Skip to content

Consume smart interoperability engine and unify Discovery/Open-SCL runtime planning #446

Description

@masarray

Parent engine work

Tracks ARIEC61850 issue #144:
masarray/ARIEC61850#144

Consumer invariant

ARSAS must treat IP Discovery and Open SCL as two bootstrap/evidence sources for the same IED.

Both paths must converge into:

  • the same canonical IED model;
  • the same MMS connection/session lifecycle;
  • the same acquisition planner;
  • the same reporting executor;
  • the same control runtime;
  • the same diagnostics/evidence model.

ARSAS must not carry a second copy of IEC 61850 protocol semantics or vendor-specific workarounds.

Field regression motivating this issue

A user test with a 7SX85-class IED showed:

  • 2 configured static DataSets, 12 represented static members;
  • 6 BRCB + 6 URCB instances discovered;
  • URCB static reporting successfully active;
  • BRCB activation failed because the engine wrote ResvTms with the wrong MMS scalar type;
  • individual signal selection can still fall to MMS polling despite static DataSet coverage.

The engine defect belongs in ARIEC61850; ARSAS must consume the corrected engine behavior and remove/avoid downstream divergent planning.

ARSAS implementation strategy

A1 — One model boundary

Introduce/strengthen one canonical-model access boundary for downstream runtime consumers. Discovery-built and SCL-built models may retain provenance but must expose the same semantic contract.

A2 — One acquisition intent

ARSAS supplies intent/policy only:

  • selected signals;
  • prefer reporting;
  • whether dynamic DataSet mutation is allowed;
  • whether residual polling is allowed.

ARIEC61850 owns:

  • RCB semantics;
  • field types;
  • ownership/reservation;
  • static/dynamic report qualification;
  • transactional activation;
  • report proof.

A3 — Static coverage first for every selection path

Individual selections must use configured static DataSet/RCB coverage before dynamic reporting or polling.

If one selected signal is contained in a configured static DataSet:

  • subscribe to the full ordered DataSet on the wire;
  • project only selected signals into the ARSAS runtime/UI;
  • do not create a dynamic DataSet merely to isolate that signal.

A4 — Common reporting path

Do not maintain separate "Discovery reporting" and "SCL reporting" engines. After canonical-model convergence both must execute through the same report planning and activation contracts.

Open SCL may use bounded online reconciliation rather than full rediscovery, but this must not create a separate runtime semantics stack.

A5 — Evidence-first diagnostics

Surface enough engine evidence to explain:

  • why a point is StaticBrcb / StaticUrcb / Dynamic / Polling residual / Unavailable;
  • exact DataSet and RCB chosen;
  • whether evidence is exact/reduced/missing/blocked;
  • why a fallback happened;
  • whether real InformationReport traffic proved acquisition.

Acceptance criteria

For the same physical IED and equivalent selected signals:

Discovery IP -> canonical model -> acquisition plan
Open SCL     -> canonical model -> acquisition plan

must produce semantically equivalent:

  • LD/LN/DO/DA identities required by runtime;
  • DataSet identities and ordered membership after reconciliation;
  • RCB family/binding;
  • control model;
  • selected signal resolution;
  • report acquisition plan.

For a test set of 6 BRCB-backed + 6 URCB-backed signals, both paths should converge to the same static acquisition classification when live state permits it.

No ARSAS vendor-name condition or duplicated ResvTms type workaround is acceptable.

Activity

  1. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    Engine implementation has started in ARIEC61850 draft PR #145 (issue #144). The first slice fixes the BRCB ResvTms wire type at the engine semantic boundary rather than adding an ARSAS/vendor workaround.

    ARSAS consumer changes will follow the engine gate: consume the qualified engine, then implement the common canonical-model/static-first acquisition convergence required here.

  2. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    Coordination update: engine #144/#145 now has a source-neutral configured-static activation entry point plus a pure CanonicalIedModel static coverage resolver. This is intentionally being built in ARIEC first so ARSAS can later consume one canonical static-first plan instead of adding another app-side heuristic.

    I am not modifying active ARSAS PR #425 (SCL association consumer) or PR #445 (canonical package CI). The eventual #446 consumer change should layer on top of those accepted/parallel authorities rather than fork them.

  3. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    Coordination checkpoint:

    I re-audited current ARSAS parallel ownership before consumer work.

    On the engine side, #145 base lane is now repaired and CI-green at 302f7882... / CI #737. The next transactional readback-proof slice is isolated as stacked ARIEC PR #146 instead of being mixed into ARSAS.

    I am intentionally not repinning engines/ARIEC61850.lock.json or creating a competing ARSAS consumer branch yet: doing so would overlap active PR #425's engine-lock ownership. Consumer convergence will start from the coordinated post-#145/#425 base, not by overwriting those parallel lanes.

  4. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    Smart hot-path consumer preparation is now staged on branch fix/446-smart-report-hotpath, based directly on active PR #425 head (not on main).

    The staged consumer logic:

    • builds/caches the engine-owned CanonicalIedModel from Live Discovery or source-correct Open-SCL ingress;
    • resolves selected points to configured static coverage locally (zero MMS traffic);
    • asks ARIEC to resolve covered DataSets to concrete live RCB targets;
    • uses targeted availability only when dynamic residual search is unnecessary;
    • otherwise retains broad availability so dynamic reporting safety is not accidentally hidden;
    • explicitly enables ARIEC's reduced-evidence configured-static policy, which still requires populated live DataSet + RptEna=false + no positive busy evidence and does not relax dynamic mutation;
    • diagnostics report targeted RCB count/read budget/DataSet cache hits.

    I have intentionally not opened/CI-promoted this consumer branch yet: PR #425 has a strict engine-lock/interoperability guard that requires its physically accepted #143 pin. Repointing that lock in a sibling thread would violate the teamwork boundary. The combined engine candidate needed by this consumer is CodeVerified at ARIEC integration head c0609d5... / CI #747; consumer pinning should be stacked/coordinated only after the #425 ownership gate is resolved.

  5. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    Engine P6 consumer-contract milestone is now staged in ARIEC61850 PR #150.

    Important integration rule for ARSAS: an inventory projected from Open SCL may be used for structural/canonical planning, but must not be labeled operational live RCB evidence. The new engine preflight requires explicit LiveMmsObserved authority before it will resolve/authorize concrete runtime RCB targets and perform targeted availability.

    This is designed so the eventual #446 consumer becomes thin:
    selected signal intent -> engine canonical coverage/preflight -> engine exact-target availability -> ARSAS presentation/runtime binding.

    No ARSAS files or engine lock were modified here because PR #425 still owns that surface.

  6. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    ARIEC P6 contract is now software-gated: combined exact head 51fa7092e83472a125aae9a29f033d31f59e6281 passed .NET CI #758.

    The future ARSAS consumer should therefore delete/reduce local IEC orchestration rather than add another path:

    1. selected signal intent -> canonical selections;
    2. engine source-aware static acquisition preflight;
    3. engine exact-target availability;
    4. ARSAS only binds returned plan/result to runtime/UI.

    Engine now also supplies canonical structural report-inventory projection with no fabricated RCB01/live-state attributes, which is the intended replacement for ARSAS-side trusted-SCL inventory fabrication.

    Still intentionally no engine-lock repin or edit to PR #425-owned SCL-association files from this lane.

  7. 54 remaining items

  8. masarray commented on Oct 9, 2026

    @masarray
    OwnerAuthor

    **Native WPF IED dialogs UX PR #486 final exact-HEAD 56de3e2e0e82f01f04c49ca270d37f752e99f86f: 9/9 GitHub Actions SUCCESS; 1404/1404 regression tests passed; native Windows portable EXE artifact #11587495503, field-capture Win-x64 #11587595323. Restyled IED Actions + Add IEC 61850 IED dialog-only with high-contrast light surface, natural height/scroll clipping protection, reduced noisy copy and preserved action/validation contracts. No engine/RCB/GI/report/session code edited. Visual user QA pending, draft/no merge/release. Owns only dialog view, small dialog copy C#, isolated dialog styles and two offline tests; preserve P7.6C #485 as stacked dependency.

  9. masarray commented on Oct 9, 2026

    @masarray
    OwnerAuthor

    P7.6C Oct 9 real diagnostic verification — startup observability validated, SOE continuity not yet qualified

    Operator supplied two separate ARSAS native startup diagnostic reports, same app assembly 1.6.40+0871caebe886327b4e442ee329a7d9fe95a9b895 (GitHub test merge, parents 397d7836e5b071d4f3c6b375f9c51879c58eeb48 and 8d764128ccf764b20d27d178dfec64ec71581b81, i.e. #485 built on #484), same engine lock 352c81e6a798635c6addcee0683235ca87ad416d. This does not include later native-dialog UX #486 HEAD 56de3e2, so it is not visual QA for #486.

    Open SCD AP J vs Discovery IP: both connected, monitoring, exact source-neutral fingerprint cb563f46ea1a61634ab67c6af4802d353d8d8f9caf8e793b7a89580525ffd206 with same three semantic basis rows, selected static values 13/13, exact RCB traffic 2/2 independently, zero uncovered and zero cyclic MMS polling. Indexed BRCB: Open SCD Rpt_ind01, Discovery Rpt_ind02 (excluded from semantic parity by design).

    New P7.6C evidence captured successfully in BOTH app processes: Report continuity : ANOMALY OBSERVED • frames=3, sequenced=2, processUpdates=60, streams=2, findings=1, BufOvfl=0, untracked=0. BRCB frames=2, SqNum=2, firstSqNum=0, lastSqNum=0, findings=1, EntryIDPresent=0, ConfRevChanges=0; early warning sequence discontinuity (duplicate/replay): previous=0, current=0. URCB frames=1, SqNum=0, missingSqNum=1, no findings. Identical pattern across separate access paths suggests repeatable startup metadata behavior but is not proof of missing/replayed events. SqNum/EntryID are IEC 61850 report optional fields; missing consumer metadata could be absent on wire under OptFlds or absent in engine projection — not distinguishable in this diagnostic. Do not suppress SqNum 0→0 warning on assumption of GI, or infer EntryID progress from presence=0.

    Qualification limits: These are two separate ~30-second application startup captures, not a before/after reconnect test within an association lifecycle. Device card shows AWAITING PEER INGRESS per process; cross-process semantic parity established by human comparison only, no in-app paired proof. Lack of BufOvfl alone doesn't prove no loss. Saved user endpoint is also shown as an IP assigned to a local NIC; do not assert a separate physical relay without endpoint provenance.

    Smart next evidence before altering engine/diagnostics: capture explicit report OptFlds (SqNum, EntryID, BufOvfl, ConfRev), raw InformationReport reason/segmentation where available, and exact per-RCB RptEna/GI/reconnect lifecycle timestamps at ARIEC authoritative decode/RCB boundary. Do not duplicate MMS parsing in ARSAS consumer. Then run continuous monitoring with timestamped before/after reconnect report traces and optional controlled non-safety SOE stimulus; no breaker commands. Keep #485/#486 draft, avoid speculative changes to static reporting or engine lock. P7.6B static semantic/report parity remains good; P7.6C diagnostic completeness demonstrably working but event-history continuity remains unqualified.

  10. masarray commented on Oct 9, 2026

    @masarray
    OwnerAuthor

    P7.6D — engine-decoded OptFlds provenance workstream / ownership (2026-10-09)

    Draft PR #487 on P7.6C #485 exact head 8d764128ccf764b20d27d178dfec64ec71581b81 (standalone sibling to IED dialog UX #486, not a rewritten UI baseline). Exact HEAD 3f2bc75d9efb3bbe84c0808650b17f64bbda4808. CI pending.

    Root cause confirmed from pinned ARIEC engine source: MmsReportFrameMapper.DecodeHeader already extracts report wire OptFlds as MmsReportOptionalFields.RawHex plus typed HasSequenceNumber/HasEntryId/HasBufferOverflow/HasConfRevision. ARSAS NativeIec61850Client dropped OptionalFields when mapping engine report frame to consumer NativeReportFrameMetadata; therefore diagnostics for real pair GR_X_7SX85 couldn't distinguish wire omitted vs requested but not decoder-projected vs no OptFlds evidence.

    Narrow read-only fix: preserve nullable decoded option bits and a maximum 8-byte hex mask; distinguish unknown/omitted/advertised-but-undecoded counters per exact RCB and write bounded evidence to Copy Diagnostic. Keep conservative SqNum 0→0 duplicate/replay warning and no-event-loss assertion. Test missing, explicitly omitted, unknown, contradictory SqNum/EntryID, empty EntryID ambiguities, hostile hex, engine-owned decoding boundary. 5 files only (adapter, immutable metadata, continuity inspector, diagnostics, new tests); no MMS/RCB writes/GI/control/polling/SCL/engine pin/runtime value path changes.

    Parallel ownership: #487 owns ONLY these OptFlds provenance adapter/inspector/diagnostics lines, #486 native dialog UX owns separate XAML and dialog source; coordinate stack integration without dropping either. Physical reconnect/SOE event-history and in-app paired-ingress proof not achieved; do not merge/release prematurely. CI budget: one atomic 5-file tree push, one minimal wording contract correction, now wait on exact HEAD, not repeated speculative commits.

  11. masarray commented on Oct 9, 2026

    @masarray
    OwnerAuthor

    P7.6D PR #487 final exact HEAD 3f2bc75d9efb3bbe84c0808650b17f64bbda4808: 11/11 CI WORKFLOWS SUCCESS, 1,408/1,408 ARSAS regression tests PASS, IEC 61850 interoperability guard green, portable Windows x64 single EXE, field-capture Windows x64, and Windows x64 installer all available. Engine-owned InformationReport OptFlds evidence is forwarded through existing adapter into immutable per-RCB Copy Diagnostics, enabling wire omitted / advertised-but-undecoded / unknown classification for SqNum and EntryID, while preserving field BRCB SqNum=0→0 warning and report-only acquisition. No engine pin, network, GI, RCB write, cyclic polling or UI changes. UX #486 is a separate sibling workstream (not included in #487 artifact). Physical OptFlds/reconnect SOE testing still required; PR stays DRAFT, not merged/released. Avoid new CI unless actual field failure or approved integration.

  12. masarray commented on Oct 9, 2026

    @masarray
    OwnerAuthor

    P7.6D field qualification — real disconnect/reconnect pair (2026-10-09)

    Operator supplied two independent application diagnostic files, each showing initial connect → stop monitoring → disconnect → reconnect → Static DataSet reporting re-arm within the same app process. Assembly 1.6.40+b35dbc821faaab706536e0358ec962f1a6cf2e80 is the exact GitHub test merge of #487 HEAD 3f2bc75d9efb3bbe84c0808650b17f64bbda4808 into #485 HEAD 8d764128ccf764b20d27d178dfec64ec71581b81, engine pinned unchanged at 352c81e6a798635c6addcee0683235ca87ad416d. Native dialog UX #486 not included.

    After reconnect, Open SCD AP J: same 13/13 displayed, exact 2/2 RCB routed, 0 uncovered, cyclic process polling=0, semantic fingerprint cb563f46ea1a61634ab67c6af4802d353d8d8f9caf8e793b7a89580525ffd206. Association-local 7 decoded frames (6 BRCB, 1 URCB), 1 finding, OptFldsDecoded=7/7, Unknown=0. BRCB switched legitimate available instance Rpt_ind01→Rpt_ind04, mask 7880 with SqNum advertised=6/6, decoded=6/6, EntryID omitted=6/6. URCB Rpt_meas01, mask 3880: SqNum omitted=1/1 and EntryID omitted=1/1. New-session BRCB warning previous=4,current=0. Earlier first-session warnings 5→0 and 0→0 appear in historical logs but are not inherited into current snapshot, indicating reset isolation.

    After reconnect, Discovery IP: same semantic fingerprint, 13/13 displayed, 2/2 RCB routed, 0 uncovered, cyclic polling=0. Fast reconnect uses cached 532-signal model without repeating full discovery. Association-local 8 decoded frames (7 BRCB, 1 URCB), 1 finding, OptFldsDecoded=8/8, Unknown=0. BRCB instance Rpt_ind01→Rpt_ind02, mask 7880: SqNum advertised+decoded=7/7 and EntryID omitted=7/7. URCB mask 3880: SqNum omitted=1/1, EntryID omitted=1/1. Current-session BRCB warning previous=5,current=0 (older first-session 5→0 and 0→0 in historical logs). Both BufOvfl=0, ConfRevChanges=0, no ambiguous/untracked metadata streams.

    Acceptance: reconnection, static coverage, report-route authority and ARIEC wire OptFlds provenance are now physically confirmed across both ingress paths. Missing URCB SqNum is IED OptFlds-omitted on the decoded InformationReport, not an ARSAS decoder failure. Empty BRCB EntryID is likewise OptFlds-omitted; there is no EntryID replay cursor in these reports. Remaining unqualified: what triggers within-new-session BRCB SqNum reset 4/5→0 (e.g., GI/integrity/RCB activation), whether any SOE history was lost, long-soak behavior and in-app paired dual-ingress proof; don't discard warnings or infer event loss. Separate process logs both report AWAITING PEER INGRESS; comparing hashes across processes is useful but not the same as in-app dual-ingress traffic proof. Discovery still reports Primary unresolved=2 vs Open SCD 0 (control/inventory provenance issue), though runtime uncovered=0.

    Recommendation: next scoped phase is engine-authoritative, timestamp-correlated RptEna/GI/first-frame cause evidence and a controlled harmless source-event test with known event count if physical setup permits; never issue breaker controls. Avoid new coding/CI for wire OptFlds classification: the field evidence supports #487 implementation as designed. Keep PR draft; no merge/release pending event-history qualification. No customer raw files, IP inventory or sensitive diagnostic payload committed.

  13. masarray commented on Oct 9, 2026

    @masarray
    OwnerAuthor

    P7.6E workstream ownership + CI-thrifty evidence correlation

    Draft PR #488, exact head d1e6cb9351d8283e99cc8a898dd82531eda96fef, stacked on P7.6D #487 exact 3f2bc75d9efb3bbe84c0808650b17f64bbda4808. No modifications to the independent UX #486.

    Field evidence P7.6D real connect/disconnect/reconnect: 13/13 Static DataSet rows, BRCB+URCB 2/2 routed per ingress, zero process polling, both OptFlds decoded. BRCB SqNum requested and decoded (mask 7880), URCB SqNum omitted (mask 3880), EntryID omitted on both; BRCB new-association warning 4→0/5→0 remains unqualified as GI/reset/replay/loss.

    Engine-authoritative discovery (pinned ARIEC 352c81e6...): existing StartConfiguredStaticReportMonitorAsync uses true RptEna write, post-enable readback verifier, one-shot GI=true write; returned engine WriteSteps already include attempted/success. MmsReportFrame.Values[].ReasonForInclusion is already decoded by engine. Consumer currently discarded write outcomes and frame GI/integrity reasons. #488 forwards existing data, never re-parses MMS.

    #488 maps exact engine static-activation outcomes into per-association per-plan evidence, then into existing per-RCB continuity snapshot; maps decoded GI/integrity reasons only when available, retaining UNKNOWN for missing. Warnings preserve 5→0/4→0, with truthful timestamp/correlation text not asserting harmless reset or no SOE loss. 6 new synthetic tests. Atomic one commit / one CI trigger batch, tests preflighted before branch publish. 7 files: NativeReportMonitorModels.cs, NativeIec61850Client.StaticDataSetReporting.cs, NativeIec61850Client.cs, Iec61850MonitorRuntime.cs, Iec61850ReportContinuityInspector.cs, DiagnosticReportBuilder.cs, ReportActivationCausalityP76ETests.cs. Other threads should not overwrite these without reconciling SHA/PR, and must preserve static reporting authority and UI #486 separately.

    CI pending and physical GI/SOE qualification pending. PR draft, no merge/release, no control commands or report/RCB/GI writes added; engine pin unchanged.

  14. masarray commented on Oct 9, 2026

    @masarray
    OwnerAuthor

    P7.6E causal report evidence draft PR #488 exact HEAD d9d11ea2a24f09f6a515c3b561daca2a373d69c1: 11/11 CI workflows SUCCESS, 1,414/1,414 ARSAS regression tests PASS (guard); field-capture Win-x64 artifact, native portable EXE, installer ready. Strict single-source engine evidence: existing configured-static ARIEC RptEna and GI WriteSteps (success/rejection/unknown), decoded per-report ReasonForInclusion GI/integrity, association-local per-plan lifetime and precise report received timestamps. No MMS parser, new RCB/GI writes, polling, controls, engine lock or values path changes. BRCB SqNum 4/5→0 warnings preserved; observed GI correlation cannot certify no SOE loss. Formatter selectively emits lifecycle detail when actual evidence exists, preserving bounded diagnostic regression. Exactly 2 commits/CI batches (first failed one valid bounded-size test, corrected production code), no reruns. Field GI/reconnect evidence still needed; draft/no merge/no release; UX PR #486 separate.

  15. masarray commented on Oct 9, 2026

    @masarray
    OwnerAuthor

    GE Multilin F650 field milestone: canonical command object + evidence-graded rejection (2026-10-09)

    User supplied F650 BCU_GE.iid, Open IID/SCL and Discovery IP diagnostic. One physical IEC 61850 BCUGEF650/CSWI1.Pos appears as three apparent commands in the native WPF Command Dock because ARSAS static control projection previously keyed companion reuse by (DataObject,DataSetReference,DisplayReference) instead of by canonical full IED/LD/LN.DO. Report/DataSet memberships must remain separate, but Operate is a single canonical target. CSWI1…CSWI16 are distinct objects; do not collapse to logical-node class CSWI alone.

    First Close on F650: wire-confirmed MMS object-access-denied (3); operator confirmed BCU was physically still Local. The Local condition is field information not transmitted in generic MMS response. Later Close/Open on Open SCL, and Close/Open on Discovery, received MMS service acceptance + process feedback. Do not claim a specific Local/Remote/interlock cause on another relay based on generic access denied alone. Pinned ARIEC engine already decodes LastApplError AddCause reasons (interlocking, synchrocheck, blocked-by-mode, no-access-authority, other client, etc.) where sent.

    Draft PR #489 stacked on P7.6E #488. Current exact head 0a47560f478437e50b399f0deba7b33dc2cedbd7; first commit 07c9e384f28b010f8d319eca158619ef97357ba2 compiled with 1422/1423 tests passed, one legitimate stale source-text-only assertion in FAT test expected ControlSupportsOperate directly inside MonitorModels after fail-closed gate was centralized into Iec61850ControlIdentity. Follow-up commit updated this test to assert the actual central fail-closed gate remains intact; no test weakened. It also added prominent, explicit operator MessageBox on failed command only (no modal on success) showing engine IED-cause certainty/evidence + checks, preserving raw request/response in Diagnostics. HEAD CI pending.

    Patch covers upstream control-companion reuse by canonical IEC reference, legacy/cached Command Dock alias dedup and unique count, one ctlModel inspection per distinct object, per-IED/per-exact-DataObject atomic TryAdd/Remove single-flight guard to avoid duplicate Operate, shared operator result classifier for Quick Dock and detailed command window, classified diagnostics. Explicit AddCause is confirmed; bare MMS access denied is MmsServiceOnly and Local/Remote, authorization, interlock are suggested checks, not inferred. No engine/SCL/reporting/GI/poll/control wire changes; commands not actually sent by development work. Native-dialog UX #486 remains a separate parallel sibling and must not be overwritten in integration.

    Needs exact-head regression/packaging, then GUI screenshot and harmless authorized bench test of negative Local and successful Remote operation. PR stays draft, no merge/public release without field qualification. CI budget target now two automatic batches total, no manual reruns.

  16. masarray commented on Oct 9, 2026

    @masarray
    OwnerAuthor

    GE F650 canonical control and failure-reason milestone draft #489 exact HEAD 0a47560f478437e50b399f0deba7b33dc2cedbd7: 12/12 GitHub Actions SUCCESS, 1,424/1,424 ARSAS tests, 292/292 FAT tests, native Windows x64 portable EXE, Win-x64 field capture. Real F650 CSWI1.Pos repeated per DataSet now normalized at producer and Command Dock; IED + exact DO single-flight prevents concurrent duplicate Operate across aliases; ARIEC AddCause is surfaced as confirmed when supplied, generic MMS object-access-denied remains unknown-specific with Local/Remote only a troubleshooting candidate; failed commands show prominent operator modal and raw protocol in Diagnostics. No RCB/GI/reporting changes or live commands issued in development. Physical UI/authorized safe bench acceptance pending; draft/no merge/release. UX #486 sibling remains unmerged/untouched.

  17. masarray commented on Oct 9, 2026

    @masarray
    OwnerAuthor

    P7.6F — GE F650 field-driven Command Dock dedup and command shout

    User-confirmed first GE Multilin F650 BCU operation was denied because physical BCU was in Local, before switching to Remote. The historical wire response was MMS object-access-denied (3) with no confirmed AddCause / ControlError; therefore a Studio client cannot truthfully assert Local from that MMS error alone, even when human field evidence establishes it afterward.

    Draft PR #490, stacked on accepted-code P7.6E #488 exact d9d11ea2a24f09f6a515c3b561daca2a373d69c1. Current exact HEAD c08273201542d4372d1f05bc8d4f8d6ef0685add. Scope limited to Models/MonitorModels.cs, MainWindow.xaml, MainWindow.xaml.cs, and new tests/ARSAS.Tests/CommandIdentityRejectionP76FTests.cs. Does NOT change ARIEC MMS/Operate/SBO/RCB/control dispatch, engine lock or Static DataSet reporting. UX dialogs #486 separate; coordinate integration instead of overwriting.

    Command identity: F650 BCUGEF650/CSWI1.Pos appears across several DataSets (e.g. CSWI, MMXU_SOGI1, REPORT1), but full device-scoped object reference identifies one actual command. Command Dock canonicalizes/group-selects one stable representative per exact target while preserving all underlying DataSet descriptors and feedback signal rows; CSWI1 and CSWI10 remain distinct.

    User requested SHOUT: a polished, non-modal, top-right warning card for failed command with a single resettable 5-second WPF DispatcherTimer. Real IED AddCause mapped to human-readable titles: blocked-by-interlocking→Command blocked by interlock, synchrocheck/authorization/operating-mode variants mapped likewise. On generic object-access-denied (3) with no AddCause, card says IED refused and advises checking Local/Remote and access; it does not assert that Local or interlock was encoded by IED. Command details remain in Diagnostics. Multiple rapid failures replace same card; no toast stacking.

    CI: first branch HEAD 9831760 failed WPF parsing due to corrupted model file patch (non-protocol scope). Restored the FULL original MonitorModels.cs from immutable base and re-applied only tiny LINQ dedup in corrective commit c082732; no source model sections lost. Merge Execution Guard: 1,424/1,424 passed, 0 failed, 0 skipped. Other exact-head CI/portable artifact checks still pending. Draft/no merge/no public release. Physical F650 with Local and Remote status, relevant interlock AddCause, and Windows screenshot of shout still requires qualification; no breaker operation requested.

  18. masarray commented on Oct 9, 2026

    @masarray
    OwnerAuthor

    P7.6F Command Dock + SHOUT draft PR #490 exact HEAD c08273201542d4372d1f05bc8d4f8d6ef0685add: 11/11 CI workflows SUCCESS, 1,424/1,424 tests PASS (run). Native portable Windows x64, field-capture Windows x64 available. One actionable row per canonical device-scoped CSWI.Pos across multiple DataSets; a single non-modal toast auto-dismisses after 5 sec, honors explicit IED AddCause ('blocked-by-interlocking'→'Command blocked by interlock', synchrocheck, authorization/mode), generic F650 MMS object-access-denied only suggests checking Local/Remote without inventing a proven cause. No ARIEC/control send/RCB/reporting changes, user screenshot and F650 physical QA pending, #486 separate, draft/no merge/release.

  19. masarray commented on Oct 9, 2026

    @masarray
    OwnerAuthor

    G1/F650 parallel PR reconciliation — integrated draft PR #491 (2026-10-09)

    Two existing parallel, separately CI-green sibling drafts must not be merged blindly: #489 canonical Command DataObject identity, reporting DataSet alias projection, ctlModel inspection and per-target single-flight MMS guard, plus engine-based AddCause/LastApplError failure classifier; #490 non-modal CommandShout overlay and alternative UI-only dedup. Both base on P7.6E #488.

    Created new integration draft #491 at exact HEAD 3c6ccc84a9fe97ae6e87262cdfd969abefedf497, stacked on #489 0a47560f478437e50b399f0deba7b33dc2cedbd7. #491 takes only the nonmodal UX concept/XAML from #490 while using #489's stronger model identity and existing evidence-graded classifier; removes blocking MessageBox in command failure path, adds one reusable dispatcher timer, safe bounded notice, and tests. Generic MMS access denied remains reason unspecified, not proven BCU Local/interlock/auth; operator confirmed hardware was Local at first F650 failure, but wire response itself does not identify that cause.

    Change discipline: precisely 5 files, 1 preassembled Git tree commit and 1 initial GitHub CI batch (11 workflows automatically started); no new MMS/control requests, engine pin, RCB/GI, polling, live reporting or physical command changes. #486 is separate native-dialog UX; #488 remains canonical report causality workstream. Avoid editing #489/#490 branches concurrently; use #491 for integration proof, keep draft until exact CI and operator GUI screenshot/bench acceptance. Earlier #489 and #490 independent successes do not validate their combined runtime; #491 CI is presently running.

  20. masarray commented on Oct 9, 2026

    @masarray
    OwnerAuthor

    P7.6F G1/F650 integration PR #491 (stacked on #489, compatible visual shout from #490), exact HEAD 3c6ccc84a9fe97ae6e87262cdfd969abefedf497: 11/11 CI SUCCESS, 1,435/1,435 regression passed, native portable Win-x64 EXE and Smart Discovery field-capture EXE verified. One commit/one CI batch. Keeps canonical physical DataObject identity, multi-DataSet membership reporting, per-target atomic control dispatch, and evidence-graded engine AddCause/LastApplError classification; replaces modal error MessageBox with one bounded, reusable-timer nonmodal CommandShout. No engine, command writes, RCB/GI, cyclic polling or SCL changes in integration. A generic F650 MMS object-access-denied does NOT prove BCU Local; show it as a user-supplied bench observation/troubleshooting check unless device provides explicit state/AddCause. F650 visual/operator bench acceptance pending; draft/no merge/no release. #489/#490 are overlapping sibling PRs; do not merge both independently and regress this reconciled integration.

  21. masarray commented on Oct 9, 2026

    @masarray
    OwnerAuthor

    Current ARSAS handoff / verified GitHub snapshot — 2026-10-09 18:02 WIB

    Status checked directly against GitHub; not an automatic promotion. Current masarray/arsas main = 7d8d8026ae96d45f44d47f361d115a437af88fbe (NOT equal to active F650 integration branch). Engine masarray/ARIEC61850 main = e5deed1d8aa11d97991695c6e390baafea7ab797, but the ARSAS active interop stack is pinned to immutable engine SHA 352c81e6a798635c6addcee0683235ca87ad416d in engines/ARIEC61850.lock.json (engine PR #153). Do not silently move this lock to engine main.

    AUTHORITATIVE NEXT SOURCE: draft integration PR #491 HEAD 3c6ccc84a9fe97ae6e87262cdfd969abefedf497, branch integration/446-f650-canonical-nonmodal-shout, based on draft #489 HEAD 0a47560f478437e50b399f0deba7b33dc2cedbd7. #489 is stacked above report causal evidence #488 HEAD d9d11ea2a24f09f6a515c3b561daca2a373d69c1, which descends from the #480–#485, #487 interoperability/reporting stack. #491 purposefully reconciles alternative F650 sibling #490: it carries the visible nonmodal command shout on top of #489’s canonical identity, single-flight protection and evidence-graded failure classification. Never cherry-pick/merge all #490 changes blindly into #491: alternative UI-only dedup would compete with upstream semantic canonicalization.

    Exactly verified CI on #491 SHA: 11/11 workflows SUCCESS; Merge Execution Guard 1,435 regression tests passed, 0 failed/skipped. Native Win-x64 portable single-EXE #11611067624; Smart Discovery field-capture x64 #11610687668. Artifacts exist in GitHub (not a public release). Code/CI/packaging accepted; physical GE F650 GUI/command field qualification pending; mainline merge/release not approved.

    F650 field basis (operator uploaded screenshot, diagnostic and BCU_GE.iid): 16 distinct CSWI*.Pos controls. E.g. CSWI1.Pos appears in three different DataSets and CSWI10.Pos in two; old Command Dock rendered aliases as multiple rows. This is one exact IEC 61850 command target per full device-scoped DataObject reference, not separate Operate services because of multi-DataSet membership. Open IID/SCL and Discovery IP both received actual BRCB/URCB reporting without cyclic process MMS polling, but selected signal counts differ (53 vs 24): do not claim semantic parity for this F650 comparison. Discovery hit 6,400 MMS-name/64-page budget and Primary unresolved=244 vs Open IID 20, a separate Discovery completeness issue, not proof of command dedup bug.

    Initial F650 CLOSE attempt returned MMS object-access-denied (3) while operator independently observed the BCU was Local; later commands worked after switching to Remote. MMS denial alone does not prove Local, interlocking, synchrocheck or auth. Explicit decoded LastApplError/AddCause can prove exact reasons. #489/#491 provide Iec61850ControlFailureReason confidence IEDExplicitAddCause vs MmsServiceOnly vs ConfirmedClient/other, visible bounded nonmodal Iec61850ControlShout 8s with single reusable DispatcherTimer, and detailed diagnostics. Do not add fake Local/Remote conclusions or automatic retries. #491 retained Iec61850ControlIdentity dedup and ConcurrentDictionary.TryAdd/TryRemove per-target atomic dispatch gating; no extra MMS Operate to aliases.

    Other workstreams not to lose: separate native IED dialog readability PR #486 HEAD 56de3e2e0e82f01f04c49ca270d37f752e99f86f is NOT included in #491 (independent sibling off #485); reconcile deliberately later, with exact-head integration CI and Windows screenshot. P7.6B static member 0/1-based fingerprint normalization and equal Open SCD vs Discovery field fingerprint on Siemens-family IED were physically tested; #484–#485 continuity inspector and #487 OptFlds provenance were field tested, #488 GI cause observation code CI-tested, but SOE/event-history continuity unproven. Do not convert completed source/CI evidence into physical acceptance.

    Next work order: (1) review active PR statuses/main/lock, read AGENTS.md, docs/WORKSTREAM_COORDINATION.md, current issue #446 and #489/#490/#491 PR descriptions+diffs; (2) obtain user screenshot from the exact #491 build showing one CSWI1.Pos row and distinct CSWI2–16, correct alarm/notice, no UI freeze, test low/high DPI; (3) use only a safe/authorized commissioning IED for negative/positive control test, capture Copy Diagnostic, LastApplError/AddCause + actual BCU Local/Remote state; do NOT operate energized breakers for UI QA; (4) if true defect, patch minimal #491 stack only with regression and exact-head CI; (5) reconcile #486 UX separately without overwriting #491/engine; (6) only after all physical gates, intentionally consolidate stacked PRs and synchronize newer main, run one final comprehensive exact-HEAD CI. Do not merge drafts prematurely or run redundant CI.

    Engineering/CI contract: engine is sole MMS/ACSE/RCB/control decoder authority; Static DataSet report-only mode never enables cyclic process polling or dynamic writes; preserve ordered FCDA, source SHA/IED/AP provenance, multi-association isolation, DataSet/RCB membership, and control single-flight. Async WPF no synchronous network UI. Prefer one atomic branch push after source preflight + synthetic failure-path tests. Keep thread ownership explicit to avoid overwriting parallel work. Treat operator-provided BCU_GE.iid and diagnostics as contextual field sources, not redistributable repo fixtures. This comment makes NO code or release status changes.

  22. masarray commented on Oct 9, 2026

    @masarray
    OwnerAuthor

    2026-10-09 combined F650 + native-dialog acceptance candidate

    Created draft PR #492, HEAD e8b05349061b5bbe600e53bea5323926d0df365a, as one atomic commit directly on exact #491 HEAD 3c6ccc84a9fe97ae6e87262cdfd969abefedf497.

    Reconciliation was evidence-based:

    Preserved unchanged from #491: canonical full-DataObject control identity, DataSet membership provenance, per-target atomic TryAdd/TryRemove single-flight, evidence-graded AddCause/MMS failure classification, 8 s nonmodal Command Shout, report-causality stack, Static DataSet report-only behavior, and engine lock 352c81e6a798635c6addcee0683235ca87ad416d.

    Exact #492 diff: only
    IpConnectWizardWindow.xaml,
    SclSignalSelectionModeWindow.xaml,
    SclSignalSelectionModeWindow.xaml.cs,
    Styles/IedTaskDialogStyles.xaml,
    tests/ARSAS.Tests/IedTaskDialogVisualRegressionTests.cs,
    tests/ARSAS.Tests/WorkspaceModeSwitchTests.cs.

    At this checkpoint GitHub automatically triggered one CI batch on #492; Merge Execution Guard, native Build ARSAS, Field Capture and other smart-discovery guards are in progress. No manual rerun was triggered. Code integration is committed; CIQualified and PhysicalVerified are not yet claimed. Keep draft; no merge/release. GE F650 one-row-per-target + safe command rejection screenshot/diagnostic and high-DPI dialog review remain physical acceptance gates.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions