Skip to content

P7.6C #446: auditable bounded per-RCB continuity evidence in Copy Diagnostic - #485

Draft
masarray wants to merge 6 commits into
feat/446-p7-6c-iec-report-continuity-evidencefrom
feat/446-p7-6c-per-rcb-continuity-snapshot
Draft

masarray wants to merge 6 commits into
feat/446-p7-6c-iec-report-continuity-evidencefrom
feat/446-p7-6c-per-rcb-continuity-snapshot

Conversation

@masarray

@masarray masarray commented Oct 8, 2026 •

Copy link
Copy Markdown
Owner

Exact-head CI and field-build qualification — 2026-10-09

  • 10/10 triggered GitHub Actions workflows SUCCESS for exact commit 8d764128ccf764b20d27d178dfec64ec71581b81, including additional SCL Interoperability R7 Build.
  • Merge Execution Guard: 1,400 passed, 0 failed, 0 skipped ARSAS.Tests, including 7 new per-RCB metadata coverage/sanitization/association-isolation tests.
  • Native Windows x64 main build, publish, tests and smoke: SUCCESS; portable single-EXE artifact.
  • Smart Discovery Field Capture: SUCCESS; field-capture x64 artifact.
  • SCL Interoperability R7: SUCCESS; R7 artifact.
  • Earlier 0a137004 compile/regression attempt found fixture-only sanitization test position issue: malicious CRLF was placed after 550 characters and intentionally truncated at 240. Fixed fixture to place CRLF before suffix so both escaping and truncation are genuinely asserted. The first failing attempt is retained in history, without weakening production escaping or skipping tests.
  • CodeCommitted / CIPassed / ArtifactAvailable: YES. P7.6B field startup semantic/report parity: verified via separately captured ingress runs. P7.6C physical SqNum metadata/reconnect/SOE completeness: pending updated field capture. Dual-in-app ingress proof and AP F physical route: pending. PR remains DRAFT / not MergeReady / not Merged / not Released, engine pin unchanged.

Field-driven continuation, stacked on P7.6C #484

Operator performed same-build Open SCD AP J and Discovery IP real field tests (Oct 9 local time), ARSAS build f9e4a4ed1ad450469a28fdda8b3ab10cada260a6 (CI-generated merge of P7.6C #484 HEAD 397d7836e5b071d4f3c6b375f9c51879c58eeb48 into P7.6B #483 5a05ab2), engine immutable 352c81e6a798635c6addcee0683235ca87ad416d. Both paths: exact same cb563f... semantic fingerprint, 13/13 displayed static values, 2/2 per-ingress RCB routed process data, 0 uncovered, 0 cyclic MMS polling. No sequence-discontinuity warning appears in these startup diagnostic excerpts.

Gap discovered: absence of WARN cannot prove the inspector actually received frame metadata, nor show SqNum OptionFields presence or observed-frame count. These ~30-s startup captures also do not qualify reconnect, event replay, SOE continuity, BRCB gap classification, or GI causality. Both sessions are independent app processes and still show AWAITING PEER INGRESS.

Scoped implementation

  • Pure, per-association per-RCB counters in existing standard-aware continuity inspector (frames, sequenced/missing SqNum, segments, warnings, BufOvfl, ConfRev changes, opaque EntryID presence only, first/last SeqNum).
  • Publish immutable snapshot atomically from monitor runtime at most once per nonempty report slice; Copy Diagnostic gives explicit NO FRAME METADATA, PARTIAL SqNum EVIDENCE, ANOMALY OBSERVED, INCOMPLETE, or OBSERVED WITHOUT SEQUENCE ALERTS. Every status explicitly notes decoded frame observations cannot prove SOE continuity.
  • Bound source stream dictionary to 64 per association (adversarial RptID churn); output to 12 streams with 240-char sanitized identifiers; stream overflow emits warning. Decode/report value path remains untouched.
  • Reset all snapshot/counts on start/restart/reconnect, do not borrow evidence across associations.
  • New synthetic regression tests for no-metadata vs observed, partial SqNum, physical backward 4→1, ConfRev+BufOvfl, immutable copy, bounded malicious labels, and lifecycle resets.

Ownership / safety / qualification

This is DIAGNOSTIC EVIDENCE ONLY. No IEC engine pin update, MMS semantics, RCB enable/disable/GI, control output, cyclic reads, report value acceptance, model rewrites, or cross-session proof persistence. Four existing files touched (inspector, runtime diagnostic only, monitor model diagnostic property, Copy Diagnostic), plus one test file. No real device addresses or diagnostic payloads committed.

Multi-thread coordination: this draft owns only report continuity region of Iec61850MonitorRuntime.cs and per-device snapshot; rebase/coordinate with concurrent work. Keep #485 stacked/draft; code/CI/artifact/physical reconnect gates remain explicit. Parent issue #446. Base immutable #484 head 397d7836e5b071d4f3c6b375f9c51879c58eeb48.

masarray commented Oct 9, 2026

Copy link
Copy Markdown
Owner Author

P7.6D — engine-decoded OptFlds provenance workstream / ownership (2026-10-09)

Draft PR #487 on P7.6C #485 exact head 8d764128ccf764b20d27d178dfec64ec71581b81 (standalone sibling to IED dialog UX #486, not a rewritten UI baseline). Exact HEAD 3f2bc75d9efb3bbe84c0808650b17f64bbda4808. CI pending.

Root cause confirmed from pinned ARIEC engine source: MmsReportFrameMapper.DecodeHeader already extracts report wire OptFlds as MmsReportOptionalFields.RawHex plus typed HasSequenceNumber/HasEntryId/HasBufferOverflow/HasConfRevision. ARSAS NativeIec61850Client dropped OptionalFields when mapping engine report frame to consumer NativeReportFrameMetadata; therefore diagnostics for real pair GR_X_7SX85 couldn't distinguish wire omitted vs requested but not decoder-projected vs no OptFlds evidence.

Narrow read-only fix: preserve nullable decoded option bits and a maximum 8-byte hex mask; distinguish unknown/omitted/advertised-but-undecoded counters per exact RCB and write bounded evidence to Copy Diagnostic. Keep conservative SqNum 0→0 duplicate/replay warning and no-event-loss assertion. Test missing, explicitly omitted, unknown, contradictory SqNum/EntryID, empty EntryID ambiguities, hostile hex, engine-owned decoding boundary. 5 files only (adapter, immutable metadata, continuity inspector, diagnostics, new tests); no MMS/RCB writes/GI/control/polling/SCL/engine pin/runtime value path changes.

Parallel ownership: #487 owns ONLY these OptFlds provenance adapter/inspector/diagnostics lines, #486 native dialog UX owns separate XAML and dialog source; coordinate stack integration without dropping either. Physical reconnect/SOE event-history and in-app paired-ingress proof not achieved; do not merge/release prematurely. CI budget: one atomic 5-file tree push, one minimal wording contract correction, now wait on exact HEAD, not repeated speculative commits.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant