffer02`, `Unbuffer01`, and `Unbuffer02` when the connected IED actually exposes them, without adding duplicate logical placeholder rows.
@@ -69,7 +78,7 @@ ARSAS is an open-source Windows IEC 61850 engineering workstation for FAT, SAT,
| Engineering problem | ARSAS response |
|---|---|
-| Vendor CID or ICD is missing, outdated, or rejected. | Perform complete live MMS discovery and generate a schema-aware **Edition 2 IID** or **Edition 1 ICD** with companion evidence. |
+| Device CID or ICD is missing, outdated, or rejected. | Perform complete live MMS discovery and generate a schema-aware **Edition 2 IID** or **Edition 1 ICD** with companion evidence. |
| Reporting setup consumes the test window before values appear. | Read an immediate MMS image, prefer verified BRCB/URCB coverage, recover bounded gaps where permitted, and keep fallback acquisition visible. |
| A multi-IED test loses device ownership and diagnostics. | Maintain an independent association, model, monitoring state, events, files, control context, and diagnostics for every IED. |
| A FAT team must rebuild IO List evidence manually. | Import the approved workbook, bind exact IEC 61850 references, record ordered **OFF → ON → OFF** evidence, and export Excel, native PDF, or a resumable `.arsas` project. |
diff --git a/ROADMAP.md b/ROADMAP.md
index 14046d336..8b93f9a75 100644
--- a/ROADMAP.md
+++ b/ROADMAP.md
@@ -52,12 +52,12 @@ ARSAS is the application and workflow layer. Protocol implementation belongs in
- Recursive and bounded directory browsing.
- Capability discovery and transparent negative responses.
- Download progress, cancellation, timeout, and retry boundaries.
-- COMTRADE set recognition (`.cfg`, `.dat`, `.hdr`, `.inf`, vendor companions).
+- COMTRADE set recognition (`.cfg`, `.dat`, `.hdr`, `.inf`, device companion files).
- Safe local naming and duplicate handling.
- Transfer evidence export and sanitized diagnostics.
- Automated engine tests for directory, open, read, close, and failure paths.
-**Definition of done:** fault records can be retrieved from representative multi-vendor test devices without vendor-specific logic in the ARSAS UI layer.
+**Definition of done:** fault records can be retrieved from representative representative test devices without device-specific logic in the ARSAS UI layer.
## Milestone 2 — Production-grade Sampled Values
diff --git a/Services/IoTesting/IoTestReferenceMatcher.cs b/Services/IoTesting/IoTestReferenceMatcher.cs
index 063190a01..80a4a4edf 100644
--- a/Services/IoTesting/IoTestReferenceMatcher.cs
+++ b/Services/IoTesting/IoTestReferenceMatcher.cs
@@ -5,7 +5,7 @@ namespace ArIED61850Tester.Services.IoTesting;
///
/// Conservative IEC 61850 reference matcher used by FAT binding. It understands
/// equivalent MMS/SCL spellings (IED-prefixed domains, the DIGSI Application display
-/// wrapper, functional-constraint tokens inside MMS references, verified Siemens
+/// wrapper, functional-constraint tokens inside MMS references, verified generic
/// functional-group/LN display folders, and exact unique object-leaf recovery for
/// incomplete imported references) but never uses fuzzy text similarity.
///
diff --git a/Services/SclWorkspaceSignalMapper.cs b/Services/SclWorkspaceSignalMapper.cs
index c82322aae..4da5013cf 100644
--- a/Services/SclWorkspaceSignalMapper.cs
+++ b/Services/SclWorkspaceSignalMapper.cs
@@ -42,7 +42,7 @@ public static IReadOnlyList BuildSignals(SclIedWorkspace works
// First apply the normal presentation policy, then merge ARIEC's mandatory
// DataSet inventory. Doing the merge after the visibility filter is deliberate:
- // an unresolved object-level FCD (common in Siemens CID files) may have no leaf
+ // an unresolved object-level FCD (common in generic CID files) may have no leaf
// DataAttribute yet, but membership in a static DataSet is sufficient authority
// for the member to exist as a Signal Selection row.
var visibleSignals = signals
diff --git a/Services/SntpClockService.cs b/Services/SntpClockService.cs
index 834146f5d..8532f6e3d 100644
--- a/Services/SntpClockService.cs
+++ b/Services/SntpClockService.cs
@@ -228,8 +228,8 @@ private async Task StartCoreAsync(SntpNetworkBinding binding, CancellationToken
SetState(
SntpClockServiceState.Serving,
binding.DirectedBroadcast == null
- ? $"SNTP UDP server active on {binding.LocalAddress}:123 with SIPROTEC compatibility stratum {_profile.Stratum}. No usable directed broadcast is available."
- : $"SNTP UDP server active on {binding.LocalAddress}:123 with SIPROTEC compatibility stratum {_profile.Stratum}; Mode 5 broadcast targets {binding.DirectedBroadcast}:123.");
+ ? $"SNTP UDP server active on {binding.LocalAddress}:123 with protection-IED compatibility stratum {_profile.Stratum}. No usable directed broadcast is available."
+ : $"SNTP UDP server active on {binding.LocalAddress}:123 with protection-IED compatibility stratum {_profile.Stratum}; Mode 5 broadcast targets {binding.DirectedBroadcast}:123.");
_receiveTask = ReceiveLoopAsync(udp, serviceCancellation.Token);
_broadcastTask = BroadcastLoopAsync(binding, serviceCancellation.Token);
diff --git a/Services/SntpPacket.cs b/Services/SntpPacket.cs
index 0aae4c6fb..a6b6ada5c 100644
--- a/Services/SntpPacket.cs
+++ b/Services/SntpPacket.cs
@@ -170,15 +170,15 @@ public readonly record struct SntpClientRequest(
public sealed record SntpServerProfile
{
///
- /// SIPROTEC compatibility advertisement used by ARSAS commissioning Clock Sync.
- /// Field experience with SIPROTEC requires a trusted-looking low stratum; stratum 2
+ /// protection-IED compatibility advertisement used by ARSAS commissioning Clock Sync.
+ /// Field experience with GENERIC_IED requires a trusted-looking low stratum; stratum 2
/// is deliberately used instead of stratum 1 so ARSAS does not claim to be a primary
/// GPS/PTP/atomic reference. ReferenceId remains LOCL and diagnostics state that the
/// laptop clock is a local commissioning source, not a traceable grandmaster.
///
- public const byte SiprotecCompatibilityStratum = 2;
+ public const byte GenericIedCompatibilityStratum = 2;
- public byte Stratum { get; init; } = SiprotecCompatibilityStratum;
+ public byte Stratum { get; init; } = GenericIedCompatibilityStratum;
public byte LeapIndicator { get; init; }
public sbyte PollExponent { get; init; } = 6;
public sbyte PrecisionExponent { get; init; } = -10;
diff --git a/docs/FAT_V2_IMPLEMENTATION_PLAN.md b/docs/FAT_V2_IMPLEMENTATION_PLAN.md
index 2db841587..bd3a870bb 100644
--- a/docs/FAT_V2_IMPLEMENTATION_PLAN.md
+++ b/docs/FAT_V2_IMPLEMENTATION_PLAN.md
@@ -93,7 +93,7 @@ Required regressions:
- identical duplicate source collapses safely;
- conflicting IED/AP sources block;
- fingerprint is order-independent;
-- Siemens-like 36 ST + 22 MX fixture remains 58/58.
+- generic-like 36 ST + 22 MX fixture remains 58/58.
### P4 — FAT workspace UX
diff --git a/docs/IEDSCOUT_CONVERGENCE.md b/docs/IEDSCOUT_CONVERGENCE.md
deleted file mode 100644
index 673294a00..000000000
--- a/docs/IEDSCOUT_CONVERGENCE.md
+++ /dev/null
@@ -1,160 +0,0 @@
-# IEDScout Convergence Contract
-
-## Product target
-
-ARSAS targets IEDScout-equivalent IEC 61850 engineering semantics with lower wire cost where possible:
-
-1. one accepted MMS association and bounded structure-first discovery;
-2. a complete canonical model with exact LN/DO/SDO/DA/FC identity;
-3. Edition 2 IID / Edition 1 ICD that can be reopened by ARSAS, reconnect to the same relay, hydrate values without full discovery, and run configured static reporting.
-
-The machine-readable authority is `evidence/iedscout-convergence-target.json`.
-
-## Merged proven baseline
-
-The physical R10 baseline was tested with:
-
-- ARSAS `eb8eb13d491f9aa265205852b8a4bab07af440ff`;
-- ARIEC61850 tested head `9935d6902d786cc69b299260fe36b835944d5e81`;
-- ARIEC61850 merged-main commit `648124097621046f5f127ceb1cf853fea54db730`.
-
-The tested engine head and merged-main commit have the identical tree SHA
-`1cf7e08f333f24994625e8fe8416dbd0a16195b1`.
-
-Merged engine provenance:
-
-- PR #134 → main merge `e6779ff74e5716af4fcfc3dc926dae0567b3cdb0`: Smart Discovery performance authority.
-- PR #135 → main merge `648124097621046f5f127ceb1cf853fea54db730`: canonical model, SCL interoperability, P1/P2 value pipeline.
-- ARSAS PR #324: consumer integration and physical R10 proof.
-
-## P0 — structural discovery freeze
-
-Contract: `P0-R9-STRUCTURAL`.
-
-AA1E1F06R4 physical reference is locked at one association, 323 confirmed MMS
-requests, 138 GetNameList, 119 GetVariableAccessAttributes, 2
-GetNamedVariableListAttributes and 64 Reads, while preserving 32 LD / 119 LN /
-860 top-level DO / 906 DO+SDO / 4925 scalar leaves / 2 DataSets / 58 FCDA / 32
-logical ReportControls / 1 SettingControl.
-
-The same-relay IEDScout comparison remains about 417 confirmed requests, 119 GVA
-and 156 Reads. ARSAS must not add traffic merely to imitate IEDScout.
-
-Forbidden regressions include a second discovery association, legacy supplemental
-browse, a second full GetNameList sweep, recursive per-leaf GVA, and eager FC-root
-value hydration on the discovery critical path.
-
-## P1 — CF projection-order repair: physically proven
-
-Contract: `P1-CF-DO-SCOPED`.
-
-R9 exposed 46 projection errors because SCL LNodeType DO order was incorrectly used
-as MMS CF-root child order. P1 reads multi-DO CF data through exact `LN$CF$DO`
-references and batches those structured reads.
-
-R10 physical reuse closes P1:
-
-- Ed2: 709 initial targets, 525 FC-root targets, 184 DO-scoped targets,
- 709/709 successful, 0 failed, `projectionErrors=0`.
-- Ed1: 708 initial targets, 524 FC-root targets, 184 DO-scoped targets,
- 708/708 successful, 0 failed, `projectionErrors=0`.
-
-No extra discovery GVA or second association was introduced.
-
-## P2 — exact-case value pipeline: physically proven
-
-Contract: `P2-CASE-EXACT-VALUES`.
-
-R9 Ed2 lost 11 projected values because a consumer cache used case-insensitive
-identity. P2 uses exact-case identity through TypeSpecification mapping, initial
-projection, trusted-SCL caching, canonical evidence and SCL instance-value targeting.
-
-R10 physical reuse closes P2:
-
-- Ed2: `projectedUniqueValues=4441`, `initialValueCache=4441`, `cacheLoss=0`.
-- Ed1: `projectedUniqueValues=4246`, `initialValueCache=4246`, `cacheLoss=0`.
-
-## R10 round-trip/reporting acceptance
-
-Both generated editions reopen as trusted SCL and reconnect without full discovery:
-
-- expected/observed/matched MMS domains: 32/32/32;
-- DataSets: 2, members: 58, missing members: 0;
-- configured report plans: Digital BRCB 36 members + Analog URCB 22 members;
-- report-covered runtime points: 58;
-- final unresolved runtime points: 0;
-- cyclic MMS process polling: 0;
-- actual InformationReport traffic observed on both editions.
-
-The early UI field `Primary unresolved=2` is not an operational loss: the exact
-static DataSet schema resolves all 58 runtime points before reporting starts.
-
-## Save-time instance values
-
-R10 physically proves bounded Save SCL enrichment while fast discovery stays
-unchanged:
-
-- canonical instance evidence: 3854 leaves;
-- Ed2 exported `Val`: 3202;
-- Ed1 exported `Val`: 3106.
-
-IEDScout's golden file has about 1529 `Val` elements. A larger count is not
-automatically better; the remaining task is semantic path/value comparison, not
-count chasing.
-
-## RCB lock
-
-The accepted representation remains:
-
-- 34 runtime RCB objects → 32 logical SCL ReportControls;
-- `Services/ConfReportControl max=34`;
-- Buffer/Digital and Unbuffer/Analog remain the two configured report authorities;
-- preallocated ADD slots without DataSet never receive an invented `datSet`.
-
-## Next improvements — do not disturb the proven wire/reuse path
-
-### 1. Template interning
-
-R10 Ed2 is semantically correct but verbose:
-
-- ARSAS: 119 LNodeType / 906 DOType / 752 DAType / about 731 KB;
-- IEDScout reference: about 38 / 60 / 17 / about 247 KB.
-
-Next work may intern only templates with identical ordered semantic fingerprints.
-Expanded model counts, FC ownership, values, DataSets/RCBs and round-trip behavior
-must remain unchanged.
-
-### 2. Reuse one save-enrichment snapshot across Ed2 and Ed1
-
-When Ed2 and Ed1 are saved in the same unchanged live association/model generation,
-both currently derive the same 3854 instance-evidence leaves. A later optimization
-may reuse that bounded snapshot across serializers, but never across reconnect,
-model-generation change or explicit refresh.
-
-### 3. Semantic Val diff
-
-Compare ARSAS vs IEDScout by exact
-`LD/LN/DO/SDO/DA/BDA/FC/bType/value` path, not raw XML position and not total
-`Val` count.
-
-## Regression signatures that are forbidden
-
-A build is rejected if it restores any of these patterns:
-
-- legacy `DiscoverAsync` as the public discovery route;
-- a second supplemental discovery association;
-- recursive per-leaf GVA expansion;
-- speculative thousands of Reads on the discovery path;
-- cross-DO positional CF projection;
-- case-insensitive IEC 61850 member/value identity;
-- WYE/DEL/SEQ SDO flattening;
-- Edition 2 tracking CDCs in Edition 1;
-- invented DataSet bindings for unassigned RCB slots;
-- silent canonical-save success without reopen/association validation.
-
-## Promotion state
-
-The R10 physical retest has passed and merge is allowed. Production promotion is
-still a separate release decision.
-
-The field result, not test count alone, decides interoperability acceptance.
diff --git a/docs/INTEROPERABILITY_CONVERGENCE.md b/docs/INTEROPERABILITY_CONVERGENCE.md
new file mode 100644
index 000000000..86fe1c77f
--- /dev/null
+++ b/docs/INTEROPERABILITY_CONVERGENCE.md
@@ -0,0 +1,206 @@
+# IEC 61850 Interoperability Convergence Contract
+
+## Current stable baseline
+
+ARSAS **1.6.38** is the current verified stable Windows release.
+
+Release source:
+
+- ARSAS release commit: `5e7ebec2779177c7f182a6a30b64218f84200a90`
+- R10 post-merge baseline: `b93ef8fb615213eb81cdfda66d89c05a0d658839`
+- ARIEC61850 merged authority: `648124097621046f5f127ceb1cf853fea54db730`
+- ARIEC61850 physical-tested head: `9935d6902d786cc69b299260fe36b835944d5e81`
+- Engine source-tree SHA: `1cf7e08f333f24994625e8fe8416dbd0a16195b1`
+
+The tested engine head and merged engine authority resolve to the same source tree.
+
+The machine-readable authority is
+`evidence/interoperability-convergence-target.json`.
+
+## Acceptance model
+
+The accepted path keeps discovery, SCL generation, trusted-SCL reuse and reporting
+as separate bounded phases:
+
+1. one accepted MMS association for structural discovery;
+2. complete LD/LN/DO/SDO/DA/FC identity;
+3. canonical Edition 2 IID or Edition 1 ICD generation;
+4. reopen through the ARSAS SCL workspace;
+5. reconnect using the trusted SCL model;
+6. bounded initial value hydration;
+7. static DataSet/report activation;
+8. runtime value acquisition through report traffic without cyclic MMS process polling.
+
+## P0 — structural discovery freeze
+
+Contract: `P0-R9-STRUCTURAL`.
+
+The physical acceptance device is locked at:
+
+- 1 MMS association;
+- 323 confirmed MMS requests on the accepted R10 path;
+- 138 GetNameList requests;
+- 119 GetVariableAccessAttributes requests;
+- 2 GetNamedVariableListAttributes requests;
+- 64 Reads;
+- 32 logical devices;
+- 119 logical nodes;
+- 860 top-level data objects;
+- 906 data objects including SDOs;
+- 4925 scalar leaves;
+- 2 DataSets / 58 FCDA;
+- 32 logical ReportControls;
+- 1 SettingControl.
+
+Regression ceilings remain bounded at 417 confirmed MMS requests,
+119 GetVariableAccessAttributes requests and 156 Reads.
+
+Forbidden regressions include:
+
+- a second discovery association;
+- supplemental legacy browsing;
+- a second full GetNameList sweep;
+- recursive per-leaf GVA expansion;
+- eager FC-root value hydration on the structural discovery critical path.
+
+## P1 — exact DO-scoped CF projection
+
+Contract: `P1-CF-DO-SCOPED`.
+
+R9 exposed 46 projection errors caused by using SCL LNodeType DO order as if it
+were MMS multi-DO CF child order. The accepted repair reads multi-DO CF data
+through exact `LN$CF$DO` references and keeps batching bounded.
+
+R10 physical reuse proves the repair:
+
+### Edition 2
+
+- initial targets: 709;
+- FC-root targets: 525;
+- DO-scoped targets: 184;
+- successful Reads: 709/709;
+- failed Reads: 0;
+- `projectionErrors=0`.
+
+### Edition 1
+
+- initial targets: 708;
+- FC-root targets: 524;
+- DO-scoped targets: 184;
+- successful Reads: 708/708;
+- failed Reads: 0;
+- `projectionErrors=0`.
+
+## P2 — exact-case value identity
+
+Contract: `P2-CASE-EXACT-VALUES`.
+
+The accepted value pipeline preserves case-distinct IEC 61850 paths through
+TypeSpecification mapping, trusted-SCL projection, cache storage, canonical
+instance evidence and SCL instance-value targeting.
+
+R10 proves zero cache loss:
+
+- Edition 2: `projectedUniqueValues=4441`,
+ `initialValueCache=4441`, `cacheLoss=0`;
+- Edition 1: `projectedUniqueValues=4246`,
+ `initialValueCache=4246`, `cacheLoss=0`.
+
+## R10 trusted-SCL round trip
+
+Both generated editions reopen and reconnect through the trusted-SCL path.
+
+Common acceptance:
+
+- expected/observed/matched MMS domains: 32/32/32;
+- static DataSets: 2;
+- static DataSet members: 58;
+- missing static members: 0;
+- report-backed runtime points: 58/58;
+- final unresolved runtime points: 0;
+- cyclic MMS process polling: 0;
+- actual InformationReport traffic observed.
+
+The intermediate field `Primary unresolved=2` is not an operational loss.
+Static DataSet identity resolves all 58 runtime points before report-backed
+acquisition is accepted.
+
+## Save-time instance evidence
+
+Save-time value enrichment remains outside the structural discovery critical
+path.
+
+R10 physical results:
+
+- canonical instance evidence: 3854 leaves;
+- Edition 2 exported `Val`: 3202;
+- Edition 1 exported `Val`: 3106.
+
+Raw `Val` count is not treated as a quality metric. Exact semantic
+path/value correctness remains the acceptance criterion.
+
+## ReportControl identity
+
+The accepted representation remains:
+
+- 34 concrete runtime RCB objects;
+- 32 logical SCL ReportControls;
+- `Services/ConfReportControl max=34`;
+- 36 digital + 22 analog static DataSet members;
+- unassigned indexed slots remain unassigned and do not receive invented
+ DataSet references.
+
+## Release verification
+
+ARSAS 1.6.38 passed:
+
+- exact release-source restore/build/test;
+- Windows portable publish and smoke test;
+- Windows installer build and silent install/uninstall smoke test;
+- R10 post-merge convergence verification;
+- SHA-256 generation;
+- SPDX 2.3 SBOM generation;
+- app/engine provenance generation;
+- artifact attestation;
+- public GitHub Release publication.
+
+Public release identity and package hashes are synchronized in
+`landing/latest.json`.
+
+## Next bounded improvements
+
+### Template interning
+
+Edition 2 is semantically correct but can reduce duplicate type templates.
+Interning is allowed only when ordered semantic fingerprints are identical.
+
+The expanded model counts, FC ownership, values, DataSets, ReportControls and
+round-trip behavior must remain unchanged.
+
+### Save-enrichment snapshot reuse
+
+A later optimization may reuse one bounded save-enrichment snapshot across
+Edition 2 and Edition 1 serialization only while the association and model
+generation are unchanged.
+
+The snapshot must be invalidated on reconnect, model-generation change or
+explicit refresh.
+
+This optimization is not part of ARSAS 1.6.38.
+
+## Regression signatures that remain forbidden
+
+A build is rejected if it restores any of these patterns:
+
+- legacy discovery as the primary route;
+- a second supplemental discovery association;
+- recursive per-leaf GVA expansion;
+- speculative high-volume Reads on the structural discovery path;
+- cross-DO positional CF projection;
+- case-insensitive IEC 61850 member/value identity;
+- WYE/DEL/SEQ SDO flattening;
+- invalid Edition 1 tracking CDC output;
+- invented DataSet bindings for unassigned RCB slots;
+- silent canonical-save success without reopen/association validation.
+
+The physical result, not test count alone, decides interoperability acceptance.
diff --git a/docs/README.md b/docs/README.md
index a7f294002..3386d3bbd 100644
--- a/docs/README.md
+++ b/docs/README.md
@@ -2,7 +2,7 @@
This directory contains the engineering, validation, licensing, provenance, release, and operating-boundary documents for the ARSAS Windows IEC 61850 engineering workstation.
-The current application version on `main` is **ARSAS 1.6.37**. Public binary identity remains tied to the latest actually published stable GitHub Release and its verified package evidence.
+The current application version on `main` is **ARSAS 1.6.38**. Public binary identity remains tied to the latest actually published stable GitHub Release and its verified package evidence.
## Start here
@@ -11,7 +11,8 @@ The current application version on `main` is **ARSAS 1.6.37**. Public binary ide
| [Project README](../README.md) | Product overview, current-version summary, feature scope, quick start, build instructions, and public claim boundary. |
| [IO List FAT Evidence Testing](IO_LIST_FAT_EVIDENCE.md) | Imported SDI test plans, OFF → ON → OFF evidence, Excel/PDF export, portable `.arsas` projects, integrity checks, and cross-laptop continuation. |
| [Architecture](ARCHITECTURE.md) | Multi-IED ownership, model identity, report-first acquisition, runtime scaling, and timestamp semantics. |
-| [SCL export](SCL_EXPORT.md) | Live-discovery and source-backed SCL export, including the 1.6.37 logical ReportControl versus runtime RCB-instance boundary. |
+| [Interoperability convergence](INTEROPERABILITY_CONVERGENCE.md) | R10 physical discovery, trusted-SCL reuse, report-backed acquisition, exact-case value identity, and 1.6.38 release verification. |
+| [SCL export](SCL_EXPORT.md) | Live-discovery and source-backed SCL export, including the 1.6.38 logical ReportControl versus runtime RCB-instance boundary. |
| [COMTRADE viewer integration](COMTRADE_VIEWER_INTEGRATION.md) | Native ArdIrec bridge, in-process cursor/Phasor/Harmonics/Locus analysis, packaging, and presentation-only easing contract. |
| [Windows releases](WINDOWS_RELEASES.md) | Installer and portable single-EXE packaging, exact release gates, checksums, SBOM, provenance, attestations, and publication boundary. |
| [GOOSE Subscriber](GOOSE_SUBSCRIBER.md) | Read-only Npcap capture, ARIEC61850 GOOSE decoding, SCL/live-discovery DataSet binding, ordered `allData` leaf semantics, diagnostics, and field validation. |
diff --git a/docs/SCL_EXPORT.md b/docs/SCL_EXPORT.md
index 3596fbe12..0e7a7bc9e 100644
--- a/docs/SCL_EXPORT.md
+++ b/docs/SCL_EXPORT.md
@@ -14,13 +14,13 @@ Each ARSAS IED card exposes a **Save SCL** action after the application has a co
The chosen profile controls root schema metadata, supported ReportControl fields, Services declarations, and default file extension.
-## ReportControl identity in ARSAS 1.6.37
+## ReportControl identity in ARSAS 1.6.38
ARSAS separates the declarative engineering model from concrete runtime RCB instances.
A source SCL file may describe one logical `ReportControl` together with `RptEnabled@max`. A connected IED can expose concrete client/runtime instances such as `Buffer01`, `Buffer02`, `Unbuffer01`, or `Unbuffer02`. Those online instances are valid live evidence, but they are not authority to duplicate or rename the logical source `ReportControl` in a source-backed IID/SCL export.
-The v1.6.37 contract is therefore:
+The v1.6.38 contract is therefore:
- live RCB selection presents the concrete runtime instances actually exposed by the connected IED;
- duplicate logical placeholder rows are not added beside those live instances;
diff --git a/docs/SNTP_CLOCK_SYNC.md b/docs/SNTP_CLOCK_SYNC.md
index 4ad3d263f..f16a35110 100644
--- a/docs/SNTP_CLOCK_SYNC.md
+++ b/docs/SNTP_CLOCK_SYNC.md
@@ -14,7 +14,7 @@ ARSAS includes a small clean-room SNTPv4 commissioning service for station-bus w
- Sends an immediate SNTPv4 Mode 5 directed broadcast, then repeats every 64 seconds by default when a usable directed-broadcast address exists.
- Sends another immediate broadcast when a newly connected IED is observed.
- Separately records `broadcast sent`, `client request seen`, and `Mode 4 reply sent` evidence.
-- Advertises synchronized commissioning packets with SIPROTEC compatibility `stratum 2` and reference ID `LOCL`.
+- Advertises synchronized commissioning packets with protection-IED compatibility `stratum 2` and reference ID `LOCL`.
- Performs a wall-clock sanity/step check. A large time step suppresses broadcast and makes that instant's unicast reply RFC-style unsynchronized (`LI=3`, `stratum=0`, `INIT`, server timestamps zero).
- Never fails an IEC 61850 association when SNTP cannot start.
@@ -29,11 +29,11 @@ FAT Clock Sync telemetry intentionally distinguishes packet activity from actual
A broadcast without a client request may still be valid when the relay is explicitly configured for broadcast NTP, but ARSAS does not treat it as an acknowledgement. For unicast SNTP, the strongest wire-level evidence is a Mode 3 request followed by a Mode 4 reply. Device-side time-quality or clock evidence is still required before declaring the relay synchronized.
-## SIPROTEC compatibility stratum
+## protection-IED compatibility stratum
-Field commissioning has shown that a conservative high-stratum local source can be rejected or remain marked unsynchronized on some SIPROTEC installations. ARSAS therefore uses `stratum 2` for both Mode 4 replies and Mode 5 broadcasts.
+Field commissioning has shown that a conservative high-stratum local source can be rejected or remain marked unsynchronized on some GENERIC_IED installations. ARSAS therefore uses `stratum 2` for both Mode 4 replies and Mode 5 broadcasts.
-The value is named in code as `SntpServerProfile.SiprotecCompatibilityStratum` and is protected by regression tests. It does not claim that the Windows laptop is physically traceable to a stratum-1 GNSS/PTP/atomic source. `LOCL` remains the reference ID and ARSAS diagnostics describe the laptop as a local commissioning source.
+The value is named in code as `SntpServerProfile.GenericIedCompatibilityStratum` and is protected by regression tests. It does not claim that the Windows laptop is physically traceable to a stratum-1 GNSS/PTP/atomic source. `LOCL` remains the reference ID and ARSAS diagnostics describe the laptop as a local commissioning source.
If the Windows clock fails the ARSAS clock-health guard, synchronized stratum is not advertised: the affected unicast response becomes unsynchronized (`LI=3`, `stratum=0`, `INIT`) and broadcast is suppressed.
@@ -75,7 +75,7 @@ If another connected IED routes through a different local IPv4 interface, ARSAS
- version/poll field copy behavior;
- Mode 4 reply semantics;
- originate timestamp echo;
-- SIPROTEC compatibility stratum 2 on unicast and broadcast packets;
+- protection-IED compatibility stratum 2 on unicast and broadcast packets;
- Mode 5 broadcast semantics;
- RFC-style unsynchronized response fields;
- directed-broadcast calculation;
diff --git a/docs/WINDOWS_RELEASES.md b/docs/WINDOWS_RELEASES.md
index 9917a9936..69f137c46 100644
--- a/docs/WINDOWS_RELEASES.md
+++ b/docs/WINDOWS_RELEASES.md
@@ -5,7 +5,7 @@ ARSAS publishes two Windows x64 deliverables from the same reviewed source revis
- `ARSAS-Windows-x64-Portable.exe` — a real self-contained single EXE for approved no-install use.
- `ARSAS-Windows-x64-Setup.exe` — the Inno Setup installer with Start Menu integration, uninstall support, and the same pinned ARIEC61850 and ArdIrec native-analysis revisions used by the release build.
-The current application version on `main` is **1.6.37**. Public download metadata remains authoritative only after the corresponding tagged GitHub Release has been published and its checksums/provenance are visible.
+The current application version on `main` is **1.6.38**. Public download metadata remains authoritative only after the corresponding tagged GitHub Release has been published and its checksums/provenance are visible.
## Official stable release path
@@ -83,8 +83,8 @@ Prerequisites:
Use the repository packaging scripts rather than hand-assembling a release folder. For example:
```powershell
-.\scripts\publish-windows-portable.ps1 -Version 1.6.37
-.\scripts\build-windows-installer.ps1 -Version 1.6.37 -Runtime win-x64
+.\scripts\publish-windows-portable.ps1 -Version 1.6.38
+.\scripts\build-windows-installer.ps1 -Version 1.6.38 -Runtime win-x64
```
Official CI additionally supplies the pinned engine projects and ArdIrec source explicitly so the build cannot silently resolve an unreviewed revision.
diff --git a/docs/WORKSTREAM_COORDINATION.md b/docs/WORKSTREAM_COORDINATION.md
index f2805da58..553abfd83 100644
--- a/docs/WORKSTREAM_COORDINATION.md
+++ b/docs/WORKSTREAM_COORDINATION.md
@@ -12,6 +12,25 @@ The ArdIrec native bridge dependency used by that workstation was integrated fir
The production `AGENTS.md` already present on `main` remains authoritative.
+## IEC 61850 qualified runtime baseline
+
+The accepted IEC 61850 runtime line was qualified on ARSAS PR #324. Its final
+source head is `b0f25569a398c7bbdc3a3a34409dbd74ebf49444`, its merged commit is
+`2b8e8adfd019bd087dc338dcc32bffefec53370f`, and both commits resolve to the
+same Git tree `cccb50607161f8637e597b43d71038ffd4becfdc`.
+
+The corresponding portable artifact was produced by workflow run
+`35412542175` with SHA-256
+`6805b878f91f3d526cc50f3e81e3eb9a1f72500217dacc8921e50bdc349c5fcc`.
+`.release/qualified-source.json` is the machine-readable authority for this
+lineage. The Windows release workflow must verify its release-sensitive
+fingerprint before packaging or publication.
+
+Public wording and identifier neutralization may be layered on this baseline
+only when the exact combined head passes regression and packaging gates. A
+version bump, documentation update, or merged/closed PR status does not by
+itself establish a new qualified runtime authority.
+
## Parallel FAT workstream
The FAT workstream remains independent and is currently represented by the stacked FAT branches/PRs, including PR #290, PR #296, and PR #303. Their existing field gate remains authoritative; this coordination note does not waive or replace it.
diff --git a/docs/field-evidence-dataset-ui-prune.md b/docs/field-evidence-dataset-ui-prune.md
index 06308fbd4..1d1a13343 100644
--- a/docs/field-evidence-dataset-ui-prune.md
+++ b/docs/field-evidence-dataset-ui-prune.md
@@ -10,6 +10,6 @@ Field validation on ARSAS `916a37e3d3c3364bc38a34e4ed2aaaa70a11cac6` with ARIEC6
The repeated restore proved the authority service was adding the rows successfully and that a later lifecycle stage removed them.
-Source audit identified `SasOperationalUiPolicy` as that stage. Its global `DataGrid.Loaded` handler scheduled a destructive prune against the underlying `IList`, removing every `SignalDefinition` rejected by `SasOperationalSignalPolicy.IsVisible`. Object-level Siemens FCDA/FCD members intentionally fail the exact-runtime-leaf policy, so mandatory static DataSet rows were deleted directly from `device.Signals`.
+Source audit identified `SasOperationalUiPolicy` as that stage. Its global `DataGrid.Loaded` handler scheduled a destructive prune against the underlying `IList`, removing every `SignalDefinition` rejected by `SasOperationalSignalPolicy.IsVisible`. Object-level generic FCDA/FCD members intentionally fail the exact-runtime-leaf policy, so mandatory static DataSet rows were deleted directly from `device.Signals`.
The fix changes this contract from source mutation to presentation-only filtering and explicitly keeps rows with static `DataSetReference` visible. The authoritative signal collection is no longer changed by DataGrid policy.
diff --git a/engines/ARIEC61850.lock.json b/engines/ARIEC61850.lock.json
index 360e72a96..83f9f635f 100644
--- a/engines/ARIEC61850.lock.json
+++ b/engines/ARIEC61850.lock.json
@@ -18,7 +18,7 @@
"fieldProvenBaseline": {
"commit": "11ab2304482600c19ba979f4fc9021ddb46b9af9",
"sourcePullRequest": 111,
- "purpose": "Pins the exact ARIEC61850 engine used by ARSAS while preserving the reviewed reporting/control ancestry. PR #76 preserves unresolved static DataSet members; PR #77 canonicalizes cross-logical-device SCL references; PR #78 keeps one descriptor per static DataSet member while separating the resolved runtime primary leaf from original FCDA/FCD identity; PR #79 projects generic Boolean status structures to scalar stVal while preserving quality/timestamp; PR #80 normalizes validated DataRef-enabled InformationReport ordering; PR #81 accepts valid zero OptFlds reports while quarantining unmapped canonical report metadata; PR #84 routes exact PrimaryValue residuals through dynamic reporting before MMS polling; PR #85 evaluates association capabilities before automatic dynamic mutation; PR #86 records dynamic-attempt failure/skip evidence and best-effort rollback. PR #87 restores baseline-safe static precedence. PR #88 adds a fail-closed single-member DefineNamedVariableList -> GetNamedVariableListAttributes -> DeleteNamedVariableList probation with exact invoke/request/response/routing/member/association/cleanup evidence. PR #89 quarantines automatic full dynamic DataSet activation because a successful one-member NVL probation does not guarantee association survival; it also preserves safe instMag/mag and instCVal/cVal projection while ambiguous structures remain raw. PR #90 / field-proven engine a18e550d07f7bbe4ff7753c180b02615075f6292 preserves G1/G1.1 Smart Control: signed primitive constraints, ordered SBO/SBOw-to-Operate wire evidence, StationControl origin compatibility, and explicit MMS Write DataAccessError including object-access-denied. G2 PR #91 adds qualification-only bounded multi-member DefineNamedVariableList/GetNamedVariableListAttributes/DeleteNamedVariableList evidence with exact ordered read-back, encoded request/PDU evidence and fail-closed cleanup; PR #92 adds the 1/4/8/16/32 qualification ladder, deterministic bisection and explicit EnvelopeQualified acceptance; PR #93 adds a default-disabled ExplicitCommissioning coordinator with hard attempt budget, exact-set failure localization and fresh-association stop semantics; PR #94 adds identity-bound qualification profiles and prevents ProductionEligible unless RCB activation, an actual correctly mapped InformationReport, and all G2.6 physical regression gates are proven. G2.4 engine PR #95 retains the commissioning-only transactional URCB TrgOps/OptFlds lease. P0 physically proved the corrected IEC 61850 MMS TrgOps reserved-bit mapping: bit 0 reserved, bits 1..5 dchg/qchg/dupd/integrity/GI, so dchg+GI encodes canonically as 0244; P0 also separates raw BER equality from IEC significant-bit equality and provides a one-URCB TrgOps-only micro-probe that never writes OptFlds, DatSet, Resv, RptEna, GI or any DataSet service. P1 adds a dedicated one-URCB OptFlds-only capture/write/readback/finally-restore micro-probe for reason-for-inclusion + data-set-name, canonical target 061800, using ten-bit significant-value comparison while never writing TrgOps, DatSet, Resv, RptEna, GI, Define/Delete DataSet, starting a report monitor, or changing profile state. The G2.4 Owner correction exposes the exact local TCP address of the active MMS association and fail-closed decodes a server RCB Owner as a 4-byte IPv4 or 16-byte IPv6 address; physical SIPROTEC Owner C0A851F0 decodes to 192.168.81.240 and may prove caller ownership only when it exactly matches the active local TCP endpoint. Owner mismatch or unsupported encoding remains a hard failure. Original RCB values remain captured for restore, raw BER evidence is retained, and Production automatic dynamic BRCB/URCB activation remains quarantined until a compatible ProductionEligible profile is consumed by a later G2 phase. FAT P5.3 engine PR #103 resolves intermediate structured static DataSet members such as MMXU A.phsA and PPV.phsAB only to typed descendants below the exact FCDA boundary, selects a unique semantic primary runtime leaf such as cVal.mag.f without crossing sibling phases, preserves original static membership identity, and leaves genuinely ambiguous structures unresolved rather than guessing. FAT P5.4 engine PR #106 adds fail-closed model-backed InformationReport projection for structured static DataSet members: an exact report member reference now resolves independently of sparse decoder-side report value position, while DataSet scope still prevents duplicate static memberships from collapsing; when a report omits the member reference, static DataSet index remains the unique fail-closed fallback. All schema-proven scalar descendants are fanned out without selecting a sibling phase, and schema mismatch preserves raw projection instead of guessing. ARSAS supplies the per-IED LiveDiscovery/SCL planning model at the report receive seam. PR #111 is a narrow continuation on the exact b9ee5fc ARSAS engine baseline: exact static DataSet/SCL semantic schema is attempted before generic structured-value heuristics so TotPF and similar members publish exact scalar leaves; generic projection remains the fail-closed fallback, and report q/t companions are ordered ahead of semantic scalar values. P1 hardening at 0d7525bd330900917fb9f6d15a46059dc3d7a70a also makes semantic expansion return the resolved authoritative member identity and replaces generic output by report-value position after semantic success, so an InformationReport that omits MemberReference but resolves uniquely through static DataSet index cannot leak unrooted projected-mx-pair leaves alongside exact semantic values. Physical BRCB compatibility hardening at 11ab2304482600c19ba979f4fc9021ddb46b9af9 adds a client-compatible persistent activation wrapper: when ResvTms is exposed it attempts an explicit 60-second BRCB reservation with implicit-RptEna fallback, keeps cleanup/release deterministic, and requests GI only after the persistent report session is registered."
+ "purpose": "Pins the exact ARIEC61850 engine used by ARSAS while preserving the reviewed reporting/control ancestry. PR #76 preserves unresolved static DataSet members; PR #77 canonicalizes cross-logical-device SCL references; PR #78 keeps one descriptor per static DataSet member while separating the resolved runtime primary leaf from original FCDA/FCD identity; PR #79 projects generic Boolean status structures to scalar stVal while preserving quality/timestamp; PR #80 normalizes validated DataRef-enabled InformationReport ordering; PR #81 accepts valid zero OptFlds reports while quarantining unmapped canonical report metadata; PR #84 routes exact PrimaryValue residuals through dynamic reporting before MMS polling; PR #85 evaluates association capabilities before automatic dynamic mutation; PR #86 records dynamic-attempt failure/skip evidence and best-effort rollback. PR #87 restores baseline-safe static precedence. PR #88 adds a fail-closed single-member DefineNamedVariableList -> GetNamedVariableListAttributes -> DeleteNamedVariableList probation with exact invoke/request/response/routing/member/association/cleanup evidence. PR #89 quarantines automatic full dynamic DataSet activation because a successful one-member NVL probation does not guarantee association survival; it also preserves safe instMag/mag and instCVal/cVal projection while ambiguous structures remain raw. PR #90 / field-proven engine a18e550d07f7bbe4ff7753c180b02615075f6292 preserves G1/G1.1 Smart Control: signed primitive constraints, ordered SBO/SBOw-to-Operate wire evidence, StationControl origin compatibility, and explicit MMS Write DataAccessError including object-access-denied. G2 PR #91 adds qualification-only bounded multi-member DefineNamedVariableList/GetNamedVariableListAttributes/DeleteNamedVariableList evidence with exact ordered read-back, encoded request/PDU evidence and fail-closed cleanup; PR #92 adds the 1/4/8/16/32 qualification ladder, deterministic bisection and explicit EnvelopeQualified acceptance; PR #93 adds a default-disabled ExplicitCommissioning coordinator with hard attempt budget, exact-set failure localization and fresh-association stop semantics; PR #94 adds identity-bound qualification profiles and prevents ProductionEligible unless RCB activation, an actual correctly mapped InformationReport, and all G2.6 physical regression gates are proven. G2.4 engine PR #95 retains the commissioning-only transactional URCB TrgOps/OptFlds lease. P0 physically proved the corrected IEC 61850 MMS TrgOps reserved-bit mapping: bit 0 reserved, bits 1..5 dchg/qchg/dupd/integrity/GI, so dchg+GI encodes canonically as 0244; P0 also separates raw BER equality from IEC significant-bit equality and provides a one-URCB TrgOps-only micro-probe that never writes OptFlds, DatSet, Resv, RptEna, GI or any DataSet service. P1 adds a dedicated one-URCB OptFlds-only capture/write/readback/finally-restore micro-probe for reason-for-inclusion + data-set-name, canonical target 061800, using ten-bit significant-value comparison while never writing TrgOps, DatSet, Resv, RptEna, GI, Define/Delete DataSet, starting a report monitor, or changing profile state. The G2.4 Owner correction exposes the exact local TCP address of the active MMS association and fail-closed decodes a server RCB Owner as a 4-byte IPv4 or 16-byte IPv6 address; physical-device Owner C0A851F0 decodes to 192.168.81.240 and may prove caller ownership only when it exactly matches the active local TCP endpoint. Owner mismatch or unsupported encoding remains a hard failure. Original RCB values remain captured for restore, raw BER evidence is retained, and Production automatic dynamic BRCB/URCB activation remains quarantined until a compatible ProductionEligible profile is consumed by a later G2 phase. FAT P5.3 engine PR #103 resolves intermediate structured static DataSet members such as MMXU A.phsA and PPV.phsAB only to typed descendants below the exact FCDA boundary, selects a unique semantic primary runtime leaf such as cVal.mag.f without crossing sibling phases, preserves original static membership identity, and leaves genuinely ambiguous structures unresolved rather than guessing. FAT P5.4 engine PR #106 adds fail-closed model-backed InformationReport projection for structured static DataSet members: an exact report member reference now resolves independently of sparse decoder-side report value position, while DataSet scope still prevents duplicate static memberships from collapsing; when a report omits the member reference, static DataSet index remains the unique fail-closed fallback. All schema-proven scalar descendants are fanned out without selecting a sibling phase, and schema mismatch preserves raw projection instead of guessing. ARSAS supplies the per-IED LiveDiscovery/SCL planning model at the report receive seam. PR #111 is a narrow continuation on the exact b9ee5fc ARSAS engine baseline: exact static DataSet/SCL semantic schema is attempted before generic structured-value heuristics so TotPF and similar members publish exact scalar leaves; generic projection remains the fail-closed fallback, and report q/t companions are ordered ahead of semantic scalar values. P1 hardening at 0d7525bd330900917fb9f6d15a46059dc3d7a70a also makes semantic expansion return the resolved authoritative member identity and replaces generic output by report-value position after semantic success, so an InformationReport that omits MemberReference but resolves uniquely through static DataSet index cannot leak unrooted projected-mx-pair leaves alongside exact semantic values. Physical BRCB compatibility hardening at 11ab2304482600c19ba979f4fc9021ddb46b9af9 adds a client-compatible persistent activation wrapper: when ResvTms is exposed it attempts an explicit 60-second BRCB reservation with implicit-RptEna fallback, keeps cleanup/release deterministic, and requests GI only after the persistent report session is registered."
},
"physicalTestedCommit": "9935d6902d786cc69b299260fe36b835944d5e81",
"mergedMainCommit": "648124097621046f5f127ceb1cf853fea54db730",
diff --git a/evidence/iedscout-convergence-target.json b/evidence/interoperability-convergence-target.json
similarity index 94%
rename from evidence/iedscout-convergence-target.json
rename to evidence/interoperability-convergence-target.json
index a853fd0ea..23b1f4354 100644
--- a/evidence/iedscout-convergence-target.json
+++ b/evidence/interoperability-convergence-target.json
@@ -1,9 +1,9 @@
{
"schemaVersion": 1,
- "name": "IEDScout discovery and SCL convergence",
+ "name": "IEC 61850 discovery and SCL interoperability convergence",
"status": "physical-retest-passed-merge-ready",
"target": {
- "discovery": "Reach IEDScout-like MMS discovery efficiency without sacrificing exact IEC 61850 model evidence.",
+ "discovery": "Maintain bounded MMS discovery efficiency while preserving exact IEC 61850 model evidence.",
"model": "Build the canonical IEC 61850 model from structure-first MMS evidence with correct LN identity, DO/SDO hierarchy, FC ownership, DataSet/RCB semantics, and schema-aware CDC handling.",
"scl": "Save Edition 2 IID / Edition 1 ICD that reopens in ARSAS, reconnects to the relay, and is usable as trusted SCL."
},
@@ -39,12 +39,12 @@
"dataSets": 2,
"runtimeReportControls": 34,
"logicalSclReportControls": 32,
- "iedScoutCapture": {
+ "acceptedDiscoveryBudget": {
"associations": 1,
- "confirmedMmsRequests": 417,
- "getVariableAccessAttributes": 119,
- "reads": 156,
- "note": "Reference capture supplied by the physical comparison; values are acceptance reference, not CI-simulated proof."
+ "maximumConfirmedMmsRequests": 417,
+ "maximumGetVariableAccessAttributes": 119,
+ "maximumReads": 156,
+ "note": "Internal physical acceptance ceiling retained as a regression budget."
},
"rejectedLegacyArsasCapture": {
"associations": 2,
@@ -53,7 +53,7 @@
"reads": 6548,
"note": "Regression signature. A future field build showing this pattern is rejected."
},
- "iedScoutSclReference": {
+ "acceptedSclShape": {
"lDevices": 32,
"logicalNodes": 119,
"dataSets": 2,
@@ -71,7 +71,7 @@
"secondFullGetNameListSweepForbidden": true,
"eagerInitialFcValueReadDuringStructuralDiscovery": false,
"typeStrategy": "LN/root structure first, bounded leaf fallback only when exact structure evidence is unavailable.",
- "physicalPerformanceGate": "Compare request count, GVA count, Read count, peak outstanding calls, TTFI and total discovery time against IEDScout on the same relay."
+ "physicalPerformanceGate": "Keep one association and remain within the locked request, GVA and Read ceilings while preserving or improving TTFI and total discovery time on the physical acceptance device."
},
"modelAcceptance": {
"prefixedLogicalNodeIdentityExamples": [
@@ -126,8 +126,7 @@
"new generated Ed1 ICD",
"diagnostic report",
"Ed2 SCL-assisted reuse diagnostic with projectionErrorSamples",
- "Ed1 SCL-assisted reuse diagnostic with projectionErrorSamples",
- "same-relay comparison against IEDScout"
+ "Ed1 SCL-assisted reuse diagnostic with projectionErrorSamples"
],
"mergeAllowedAfterPhysicalRetest": true,
"physicalRetestPassed": true,
@@ -332,29 +331,22 @@
},
"saveTimeInstanceValues": {
"observedR9ExportValCount": 0,
- "referenceIedScoutValCount": 1529,
"status": "mechanism-physically-proven-semantic-diff-open",
"rule": "Keep structural discovery read-free; acquire bounded safe FC-root values only during explicit Save SCL and verify resulting instance evidence physically.",
"r10InstanceEvidence": 3854,
"r10Edition2ValCount": 3202,
"r10Edition1ValCount": 3106,
- "note": "Save-time value enrichment is physically proven. More Val elements than IEDScout is not treated as automatically better; exact semantic path/value comparison remains open."
+ "note": "Save-time value enrichment is physically proven. Exact semantic path/value validation remains the acceptance criterion; raw Val count alone is not treated as a quality metric."
},
"templateReuse": {
"status": "next-improvement",
- "rule": "Reduce duplicate LNodeType/DOType/DAType templates only after wire and semantic reuse parity is stable.",
+ "rule": "Reduce duplicate LNodeType/DOType/DAType templates only after wire behavior and semantic SCL reuse are stable.",
"r10Edition2": {
"lNodeType": 119,
"doType": 906,
"daType": 752,
"fileBytes": 731266
},
- "iedScoutReference": {
- "lNodeType": 38,
- "doType": 60,
- "daType": 17,
- "fileBytesApprox": 247000
- },
"acceptance": "Intern only structurally and semantically identical templates. Expanded 32/119/860/906/4925 model, FC ownership, values and round-trip behavior must remain unchanged."
},
"saveEnrichmentReuse": {
diff --git a/landing/device-evidence.json b/landing/device-evidence.json
index 9a17341ec..787304dac 100644
--- a/landing/device-evidence.json
+++ b/landing/device-evidence.json
@@ -14,7 +14,7 @@
{
"id": "field-profile-a-file-service",
"publicLabel": "Anonymized field profile A — MMS file-service transport",
- "identityDisclosure": "Vendor, model, installation and firmware are not published.",
+ "identityDisclosure": "Device model, installation and firmware identifiers are not published.",
"evidenceDate": "2026-07",
"services": {
"mmsAssociation": "observed",
@@ -44,7 +44,7 @@
{
"id": "field-profile-b-rcb-export",
"publicLabel": "Anonymized field profile B — RCB and SCL export evidence",
- "identityDisclosure": "Vendor, model, installation and firmware are not published.",
+ "identityDisclosure": "Device model, installation and firmware identifiers are not published.",
"evidenceDate": "2026-07",
"services": {
"mmsAssociation": "observed",
@@ -59,7 +59,7 @@
"conditions": [
"Live RCB names, TriggerOptions, OptionalFields, BufTm and IntgPd were preserved as read-only evidence.",
"Selected-RCB export retained the exact live MMS RCB identity and avoided duplicate instance suffixes.",
- "Exported SCL remains an engineering baseline and requires independent schema, project and vendor validation.",
+ "Exported SCL remains an engineering baseline and requires independent schema, project and implementation validation.",
"No runtime RCB reservation or write is implied by this evidence profile."
],
"evidenceLinks": [
diff --git a/landing/partials/footer.html b/landing/partials/footer.html
index 51d17d447..00d42f3ce 100644
--- a/landing/partials/footer.html
+++ b/landing/partials/footer.html
@@ -15,7 +15,7 @@
Use the evidence to narrow the cause—not to claim conformance.
ARSAS can expose live model, report, GOOSE, file, control and diagnostic evidence. Final conclusions still depend on the approved project design, vendor documentation, test procedure, network access and independent verification.
Use the evidence to narrow the cause—not to claim conformance.
ARSAS can expose live model, report, GOOSE, file, control and diagnostic evidence. Final conclusions still depend on the approved project design, device documentation, test procedure, network access and independent verification.
Engineering purpose · open source · practical evidence
Built to make practical IEC 61850 work clearer and faster.
ARSAS is an independent open-source Windows engineering workstation created to reduce repetitive setup during IEC 61850 laboratory work, FAT, SAT, commissioning, troubleshooting and multi-vendor integration.
Engineering purpose · open source · practical evidence
Built to make practical IEC 61850 work clearer and faster.
ARSAS is an independent open-source Windows engineering workstation created to reduce repetitive setup during IEC 61850 laboratory work, FAT, SAT, commissioning, troubleshooting and multi-device integration.
Useful testing should begin from the evidence available in the IED.
IEC 61850 workflows can lose significant time before the first useful value appears: preparing engineering files, inspecting DataSets, finding usable Report Control Blocks, mapping signals across tools and diagnosing why communication works while reporting remains silent.
ARSAS brings live MMS discovery, reporting visibility, GOOSE supervision, file transfer, SCL context, control evidence and diagnostics into one focused workspace.
ARSAS does not claim universal interoperability, conformance certification, switching authority or replacement of approved vendor engineering systems. It is designed to expose live behavior, preserve negative evidence and help engineers make better-informed decisions.
Capability status, preview scope, limitations and safety boundaries remain explicit throughout the product website.
+
Why ARSAS exists
Useful testing should begin from the evidence available in the IED.
IEC 61850 workflows can lose significant time before the first useful value appears: preparing engineering files, inspecting DataSets, finding usable Report Control Blocks, mapping signals across tools and diagnosing why communication works while reporting remains silent.
ARSAS brings live MMS discovery, reporting visibility, GOOSE supervision, file transfer, SCL context, control evidence and diagnostics into one focused workspace.
ARSAS does not claim universal interoperability, conformance certification, switching authority or replacement of approved engineering systems. It is designed to expose live behavior, preserve negative evidence and help engineers make better-informed decisions.
Capability status, preview scope, limitations and safety boundaries remain explicit throughout the product website.
Author and maintainer
{{AUTHOR_NAME}}
Ari Sulistiono is a substation automation engineer focused on protection and control, IEC 61850 communication, testing, commissioning, troubleshooting and practical engineering productivity.
ARSAS turns recurring field and integration problems into a reusable public engineering tool while keeping customer, employer, credential, relay-setting and substation data outside the repository.
Source, architecture and issue history are public.
Developers, contributors and technical reviewers can inspect the implementation, license, engineering boundaries and project history on GitHub. Product documentation and release guidance remain available throughout this website.
Status · kondisi · tanggal evidence · public record
Compatibility adalah klaim evidence per service—bukan sekadar logo vendor.
ARSAS hanya mempublikasikan evidence yang dapat dikaitkan dengan behavior protokol, versi aplikasi, kondisi dan engineering record publik. Saat ini belum ada entry vendor/model yang dipublikasikan dengan nama.
Status · kondisi · tanggal evidence · public record
Compatibility adalah klaim evidence per service—bukan sekadar label produk.
ARSAS hanya mempublikasikan evidence yang dapat dikaitkan dengan behavior protokol, versi aplikasi, kondisi dan engineering record publik. Saat ini belum ada entry implementasi perangkat/model yang dipublikasikan dengan nama.
VerifiedConditionalObservedNot testedFailed with known issue
“Verified” berarti ada repeated evidence untuk scope service yang dinyatakan. Status ini bukan sertifikasi conformity IEC 61850 dan tidak mengesahkan seluruh firmware, Logical Device atau konfigurasi proyek.
- Tanggal evidence · 2026-07
Profile field anonim A — transport MMS file service
Vendor, model, instalasi dan firmware tidak dipublikasikan. Evidence publik membahas behavior protokol, bukan endorsement produk.
Service
Status
MMS association
Observed
FileDirectory
Verified
File transfer
Conditional
Live model, reporting, GOOSE, control
Not tested
Kondisi
Nested FileDirectory entry dan rooted file path teramati.
FileOpen dapat mengembalikan signed Integer32 FRSM termasuk nilai negatif.
Respons FileRead besar memerlukan segmented COTP reassembly.
Transfer berhasil tidak membuktikan record lengkap atau scaling COMTRADE.
Registry publik device-evidence.json memuat profile ID, status service, kondisi dan public link yang sama dengan halaman ini. CI menolak status tidak dikenal, link hilang atau named-device claim tanpa metadata evidence.
Sertakan versi ARSAS, operating system, service yang diuji, diagnostic sanitized, firmware bila boleh dibuka dan hasil yang reproducible. Credential serta identifier rahasia harus dihapus.
Registry publik device-evidence.json memuat profile ID, status service, kondisi dan public link yang sama dengan halaman ini. CI menolak status tidak dikenal, link hilang atau identified-device claim tanpa metadata evidence.
Laporkan behavior service, bukan hanya label produk.
Sertakan versi ARSAS, operating system, service yang diuji, diagnostic sanitized, firmware bila boleh dibuka dan hasil yang reproducible. Credential serta identifier rahasia harus dihapus.
Schema · identity · references · edition · live recovery
A rejected CID file does not automatically mean the relay is not interoperable.
First determine whether the failure is XML syntax, SCL structure, physical identity, edition handling, vendor-private content, broken references or a mismatch between the file and the running IED. When the source cannot be repaired safely, complete live discovery can provide a new bounded baseline.
Preserve the original file and capture the exact import error.
Do not begin by deleting arbitrary XML sections. Record the parser location or rejected reference, the receiving tool and edition expectation, then compare the file with live IED evidence.
Typical symptoms
schema or namespace error during import
unknown or unsupported edition element
physical IED identity or MMS domain mismatch
unresolved DataSet, FCDA, RCB or communication reference
vendor-private section rejected by another tool
file imports but reporting remains silent
Diagnostic path
Separate file validity from integration usefulness.
A file can be valid XML but unsuitable for a target configurator. It can also import successfully while representing an outdated device model, incorrect identity or incomplete reporting assignment.
01
Record the receiving-system evidence
Keep the original filename, edition, namespace, exact error message, reported location and receiving software version.
02
Validate identity and critical references
Trace physical IED name, AccessPoint, server, full Logical Device domains, DataSets, FCDA members, RCBs and communication references without blind deletion.
03
Compare with the live IED
Confirm endpoint, complete typed model, DataSet directory, concrete RCB names and options currently exposed by the relay.
04
Choose the recovery path
Repair or normalize the opened source when its relationships remain trustworthy. Otherwise generate Edition 2 IID or Edition 1 ICD from complete live discovery.
05
Reduce only when the receiving workflow requires it
For a bounded gateway or legacy SAS path, audit availability and export exactly one verified RCB as an Edition 1 or Edition 2 CID baseline.
Live recovery can preserve
Relationships commonly damaged by manual cleanup.
physical identity separate from MMS Logical Device domains
complete typed hierarchy and available type information
DataSet membership and member order
exact indexed runtime RCB names
available trigger, optional-field and timing evidence
source, endpoint and export provenance
Still requires validation
The receiving importer remains authoritative for acceptance.
Generated SCL is vendor-neutral and schema-aware, but proprietary tools can apply rules beyond the standard. Retest the exact importer and preserve its result as project evidence.
Build a bounded integration baseline
Select the intended RCB, retain verified DataSet members and choose the required SCL edition instead of removing unrelated XML through trial and error.
Related guides
Check whether the file still matches the running relay.
Continue with live-model comparison, the IP-to-SCL workspace or the complete multi-vendor integration workflow.
Schema · identity · references · edition · live recovery
A rejected CID file does not automatically mean the relay is not interoperable.
First determine whether the failure is XML syntax, SCL structure, physical identity, edition handling, implementation-private content, broken references or a mismatch between the file and the running IED. When the source cannot be repaired safely, complete live discovery can provide a new bounded baseline.
Preserve the original file and capture the exact import error.
Do not begin by deleting arbitrary XML sections. Record the parser location or rejected reference, the receiving tool and edition expectation, then compare the file with live IED evidence.
Typical symptoms
schema or namespace error during import
unknown or unsupported edition element
physical IED identity or MMS domain mismatch
unresolved DataSet, FCDA, RCB or communication reference
implementation-private section rejected by another tool
file imports but reporting remains silent
Diagnostic path
Separate file validity from integration usefulness.
A file can be valid XML but unsuitable for a target configurator. It can also import successfully while representing an outdated device model, incorrect identity or incomplete reporting assignment.
01
Record the receiving-system evidence
Keep the original filename, edition, namespace, exact error message, reported location and receiving software version.
02
Validate identity and critical references
Trace physical IED name, AccessPoint, server, full Logical Device domains, DataSets, FCDA members, RCBs and communication references without blind deletion.
03
Compare with the live IED
Confirm endpoint, complete typed model, DataSet directory, concrete RCB names and options currently exposed by the relay.
04
Choose the recovery path
Repair or normalize the opened source when its relationships remain trustworthy. Otherwise generate Edition 2 IID or Edition 1 ICD from complete live discovery.
05
Reduce only when the receiving workflow requires it
For a bounded gateway or legacy SAS path, audit availability and export exactly one verified RCB as an Edition 1 or Edition 2 CID baseline.
Live recovery can preserve
Relationships commonly damaged by manual cleanup.
physical identity separate from MMS Logical Device domains
complete typed hierarchy and available type information
DataSet membership and member order
exact indexed runtime RCB names
available trigger, optional-field and timing evidence
source, endpoint and export provenance
Still requires validation
The receiving importer remains authoritative for acceptance.
Generated SCL is implementation-neutral and schema-aware, but proprietary tools can apply rules beyond the standard. Retest the exact importer and preserve its result as project evidence.
Build a bounded integration baseline
Select the intended RCB, retain verified DataSet members and choose the required SCL edition instead of removing unrelated XML through trial and error.
Related guides
Check whether the file still matches the running relay.
Continue with live-model comparison, the IP-to-SCL workspace or the complete multi-device integration workflow.
Gunakan Direct atau SBO bertipe hanya saat procedure, role dan kondisi plant mengizinkan active control.
05
Pertahankan negative evidence
Unsupported service, rejected write, report gap, timeout dan command failure tetap terlihat untuk root-cause analysis.
Event evidence dengan konteks perangkat
Pisahkan continuous value dari perubahan bermakna sambil mempertahankan timestamp, quality, source dan IED attribution.
Berguna untuk
Investigasi live-system yang terkontrol.
Troubleshooting reporting dan quality
Pemeriksaan GOOSE sequence dan subscription
Review control completion dan feedback
Pengambilan fault record setelah event
Diagnostik komunikasi multi-IED
Batas engineering
Kewenangan commissioning tetap berada di luar aplikasi.
ARSAS tidak memberikan switching permission, menentukan keselamatan plant, menggantikan protection testing, menyetujui setting atau meniadakan site procedure, cybersecurity control dan independent verification.
ARSAS does not grant switching permission, determine plant safety, replace protection testing, approve settings or override site procedures, cybersecurity controls and independent verification.
-
Related workflows
Connect commissioning evidence to the project lifecycle.
Status · conditions · evidence date · public record
Compatibility is a service-level evidence claim—not a vendor logo.
ARSAS publishes only bounded evidence that can be tied to a protocol behavior, application version, condition and public engineering record. There are currently no publicly named vendor/model entries.
Status · conditions · evidence date · public record
Compatibility is a service-level evidence claim—not a device implementation logo.
ARSAS publishes only bounded evidence that can be tied to a protocol behavior, application version, condition and public engineering record. There are currently no publicly named device implementation/model entries.
VerifiedConditionalObservedNot testedFailed with known issue
“Verified” means repeated evidence exists for the declared service scope. It is not IEC 61850 conformance certification and does not approve every firmware, Logical Device or project configuration.
- Evidence date · 2026-07
Anonymized field profile A — MMS file-service transport
Vendor, model, installation and firmware are not published. The public evidence concerns protocol behavior, not product endorsement.
Service
Status
MMS association
Observed
FileDirectory
Verified
File transfer
Conditional
Live model, reporting, GOOSE, control
Not tested
Conditions
Nested FileDirectory entries and rooted file paths were observed.
FileOpen could return a signed Integer32 FRSM, including negative values.
Large FileRead responses required segmented COTP reassembly.
Transfer success does not prove record completeness or COMTRADE scaling.
The public device-evidence.json registry contains the same profile IDs, service statuses, conditions and public links shown here. CI rejects unsupported status values, missing links or a named-device claim without explicit evidence metadata.
Provide the ARSAS version, operating system, service under test, sanitized diagnostics, firmware when disclosure is allowed and a reproducible result. Confidential identifiers and credentials must be removed.
The public device-evidence.json registry contains the same profile IDs, service statuses, conditions and public links shown here. CI rejects unsupported status values, missing links or a identified-device claim without explicit evidence metadata.
Report the service behavior—not only the product label.
Provide the ARSAS version, operating system, service under test, sanitized diagnostics, firmware when disclosure is allowed and a reproducible result. Confidential identifiers and credentials must be removed.
{{> download-cta}}
diff --git a/landing/templates/faq-arsas.html b/landing/templates/faq-arsas.html
index da4053efa..8c8fbf596 100644
--- a/landing/templates/faq-arsas.html
+++ b/landing/templates/faq-arsas.html
@@ -29,7 +29,7 @@
-
+
{{> header}}
@@ -42,7 +42,7 @@
Mengapa Windows SmartScreen dapat memberi warning?
Binary Windows publik saat ini belum Authenticode-signed. Cocokkan exact SHA-256 di Download Center sebelum digunakan. Warning tidak disembunyikan dan juga bukan bukti otomatis malware.
Apa perbedaan Installer dan Portable ZIP?
Scope fitur IEC 61850 sama. Installer memberi registrasi Windows, Start menu dan uninstall. Portable berjalan dari folder writable yang disetujui dan diperbarui dengan mengganti package.
Apakah Npcap wajib?
Npcap diperlukan untuk capture raw-Ethernet GOOSE dan Sampled Values. Association MMS, model discovery, read, reporting, generate SCL dan file service biasa tidak secara inheren memerlukan Npcap.
- Apakah ARSAS mendukung semua vendor IEC 61850?
Tidak ada klaim universal vendor. Generated SCL bersifat vendor-neutral, typed dan schema-aware, tetapi compatibility tetap service-specific dan proprietary importer dapat memiliki rule di luar standard. Setiap receiving system harus divalidasi.
+ Apakah ARSAS mendukung semua implementasi IEC 61850?
Tidak ada klaim universal untuk seluruh implementasi. Generated SCL bersifat implementation-neutral, typed dan schema-aware, tetapi compatibility tetap service-specific dan proprietary importer dapat memiliki rule di luar standard. Setiap receiving system harus divalidasi.
Apakah ARSAS dapat membuat atau menulis DataSet dan RCB?
Konfigurasi existing dan evidence read-only diprioritaskan. Workflow recovery tertentu hanya memakai write bila supported, enabled dan authorized. Write berhasil tidak membuktikan konfigurasi proyek benar.
Apakah ARSAS dapat melakukan control?
Workflow Direct dan Select-Before-Operate tersedia secara guarded. Active control memerlukan procedure, plant authority, interlock yang benar dan independent safety check.
Apakah ARSAS aman untuk jaringan operasional?
Tidak ada software yang sendirian dapat menyatakan jaringan aman. Gunakan hanya dalam boundary laboratorium, FAT, SAT atau commissioning yang disetujui dengan routing, permission dan recovery procedure terkontrol.
diff --git a/landing/templates/faq.html b/landing/templates/faq.html
index 9d6a1e01b..23b919606 100644
--- a/landing/templates/faq.html
+++ b/landing/templates/faq.html
@@ -29,7 +29,7 @@
-
+
{{> header}}
@@ -42,7 +42,7 @@
Why can Windows SmartScreen show a warning?
The current public Windows binaries are not Authenticode-signed. Verify the exact SHA-256 published in the Download Center before use. The warning is not hidden or presented as proof of malware.
What is the difference between Installer and Portable ZIP?
The IEC 61850 feature scope is the same. Installer provides Windows registration, Start menu and uninstall behavior. Portable ZIP runs from an approved writable folder and is updated by replacing the package.
Is Npcap required?
Npcap is required for raw-Ethernet GOOSE and Sampled Values capture. Ordinary MMS association, model discovery, reads, reporting, SCL generation and file-service workflows do not inherently require Npcap.
- Does ARSAS support every IEC 61850 vendor?
No universal vendor claim is made. Generated SCL is vendor-neutral, typed and schema-aware, but compatibility is service-specific and proprietary importers may add rules beyond the standard. Validate every receiving system.
+ Does ARSAS support every IEC 61850 implementation?
No universal implementation claim is made. Generated SCL is implementation-neutral, typed and schema-aware, but compatibility is service-specific and proprietary importers may add rules beyond the standard. Validate every receiving system.
Can ARSAS create or write DataSets and RCBs?
Existing configuration and read-only evidence are preferred. Specific recovery workflows may use writes only where supported, enabled and authorized. A successful write is not proof that the project configuration is correct.
Can ARSAS operate control objects?
Guarded Direct and Select-Before-Operate workflows exist. Active control requires an approved procedure, plant authority, correct interlocks and independent safety checks. Never use a software button as the sole authorization.
Is ARSAS safe for an operational network?
No software alone can declare an operational network safe. Use ARSAS only inside an approved laboratory, FAT, SAT or commissioning boundary with controlled routing, permissions and recovery procedures.
Move from endpoint access to witnessed service evidence.
Adapt the sequence to the approved FAT procedure and project responsibilities.
01
Connect and discover
Add the approved endpoint, establish MMS association and inspect the live hierarchy, DataSets, RCBs and control model.
02
Select the FAT signals
Choose status, measurement, quality and timestamp points required by the test sheet instead of mapping the entire IED blindly.
03
Validate acquisition
Prefer configured reporting, verify exact DataSet membership and keep unsupported or unavailable coverage visible.
04
Inspect GOOSE and control
Check stream identity and sequence evidence, then execute only approved Direct or SBO operations with visible completion results.
05
Confirm files and diagnostics
Probe available fault records and retain communication, report, frame and service outcomes with the originating IED.
Keep evidence attributable to the tested IED
Whether the session starts from an IO List or manual signal selection, review identity, object reference, value, quality, timestamp and acquisition source together.
-
Useful for
Protection and substation automation FAT.
SDI IO List indication proof
Relay and bay-controller communication checks
BRCB and URCB behavior
GOOSE publishing and subscription evidence
Direct and SBO control validation
Disturbance-record file access
Boundary
FAT acceptance remains procedural.
ARSAS does not replace calibrated injection equipment, protection-function testing, approved drawings, settings review, cybersecurity controls, witness sign-off, digital signatures or vendor responsibility. IO List FAT is available on current mainline; verify the stable release scope before use.
ARSAS does not replace calibrated injection equipment, protection-function testing, approved drawings, settings review, cybersecurity controls, witness sign-off, digital signatures or implementation responsibility. IO List FAT is available on current mainline; verify the stable release scope before use.
GOOSE sequence values explain whether the publisher changed state or retransmitted the same state.
Interpret sequence evidence together with goCBRef, DataSet, APPID, VLAN, source MAC, TAL and payload. One counter alone is not enough to identify the stream.
stNum
State number
A new published state is normally associated with a state-number change. Confirm that the ordered payload or relevant status also changed as expected.
sqNum
Sequence number
Retransmissions of the current state normally advance sequence evidence. Gaps, resets or unexpected patterns require context from capture continuity and publisher restart behavior.
Diagnostic path
Supervise the whole stream identity.
First prove that consecutive frames belong to the same publisher and control block. Then examine state, sequence, retransmission interval and TAL behavior.
01
Bind the stream identity
Use source and destination MAC, APPID, VLAN, goCBRef and DataSet reference.
02
Track state transitions
Compare stNum with the ordered allData payload and the expected process event.
03
Track retransmission
Inspect sqNum progression and frame timing while the state remains unchanged.
04
Supervise TAL and capture gaps
Separate a publisher that exceeded its advertised lifetime from a local capture interruption or interface problem.
Observe sequence and payload together
ARSAS keeps stream identity, flags, TAL, counters and ordered payload visible in one GOOSE session.
A counter reset is not automatically a device fault.
Publisher restart, configuration activation or capture discontinuity can change the observed pattern. Correlate the timing with device and project events.
A healthy sequence does not prove correct semantics.
The stream can be timely and internally consistent while the DataSet order, scaling or subscriber mapping is wrong.
Related pages
Continue with GOOSE workflow evidence.
Review the analyzer capability and multi-vendor integration path.
GOOSE sequence values explain whether the publisher changed state or retransmitted the same state.
Interpret sequence evidence together with goCBRef, DataSet, APPID, VLAN, source MAC, TAL and payload. One counter alone is not enough to identify the stream.
stNum
State number
A new published state is normally associated with a state-number change. Confirm that the ordered payload or relevant status also changed as expected.
sqNum
Sequence number
Retransmissions of the current state normally advance sequence evidence. Gaps, resets or unexpected patterns require context from capture continuity and publisher restart behavior.
Diagnostic path
Supervise the whole stream identity.
First prove that consecutive frames belong to the same publisher and control block. Then examine state, sequence, retransmission interval and TAL behavior.
01
Bind the stream identity
Use source and destination MAC, APPID, VLAN, goCBRef and DataSet reference.
02
Track state transitions
Compare stNum with the ordered allData payload and the expected process event.
03
Track retransmission
Inspect sqNum progression and frame timing while the state remains unchanged.
04
Supervise TAL and capture gaps
Separate a publisher that exceeded its advertised lifetime from a local capture interruption or interface problem.
Observe sequence and payload together
ARSAS keeps stream identity, flags, TAL, counters and ordered payload visible in one GOOSE session.
A counter reset is not automatically a device fault.
Publisher restart, configuration activation or capture discontinuity can change the observed pattern. Correlate the timing with device and project events.
A healthy sequence does not prove correct semantics.
The stream can be timely and internally consistent while the DataSet order, scaling or subscriber mapping is wrong.
Related pages
Continue with GOOSE workflow evidence.
Review the analyzer capability and multi-device integration path.
{{> guide-boundary}}{{> download-cta}}{{> footer}}
\ No newline at end of file
diff --git a/landing/templates/id.html b/landing/templates/id.html
index ed746827e..58ec8ec97 100644
--- a/landing/templates/id.html
+++ b/landing/templates/id.html
@@ -52,7 +52,7 @@
Belajar sambil bekerja
Setiap halaman fitur harus menjawab “apa ini, kapan digunakan, dan apa yang bisa gagal?”
Pusat Belajar menghubungkan konsep protokol dengan workflow ARSAS yang nyata, lalu mengarahkan langsung ke troubleshooting saat hasil yang diharapkan tidak muncul.
Periksa produk Windows yang bekerja, bukan marketing mockup.
Screenshot publik menunjukkan session IED independen, live value, supervisi GOOSE dan diagnostic. Tutorial menjelaskan apa yang perlu diperhatikan pada setiap workspace.
Session multi-IED independen
Setiap device mempertahankan association, model dan diagnostic history sendiri.
Live value attributable
Identity, reference, value, quality, timestamp dan acquisition source tetap bersama.
Supervisi GOOSE
Periksa identity stream, sequence, retransmission dan ordered payload evidence.
Diagnostic yang dapat disalin
Pertahankan failure attributable sebelum mengubah IED, network atau project file.
Every feature page should answer “what is it, when do I use it, and what can go wrong?”
The Learning Center connects protocol concepts to the actual ARSAS workflow, then links directly to troubleshooting when the expected result does not appear.
Inspect the working Windows product—not a marketing mockup.
Current screenshots show independent IED sessions, live values, GOOSE supervision and diagnostics. The tutorials explain what to look for in each workspace.
01Independent multi-IED sessions
Each device retains its own association, model, monitoring state and diagnostic history.
IP-to-SCL · live model · reporting · GOOSE · integrasi gateway
Integrasi multi-vendor IEC 61850 dengan jalur recovery saat vendor file gagal.
Gunakan ARSAS untuk discovery complete live IED model, generate IID atau ICD ketika vendor file tidak usable, normalize bounded single-IED SCL, membandingkan configured intent dengan runtime evidence, dan mengisolasi mismatch reporting atau GOOSE sebelum mengubah project tujuan.
IP-to-SCL · live model · reporting · GOOSE · integrasi gateway
Integrasi multi-perangkat IEC 61850 dengan jalur recovery saat engineering file gagal.
Gunakan ARSAS untuk discovery complete live IED model, generate IID atau ICD ketika engineering file tidak usable, normalize bounded single-IED SCL, membandingkan configured intent dengan runtime evidence, dan mengisolasi mismatch reporting atau GOOSE sebelum mengubah project tujuan.
Recovery dari IPComplete live discovery menjadi IID Edition 2 atau ICD Edition 1
Normalize SCLBounded generic single-IED conversion dengan structured findings
Verifikasi runtimeReporting, GOOSE, identity, DataSet dan RCB dalam live context
Export sengajaSatu verified RCB sebagai baseline CID Edition 1 atau Edition 2
Workflow yang disarankan
Temukan mismatch sebelum mengubah salah satu sistem.
Failure interoperability biasanya berada di antara tiga sumber: IED yang online, engineering file yang menggambarkan intended configuration, dan proprietary expectation SAS atau gateway penerima.
01
Identifikasi source yang tersedia
Mulai dari alamat IP IED, CID/ICD/IID/SCD yang tersedia, atau keduanya. Pertahankan original file dan catat receiving system yang dituju.
02
Discovery IED live secara lengkap
Periksa physical identity, full MMS domain, hierarchy, DataSet, RCB, type information dan service behavior aktual.
03
Generate atau normalize bounded SCL
Buat IID/ICD dari complete live discovery, atau convert opened source menjadi generic single-IED output sambil mempertahankan findings dan provenance.
Import bounded output, pertahankan exact error, lalu pisahkan masalah schema, identity, reference, reporting dan proprietary importer sebelum melakukan perubahan.
Failure yang umum
“CID rejected” bukan root cause.
Physical IED identity tidak cocok dengan project penerima
Logical Device domain dipotong atau ditafsirkan ulang
Expectation Edition 1 dan Edition 2 berbeda
DataSet member atau FCDA reference hilang
Indexed RCB name dimodifikasi secara salah
Receiving tool menerapkan proprietary rule yang tidak terdokumentasi
Evidence path ARSAS
Pertahankan setiap layer tetap terlihat.
Live device identity dan complete model
Original configured SCL intent
Generated atau normalized bounded output
Read-only live RCB availability serta options
Observed GOOSE communication dan payload
Exact receiving-system import result
-
Bounded selected-RCB CID export
Audit live availability, pilih reporting path dan pertahankan exact RCB identity serta verified DataSet evidence sebelum export baseline integrasi.
-
Berguna untuk
Integrasi SAS, gateway dan IED.
Recovery saat vendor CID atau ICD tidak dapat dipakai
Alignment project Edition 1 dan Edition 2
Troubleshooting DataSet dan RCB reporting
Verifikasi address, reference dan payload GOOSE
Perbandingan configured-to-live model
Attribution diagnostic multi-IED
Batas engineering
Evidence bukan universal conformance.
Koneksi, generation atau import yang berhasil belum membuktikan conformance penuh, interoperability dengan semua vendor, kebenaran project atau acceptance oleh proprietary tool lain. Final validation FAT/SAT tetap diperlukan.
+
Bounded selected-RCB CID export
Audit live availability, pilih reporting path dan pertahankan exact RCB identity serta verified DataSet evidence sebelum export baseline integrasi.
+
Berguna untuk
Integrasi SAS, gateway dan IED.
Recovery saat CID perangkat atau ICD tidak dapat dipakai
Alignment project Edition 1 dan Edition 2
Troubleshooting DataSet dan RCB reporting
Verifikasi address, reference dan payload GOOSE
Perbandingan configured-to-live model
Attribution diagnostic multi-IED
Batas engineering
Evidence bukan universal conformance.
Koneksi, generation atau import yang berhasil belum membuktikan conformance penuh, interoperability dengan semua implementasi, kebenaran project atau acceptance oleh proprietary tool lain. Final validation FAT/SAT tetap diperlukan.
IP-to-SCL · live model · reporting · GOOSE · gateway integration
Multi-vendor IEC 61850 integration with a recoverable path when the vendor file fails.
Use ARSAS to discover the complete live IED model, generate IID or ICD when the available vendor file is unusable, normalize bounded single-IED SCL, compare configured intent with runtime evidence, and isolate reporting or GOOSE mismatches before editing the target project.
IP-to-SCL · live model · reporting · GOOSE · gateway integration
Multi-device IEC 61850 integration with a recoverable path when the engineering file fails.
Use ARSAS to discover the complete live IED model, generate IID or ICD when the available engineering file is unusable, normalize bounded single-IED SCL, compare configured intent with runtime evidence, and isolate reporting or GOOSE mismatches before editing the target project.
Recover from IPComplete live discovery to Edition 2 IID or Edition 1 ICD
Normalize SCLBounded generic single-IED conversion with structured findings
Verify runtimeReporting, GOOSE, identity, DataSets and RCBs in live context
Export intentionallyOne verified RCB as an Edition 1 or Edition 2 CID baseline
Suggested workflow
Find the mismatch before changing either system.
Interoperability failures usually sit between three sources: the IED that is online, the engineering file that describes intended configuration, and the proprietary expectations of the receiving SAS or gateway.
01
Identify the available source
Start from the approved IED IP address, the available CID/ICD/IID/SCD, or both. Preserve the original file and record the intended receiving system.
02
Discover the live IED completely
Inspect physical identity, full MMS domains, hierarchy, DataSets, RCBs, type information and service behavior actually exposed by the device.
03
Generate or normalize bounded SCL
Create IID or ICD from complete live discovery, or convert the opened source into a generic single-IED output while retaining findings and provenance.
Import the bounded output, retain exact errors, and separate schema, identity, reference, reporting and proprietary importer problems before making changes.
Typical failure
“CID rejected” is not a root cause.
Physical IED identity does not match the receiving project
Logical Device domains were shortened or reinterpreted
Edition 1 and Edition 2 expectations differ
DataSet members or FCDA references are missing
An indexed RCB name was modified incorrectly
The receiving tool applies an undocumented proprietary rule
ARSAS evidence path
Keep each layer visible.
Live device identity and complete model
Original configured SCL intent
Generated or normalized bounded output
Read-only live RCB availability and options
Observed GOOSE communication and payload
Exact receiving-system import result
-
Bounded selected-RCB CID export
Audit live availability, choose the intended reporting path and preserve exact RCB identity plus verified DataSet evidence before exporting the integration baseline.
-
Useful for
SAS, gateway and IED integration.
Recovering when a vendor CID or ICD cannot be used
Edition 1 and Edition 2 project alignment
Reporting DataSet and RCB troubleshooting
GOOSE address, reference and payload verification
Configured-to-live model comparison
Multi-IED diagnostic attribution
Boundary
Evidence is not universal conformance.
A successful connection, generation or import does not prove full IEC 61850 conformance, interoperability with every vendor, project correctness or acceptance by another proprietary tool. Final FAT/SAT engineering validation remains required.
+
Bounded selected-RCB CID export
Audit live availability, choose the intended reporting path and preserve exact RCB identity plus verified DataSet evidence before exporting the integration baseline.
+
Useful for
SAS, gateway and IED integration.
Recovering when a device CID or ICD cannot be used
Edition 1 and Edition 2 project alignment
Reporting DataSet and RCB troubleshooting
GOOSE address, reference and payload verification
Configured-to-live model comparison
Multi-IED diagnostic attribution
Boundary
Evidence is not universal conformance.
A successful connection, generation or import does not prove full IEC 61850 conformance, interoperability with every implementation, project correctness or acceptance by another proprietary tool. Final FAT/SAT engineering validation remains required.
Dari akses endpoint menuju service evidence yang dapat disaksikan.
Sesuaikan urutan dengan FAT procedure dan tanggung jawab proyek yang sudah disetujui.
01
Connect dan discovery
Tambahkan endpoint, bangun association MMS dan periksa hierarchy live, DataSet, RCB serta control model.
02
Pilih signal FAT
Pilih status, measurement, quality dan timestamp yang dibutuhkan test sheet tanpa mapping seluruh IED secara buta.
03
Validasi acquisition
Prioritaskan configured reporting, periksa membership DataSet secara tepat dan pertahankan coverage yang tidak tersedia tetap terlihat.
04
Periksa GOOSE dan control
Review identity serta sequence stream, lalu jalankan Direct atau SBO hanya bila diizinkan dengan hasil completion yang terlihat.
05
Konfirmasi file dan diagnostik
Probe fault record dan pertahankan outcome komunikasi, report, frame serta service bersama IED asal.
Pertahankan evidence attributable ke IED yang diuji
Baik session dimulai dari IO List maupun manual signal selection, review identity, object reference, value, quality, timestamp dan acquisition source bersama-sama.
-
Berguna untuk
FAT proteksi dan substation automation.
Proof indication SDI dari IO List
Communication check relay dan bay controller
Perilaku BRCB dan URCB
Evidence publishing dan subscription GOOSE
Validasi Direct dan SBO control
Akses disturbance-record file
Batas engineering
Acceptance FAT tetap bersifat prosedural.
ARSAS tidak menggantikan calibrated injection equipment, pengujian fungsi proteksi, approved drawing, settings review, cybersecurity control, witness sign-off, digital signature atau tanggung jawab vendor. IO List FAT tersedia pada mainline saat ini; verifikasi scope stable release sebelum penggunaan.
ARSAS tidak menggantikan calibrated injection equipment, pengujian fungsi proteksi, approved drawing, settings review, cybersecurity control, witness sign-off, digital signature atau tanggung jawab implementation. IO List FAT tersedia pada mainline saat ini; verifikasi scope stable release sebelum penggunaan.
Konfirmasi apa yang berubah antara factory dan site.
Instalasi, addressing, gateway mapping, switch configuration dan final project file dapat menimbulkan perbedaan yang tidak terlihat saat FAT.
01
Verifikasi akses endpoint
Konfirmasi IP address, interface dan association MMS independen untuk perangkat yang sudah terpasang.
02
Bandingkan configured dan live context
Gunakan SCL sebagai project intent sambil memeriksa model dan service yang benar-benar ditawarkan IED.
03
Validasi report dan value
Konfirmasi coverage DataSet, state RCB, quality, timestamp dan reason-for-inclusion.
04
Periksa perilaku GOOSE
Bandingkan APPID, VLAN, destination MAC, sequence counter, retransmission dan ordered payload dengan site design.
05
Isolasi kegagalan integrasi
Gunakan diagnostik per IED untuk membedakan association, report, frame, gateway, file-service dan command-completion problem.
Session independen untuk perangkat terpasang
Model, monitoring, reporting, event, file dan diagnostik tetap dapat dikaitkan ke setiap IED saat sistem gardu diuji.
Berguna untuk
Validasi site end-to-end.
Connectivity relay dan bay controller terpasang
Investigasi signal path SCADA dan gateway
GOOSE subscription dan station-bus check
Evidence control completion dan feedback
Akses disturbance record
Batas engineering
SAT tetap merupakan aktivitas proyek terkontrol.
ARSAS tidak menggantikan approved site procedure, authorization keamanan network, injection test, wiring check, protection-setting verification, switching control atau customer acceptance record.
ARSAS does not replace approved site procedures, network-security authorization, injection testing, wiring checks, protection-setting verification, switching control or customer acceptance records.
Practical tutorial · ICD · CID · SCD · IID · live model
Understand the SCL file, compare it with the IED and export only what the next system needs.
ARSAS helps engineers open configured SCL, discover a live IED model from an approved IP address, preserve identity and relationships, and prepare bounded IID, ICD or CID output. The useful outcome is not simply “valid XML”—it is a traceable baseline that the receiving SAS, gateway or engineering tool can independently validate.
SCL is the engineering description that connects device capability, project configuration and system integration.
ICD commonly describes what an IED can support. CID commonly describes the configuration delivered to one IED. SCD represents the integrated substation project. IID is commonly used for an instantiated IED description exchanged during engineering updates. These are practical roles, not permission to ignore edition, schema, project-profile or vendor rules.
SCL is the engineering description that connects device capability, project configuration and system integration.
ICD commonly describes what an IED can support. CID commonly describes the configuration delivered to one IED. SCD represents the integrated substation project. IID is commonly used for an instantiated IED description exchanged during engineering updates. These are practical roles, not permission to ignore edition, schema, project-profile or implementation rules.
Choose the file by its job, not only its extension.
ICD — IED Capability Description
A capability-oriented description supplied for system engineering. It commonly represents the functions, data and communication features an IED family or configuration can offer.
CID — Configured IED Description
A device-focused configured description intended for one IED. It may include communication, DataSets, reports, GOOSE and project-specific settings.
SCD — Substation Configuration Description
The wider integrated system model produced by system configuration engineering, including multiple IEDs, communication relationships and substation context.
IID — Instantiated IED Description
An instantiated IED description used in supported engineering exchange or update workflows, especially where Edition 2-oriented tooling expects device-specific system context.
SSD — System Specification Description
A specification-oriented view of substation functions and topology before all IED implementation details are assigned.
Edition and profile matter
The same extension does not guarantee identical schema edition, namespace, optional content or importer behavior. Confirm the receiving contract.
-
When to use SCL Workspace
Use it when configured intent and live evidence must be compared or exchanged.
Missing or stale file
Build a typed baseline from live discovery
Use an approved IED endpoint when the available vendor file is missing, outdated or cannot explain the online server model.
Importer rejection
Reduce the input to a bounded device scope
Preserve exact identity, model, DataSet and RCB evidence while avoiding an oversized multi-IED project file for a limited receiver.
Integration review
Compare live model and configured intent
Keep differences visible instead of silently replacing the source file or assuming the running IED exactly matches the project SCL.
Reporting handover
Export one verified RCB path
Prepare a selected-RCB CID baseline when the receiving SAS or gateway needs one explicit reporting path.
+
When to use SCL Workspace
Use it when configured intent and live evidence must be compared or exchanged.
Missing or stale file
Build a typed baseline from live discovery
Use an approved IED endpoint when the available implementation file is missing, outdated or cannot explain the online server model.
Importer rejection
Reduce the input to a bounded device scope
Preserve exact identity, model, DataSet and RCB evidence while avoiding an oversized multi-IED project file for a limited receiver.
Integration review
Compare live model and configured intent
Keep differences visible instead of silently replacing the source file or assuming the running IED exactly matches the project SCL.
Reporting handover
Export one verified RCB path
Prepare a selected-RCB CID baseline when the receiving SAS or gateway needs one explicit reporting path.
-
Before you start
Ask what the receiving system actually accepts.
Required file type and IEC 61850 edition
Expected physical IED name and AccessPoint identity
Allowed namespace, schema and vendor profile
Required DataSets, RCBs, GOOSE or communication sections
Whether a full project, one IED or one selected RCB is required
Source boundary
Configured intent and live evidence are different sources.
An SCL file can be stale or incomplete. A live IED model can omit wider project relationships. Preserve both, record provenance and make differences reviewable rather than declaring either source universally correct.
+
Before you start
Ask what the receiving system actually accepts.
Required file type and IEC 61850 edition
Expected physical IED name and AccessPoint identity
Allowed namespace, schema and implementation profile
Required DataSets, RCBs, GOOSE or communication sections
Whether a full project, one IED or one selected RCB is required
Source boundary
Configured intent and live evidence are different sources.
An SCL file can be stale or incomplete. A live IED model can omit wider project relationships. Preserve both, record provenance and make differences reviewable rather than declaring either source universally correct.
Step-by-step in ARSAS
Create a bounded SCL baseline without losing the source context.
01
Define the receiving-system requirement
Record the target tool, edition, expected IED identity, required services and whether it needs IID, ICD, CID or another approved SCL scope.
02
Choose live discovery or an existing SCL source
Connect to an approved IED for complete MMS discovery, or open the available SCD, CID, ICD, IID, SSD or compatible XML. Keep the original file unchanged.
03
Verify physical identity and model hierarchy
Separate the physical IED name from MMS domains and Logical Devices. Review Logical Nodes, Data Objects, Data Attributes, types and Functional Constraints.
04
Review DataSets, RCBs and communication context
Check member order, exact runtime RCB names, trigger options, optional fields, report IDs, configuration revision, endpoint and available GOOSE or communication identity.
05
Choose the bounded target output
Generate Edition 2 IID or Edition 1 ICD from complete live discovery where appropriate, normalize a single-IED source, or select one verified RCB for a bounded CID baseline.
06
Validate the output in the receiving system
Review SCL, companion evidence and findings, then import into the intended SAS, gateway or engineering tool. Record every rejection or modification instead of editing identity by trial and error.
@@ -37,7 +37,7 @@
What is the difference between ICD, CID, SCD and IID?
ICD commonly describes IED capability, CID one configured IED, SCD the integrated substation project and IID an instantiated IED exchange or update description. Verify the exact edition and project profile.
Can a live IED model replace the project SCD?
No. Live discovery shows what one server exposes now. The SCD can contain wider system, subscriber and communication relationships that one IED cannot reveal.
Does valid XML guarantee the SCL will import correctly?
No. The receiver may apply identity, edition, namespace, DataSet, RCB and proprietary profile rules. Review the resulting imported model.
-
Next lesson
Compare the configured stream with observed GOOSE traffic.
Use GOOSE Analyzer to verify publisher identity, sequence, TAL and payload order, while keeping subscriber operation and end-to-end protection acceptance as separate tests.
Compare the configured stream with observed GOOSE traffic.
Use GOOSE Analyzer to verify publisher identity, sequence, TAL and payload order, while keeping subscriber operation and end-to-end protection acceptance as separate tests.
IO List FAT · general FAT · SAT · commissioning · integration
IEC 61850 workflows that turn approved inputs into project evidence and reusable output.
Start from an approved ARSAS IO List when a digital-indication test plan already exists, or start from an endpoint/SCL for general engineering. ARSAS keeps device identity, live behavior, evidence and bounded project output connected.
Start from the IO ListStrict SDI plan, one-IED execution and ordered transition evidence
Start from the endpointComplete live model discovery without requiring usable vendor SCL
Export evidenceExcel result, native PDF and verified portable .arsas project
Carry context forwardFAT, SAT, commissioning and integration remain attributable per IED
+
Start from the IO ListStrict SDI plan, one-IED execution and ordered transition evidence
Start from the endpointComplete live model discovery without requiring usable device SCL
Export evidenceExcel result, native PDF and verified portable .arsas project
Carry context forwardFAT, SAT, commissioning and integration remain attributable per IED
Project workflows
Choose the starting condition and stage you are preparing for.
The IO List workspace is a read-only test-plan layer for imported SDI points. General FAT and engineering workflows continue to cover discovery, reporting, GOOSE, files, SCL and guarded control.
Factory test plan
IO List FAT evidence
Import approved digital indications, bind to the intended IED, require OFF → ON → OFF, and export Excel, native PDF or a resumable .arsas project.
Validate the complete live model, selected signals, reports, GOOSE, control outcomes, disturbance-record access and integration output before shipment.
Use General IEC 61850 Testing for endpoint-led engineering. Use FAT / IO List Testing for imported SDI plans and durable transition evidence. Both retain the originating IED and explicit evidence boundaries.
-
Practical value
Start from the approved evidence source.
Use an IO List for repeatable indication proof, or use the endpoint and SCL context to investigate broader IEC 61850 services. Preserve what happened and what still requires review.
Engineering boundary
ARSAS supports the test process.
It does not replace approved procedures, calibrated test equipment, protection-setting verification, switching authority, witness acceptance, formal signatures, target-system import validation or vendor responsibility.
+
Practical value
Start from the approved evidence source.
Use an IO List for repeatable indication proof, or use the endpoint and SCL context to investigate broader IEC 61850 services. Preserve what happened and what still requires review.
Engineering boundary
ARSAS supports the test process.
It does not replace approved procedures, calibrated test equipment, protection-setting verification, switching authority, witness acceptance, formal signatures, target-system import validation or device-owner responsibility.
Technical review is part of the product—not decorative copy.
ARSAS documentation distinguishes what the current software visibly demonstrates, what depends on relay support or project permissions, what is still preview quality, and what remains roadmap intent.
Tutorial praktis · ICD · CID · SCD · IID · live model
Pahami file SCL, bandingkan dengan IED dan export hanya yang dibutuhkan sistem berikutnya.
ARSAS membantu engineer membuka configured SCL, discovery live model dari alamat IP IED yang disetujui, mempertahankan identity serta relationship, lalu menyiapkan bounded output IID, ICD atau CID. Hasil yang berguna bukan hanya “XML valid”, tetapi baseline traceable yang dapat diverifikasi ulang oleh SAS, gateway atau engineering tool penerima.
SCL adalah deskripsi engineering yang menghubungkan capability perangkat, konfigurasi proyek dan integrasi sistem.
ICD umumnya menjelaskan capability IED. CID umumnya menjelaskan konfigurasi untuk satu IED. SCD mewakili project gardu yang terintegrasi. IID lazim digunakan sebagai instantiated IED description pada workflow exchange atau update engineering. Peran praktis ini tidak menghapus aturan edition, schema, project profile atau vendor.
SCL adalah deskripsi engineering yang menghubungkan capability perangkat, konfigurasi proyek dan integrasi sistem.
ICD umumnya menjelaskan capability IED. CID umumnya menjelaskan konfigurasi untuk satu IED. SCD mewakili project gardu yang terintegrasi. IID lazim digunakan sebagai instantiated IED description pada workflow exchange atau update engineering. Peran praktis ini tidak menghapus aturan edition, schema, project profile atau implementation.
Pilih file berdasarkan tugasnya, bukan hanya extension.
ICD — IED Capability Description
Deskripsi berorientasi capability untuk system engineering. Umumnya berisi fungsi, data dan communication feature yang dapat ditawarkan sebuah IED atau keluarga produk.
CID — Configured IED Description
Deskripsi configured yang berfokus pada satu IED. Dapat membawa communication, DataSet, report, GOOSE dan setting yang spesifik terhadap proyek.
SCD — Substation Configuration Description
Model sistem terintegrasi dari proses system configuration, termasuk banyak IED, communication relationship dan konteks substation.
IID — Instantiated IED Description
Deskripsi instantiated IED untuk workflow exchange atau update engineering yang didukung, terutama pada toolchain berorientasi Edition 2.
SSD — System Specification Description
View berorientasi specification terhadap fungsi dan topologi substation sebelum seluruh detail implementasi IED ditetapkan.
Edition dan profile tetap penting
Extension yang sama tidak menjamin edition schema, namespace, optional content atau behavior importer yang sama. Konfirmasi contract receiving system.
-
Kapan memakai Workspace SCL
Gunakan saat configured intent dan live evidence harus dibandingkan atau dipertukarkan.
File hilang atau stale
Buat typed baseline dari live discovery
Gunakan endpoint IED yang disetujui saat vendor file hilang, outdated atau tidak dapat menjelaskan online server model.
Importer menolak file
Kurangi input menjadi bounded device scope
Pertahankan exact identity, model, DataSet dan RCB evidence tanpa mengirim project multi-IED yang terlalu besar ke receiver terbatas.
Review integrasi
Bandingkan live model dengan configured intent
Biarkan perbedaan terlihat. Jangan diam-diam mengganti source file atau berasumsi running IED identik dengan project SCL.
Handover reporting
Export satu verified RCB path
Siapkan baseline CID selected-RCB ketika SAS atau gateway penerima hanya membutuhkan satu reporting path yang eksplisit.
+
Kapan memakai Workspace SCL
Gunakan saat configured intent dan live evidence harus dibandingkan atau dipertukarkan.
File hilang atau stale
Buat typed baseline dari live discovery
Gunakan endpoint IED yang disetujui saat implementation file hilang, outdated atau tidak dapat menjelaskan online server model.
Importer menolak file
Kurangi input menjadi bounded device scope
Pertahankan exact identity, model, DataSet dan RCB evidence tanpa mengirim project multi-IED yang terlalu besar ke receiver terbatas.
Review integrasi
Bandingkan live model dengan configured intent
Biarkan perbedaan terlihat. Jangan diam-diam mengganti source file atau berasumsi running IED identik dengan project SCL.
Handover reporting
Export satu verified RCB path
Siapkan baseline CID selected-RCB ketika SAS atau gateway penerima hanya membutuhkan satu reporting path yang eksplisit.
-
Sebelum mulai
Tanyakan apa yang benar-benar diterima receiving system.
Tipe file dan IEC 61850 edition yang diperlukan
Physical IED name dan AccessPoint identity yang diharapkan
Namespace, schema dan vendor profile yang diperbolehkan
DataSet, RCB, GOOSE atau communication section yang dibutuhkan
Apakah receiver memerlukan full project, satu IED atau satu selected RCB
Batas source
Configured intent dan live evidence adalah dua sumber berbeda.
SCL dapat stale atau incomplete. Live IED model dapat tidak membawa relationship proyek yang lebih luas. Pertahankan keduanya, catat provenance dan buat perbedaan dapat direview.
+
Sebelum mulai
Tanyakan apa yang benar-benar diterima receiving system.
Tipe file dan IEC 61850 edition yang diperlukan
Physical IED name dan AccessPoint identity yang diharapkan
Namespace, schema dan implementation profile yang diperbolehkan
DataSet, RCB, GOOSE atau communication section yang dibutuhkan
Apakah receiver memerlukan full project, satu IED atau satu selected RCB
Batas source
Configured intent dan live evidence adalah dua sumber berbeda.
SCL dapat stale atau incomplete. Live IED model dapat tidak membawa relationship proyek yang lebih luas. Pertahankan keduanya, catat provenance dan buat perbedaan dapat direview.
Langkah di ARSAS
Buat baseline SCL yang bounded tanpa kehilangan source context.
01
Tentukan requirement receiving system
Catat target tool, edition, expected IED identity, service yang dibutuhkan dan apakah memerlukan IID, ICD, CID atau scope SCL lain yang disetujui.
02
Pilih live discovery atau source SCL existing
Hubungkan IED yang disetujui untuk complete MMS discovery, atau buka SCD, CID, ICD, IID, SSD maupun XML kompatibel yang tersedia. File source asli tetap tidak berubah.
03
Verifikasi physical identity dan model hierarchy
Pisahkan physical IED name dari MMS domain serta Logical Device. Review Logical Node, Data Object, Data Attribute, type dan Functional Constraint.
Generate IID Edition 2 atau ICD Edition 1 dari complete live discovery jika sesuai, normalize source menjadi single-IED, atau pilih satu verified RCB untuk baseline CID yang bounded.
06
Validasi output pada receiving system
Review SCL, companion evidence dan findings, lalu import ke SAS, gateway atau engineering tool yang dituju. Catat setiap rejection atau modification, jangan mengubah identity dengan trial and error.
@@ -37,7 +37,7 @@
Apa perbedaan ICD, CID, SCD dan IID?
ICD umumnya menjelaskan capability IED, CID satu IED configured, SCD project gardu terintegrasi dan IID deskripsi instantiated IED untuk exchange atau update. Verifikasi edition dan project profile yang berlaku.
Apakah live model IED dapat menggantikan project SCD?
Tidak. Live discovery memperlihatkan apa yang ditawarkan satu server sekarang. SCD dapat membawa system, subscriber dan communication relationship yang tidak dapat diungkap satu IED.
Apakah XML valid menjamin SCL dapat diimport dengan benar?
Tidak. Receiver dapat menerapkan aturan identity, edition, namespace, DataSet, RCB dan proprietary profile. Review model hasil import.
-
Pelajaran berikutnya
Bandingkan configured stream dengan traffic GOOSE yang diamati.
Gunakan Analyzer GOOSE untuk memverifikasi publisher identity, sequence, TAL dan payload order, sementara subscriber operation serta acceptance proteksi end-to-end tetap menjadi test terpisah.
Bandingkan configured stream dengan traffic GOOSE yang diamati.
Gunakan Analyzer GOOSE untuk memverifikasi publisher identity, sequence, TAL dan payload order, sementara subscriber operation serta acceptance proteksi end-to-end tetap menjadi test terpisah.