Skip to content

P10.6: resolve Discovery IP IED Name using previously verified IID (BCUGE) without guessing MMS domain - #517

Merged
masarray merged 8 commits into
fix/512-goose-event-header-alignmentfrom
fix/p10-6-remembered-trusted-scl-discovery-identity
Oct 11, 2026
Merged

masarray merged 8 commits into
fix/512-goose-event-header-alignmentfrom
fix/p10-6-remembered-trusted-scl-discovery-identity

Conversation

@masarray

Copy link
Copy Markdown
Owner

P10.6 — fix IP-only Discovery name authority from independently verified original IID

Actual attached physical/simulator captures (2026-10-11)

Two user Diagnostic Reports show same IP 192.16.1.33:102, same MMS raw domain BCUGEF650 and same pinned engine 00ad2819..., but Discovery reports IED_192_16_1_33 HostFallback (Low) while Open SCL from original BCU_GE.iid, IED BCUGE, AP S1, succeeds and reports BCUGE. Both paths independently route 6/6 real static RCB and 67 process points, zero cyclic polling. Discovery source cannot reliably partition BCUGEF650 as BCUGE + F650 without engineering proof.

Correction

  • First successful SCL-assisted MMS association now saves the operator-opened IID source path along with already-persisted exact SHA-256 + IED + AP + IP:port. This is an additive optional JSON field, backward-compatible with legacy endpoint history. Offline file open or a mere guessed IP never creates source authority.
  • Subsequent standalone IP Discovery re-loads source, SHA-256 validates original bytes, uses engine's exact unique SCL IED/AP/domain matcher against the fresh full observed MMS domain set, and requires exact endpoint and unique single AP. Multiple matching sources, changed files, missing source, mismatched endpoint/LDs, multi-AP or >16 candidates all fail closed. No device/vendor heuristic, IP-only guess, extra MMS requests, or dynamic polling. If no previously verified source exists, honest fallback remains, with explanation to operator.
  • Keep TrustedLiveIdentity proof association-only (non-serialized), reset on each new connection. Do not replace engine LiveDiscoveryModel immutable wire provenance, or attach SclWorkspace/activate Open SCL flow. Static reporting/GOOSE remain live MMS-owned.
  • Parity correction: a fresh trusted high-confidence identity proof allows live engine model to retain IED_192_16_1_33 while consumer semantic fingerprint uses verified BCUGE; manual card renames without a matching trusted proof are rejected.
  • Regression: original GE F650 IID match and LP mapping, no prior successful connection, legacy records, edited IID SHA, wrong IP, wrong domain, competing IID files, multiAP SCL, and parity fail-closed boundary.
  • Consumer-only diff: no ARIEC61850 engine change, lock stays 00ad2819b99ffe6b3f885e59aa24a6afb2b4d8e1. Base is 11/11-green P10.5 staging 6f717890849e3e33c7e107440c60dbb351f55fc2.

Important acceptance constraints

Manual: On this new version, first Open original BCU_GE.iid and successfully Play to the same 192.16.1.33:102 once, then start fresh IP-only Discovery (can restart app). The next scan should identify BCUGE, TrustedSclExactDomainMatch (High) with exact raw MMS BCUGEF650, and show unchanged static report 67/67 / 6/6. Unmodified older EXEs have no stored source path and therefore cannot retroactively auto-verify their history. Standalone first-ever Discovery without operator IID remains provisional by protocol design. Physical R10 and public main release remain gated; do not suppress BRCB warnings or infer GOOSE event loss.

CI: draft until exact-head Windows build and regression green; then guarded FF only into staging (no main/release).

@masarray
masarray merged commit a883510 into fix/512-goose-event-header-alignment Oct 11, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant