Skip to content

BLOCKED P10.9E — ARIEC core routing guard pin requires additive CodeVerified provenance, not merge-ready - #530

Draft
masarray wants to merge 1 commit into
fix/512-goose-event-header-alignmentfrom
fix/p10-9e-core-report-route-lock
Draft

masarray wants to merge 1 commit into
fix/512-goose-event-header-alignmentfrom
fix/p10-9e-core-report-route-lock

Conversation

@masarray

Copy link
Copy Markdown
Owner

Functional core engine integration, no new BCUGE diagnostic-only milestone

Based exactly on field-proven ARSAS P10.9C staging 83e3ac4d4437f60b73b3a1328c1188dc36c3d4a5 and pinned ARIEC staging fa93c9fdc7cd98fd3624227ee21c3eefc68bcac7. This one-file-only PR updates engines/ARIEC61850.lock.json from the old engine commit 00ad2819b99ffe6b3f885e59aa24a6afb2b4d8e1 to exact validated engine commit fa93c9fdc7cd98fd3624227ee21c3eefc68bcac7.

What actually changes in ARSAS client

ARIEC PR #164 (engine .NET Windows CI #38142115574 SUCCESS) corrects a proven report identity safety flaw: previously if MMS RptID uniquely matched a subscribed RCB yet the decoded report advertised a different domain-qualified DatSet, engine might project values using wrong member mapping. Now such explicitly contradictory reports are quarantined before process-value publication, preserving compatibility with omitted or abbreviated DatSet fields. Four new deterministic core tests, all passed. ARSAS engine lock guarantees the Windows artifact builds against the fixed code rather than unknowingly reusing prior DLLs. This is an actual runtime consumer change, not extra diagnostic fields.

Distinct simulator fix in the same engine ancestry

ARIEC PR #163, .NET CI #38141582981 SUCCESS, corrected another independently reproducible correctness race in the standalone ARIEC simulator: per-report Task.Run could serialize MMS frames on wire in a different order from server-side SqNum assignment. One FIFO sender per association replaces per-report tasks and has a deterministic two-GI blocked-send regression. ARSAS does not reference the Simulation project, so this simulator-only fix is not claimed to change the ARSAS executable's reception of external BCUGE reports.

Safety and field scope

  • ARSAS main untouched, candidate branch from P10.9C. Exactly one JSON lock file changed, no UI, report activation, SCL model, RCB/GI controls, decoder, GOOSE, MMS process polling, data reads, physical IED control or workflow changes.
  • Current private BCUGE 19:41 / 19:43 WIB evidence: 8 DataSets / 124 static members, 67/67 displayed, 6/6 exact routed RCBs, zero cyclic polling; 19 SqNum discontinuities and two BufOvfl on each ingress. Neither fix is claimed to resolve all these external simulator warnings, because logs don't prove contradictory DatSet, and ARIEC simulator code always produces BufOvfl=false. Keep BRCB Issue #520 open; no repeated identical field logs requested merely for this patch.
  • Validate exact engine lock, full ARSAS .NET Windows native bridge regression and artifact on PR-head CI before stage promotion. Preserve P10.9C/P10.9B/P10.9A/P10.8E/P10.6 checkpoints and pinned field model paths. Guarded FF only; parent #512 stays draft. Physical capture still required before making SOE losslessness claims.

@masarray masarray changed the title P10.9E — pin verified ARIEC core RptID/DatSet consistency guard without changing static acquisition BLOCKED P10.9E — ARIEC core routing guard pin requires additive CodeVerified provenance, not merge-ready Oct 11, 2026

Copy link
Copy Markdown
Owner Author

HARD BLOCK — 2026-10-11 exact candidate CI; do not promote

Candidate commit 3e84d6951fa405f8ceb2505664f91e57827e3060 is NOT merge-ready. All 14 workflows terminal: 4 SUCCESS, 10 FAILURE, 0 pending. The new pinned upstream engine fa93c9fdc7cd98fd3624227ee21c3eefc68bcac7 independently passed both ARIEC .NET CIs and compilation in canonical ARSAS Build #38142378711, but 3 of 1593 consumer xUnit tests failed because current ARSAS physical provenance and CodeVerified pin rules explicitly accept old engine 00ad2819..., not a new unqualified core revision. Other IO/SV/R7/production workflows fail closed at this same authority boundary. Do not bypass these tests, rewrite immutable physical evidence or fake an accepted R10 result. No portable EXE for this failed candidate and no main/staging/release merge.

Preserved safe baseline: ARSAS staging 83e3ac4d4437f60b73b3a1328c1188dc36c3d4a5, consumer lock 00ad2819b99ffe6b3f885e59aa24a6afb2b4d8e1, safe checkpoint checkpoint/p10-9c-discovery-last-ip-83e3ac4d, 16/16 prior staging CI green.

Unblock plan: Issue #531 defines an explicit provenance/ancestry-bound CodeVerified-only trial (without modifying historical field-tested physical authority), negative CI tests for forbidden main/release promotion, then exact-head consumer full CI. This draft PR may be reused only if all gates pass under that approved additive scope. Upstream ARIEC #163 and #164 are already merged and individually engine-CI green. BCUGE external BRCB anomalies are not claimed resolved by either patch; Issue #520 remains open.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant