Repository navigation
P3-H: SMV standards invariants, deterministic WirePlan and recovery orchestration #139
Description
Activity
- added 2 commits that reference this issue
on Oct 6, 2026 masarray commented
on Oct 6, 2026 OwnerAuthorMore actionsRecovery checkpoint — 2026-10-07 P1.1 / P1.2 handoff
Accepted lineage:
- P3-H P0: centralize Process Bus VLAN invariants #140 merged ->
ea42c6892768fc48f996e4b011d43648b1241542 - P3-H P0.1: encoder-produced deterministic SV WirePlan #141 merged ->
f3a107ec4cc4eca553ee467911c979afd057ce4d - P3-H P1: separate SV sampling and Ethernet frame cadence #142 merged ->
67cf57e01e3d53a98c66b10934f73c0eb1381d75
Current active node:
- P1.1 explicit SV profile-family + transport authority — PR P3-H P1.1: explicit SV profile-family and transport authority #143
- branch:
hardening/smv-p1-1-profile-family - exact head:
5ded1506ddb58cf8b3f7eb2183abb501d9ab3e24 - base:
main@67cf57e01e3d53a98c66b10934f73c0eb1381d75 - current main has not moved beyond the P1 merge; branch is ahead and not behind.
P1.1 review hardening added after the originally green head:
- malformed explicit
SampledValueControl@multicastno longer normalizes silently into deployable multicast=true; - parser preserves a validity provenance bit while retaining the IEC default value only for inspection;
- profile compilation fails closed on malformed transport intent;
- canonical SCL export refuses to wash malformed transport input into a valid configuration;
- workspace semantic comparison includes the provenance bit.
Therefore: do not merge #143 based on the previously green head
2cb0f8a.... Exact-head CI for5ded1506...is the only acceptance authority. No failure observed at checkpoint time; workflows are running/queued.Next coordination node:
- P3-H P1.2: IEC 61869-9 variant, dataset and scaling authority #144 — P3-H P1.2: IEC 61869-9 variant, dataset and scaling authority
- P3-H P1.2: IEC 61869-9 variant, dataset and scaling authority #144 is coordination-only until P3-H P1.1: explicit SV profile-family and transport authority #143 merges.
- do not create another P1.2 issue or branch from pre-P3-H P1.1: explicit SV profile-family and transport authority #143 main.
P1.2 standards boundary recorded in #144:
- published IEC 61869-9:2016 remains the conformance baseline;
- AMD1 is still draft/CDV in 2026; SynchSrcID/slew-sync must not be claimed as published conformance;
- rational variant authority must include recognized sample/frame families including F4800S2 and F14400S6;
- standard scaling authority: Current 1 mA/count, Voltage 10 mV/count;
- dataset semantics require resolvable AmpSv/VolSv measurement + corresponding Quality pairing;
- vendor limits such as 24/32 channels remain device capability, never generic standard rules;
- current ESP32-P4 remains non-deployable for IEC 61869-9 until explicit runtime capability is added/evidenced.
Freeze/refresh rule:
- inspect P3-H P1.1: explicit SV profile-family and transport authority #143 exact-head CI and merge state;
- if P3-H P1.1: explicit SV profile-family and transport authority #143 is merged, read P3-H P1.2: IEC 61869-9 variant, dataset and scaling authority #144 and branch P1.2 from the exact post-P3-H P1.1: explicit SV profile-family and transport authority #143 main SHA;
- otherwise continue only P3-H P1.1: explicit SV profile-family and transport authority #143 review/fixes;
- never restart P0/P0.1/P1 or recreate profile-family authority.
- P3-H P0: centralize Process Bus VLAN invariants #140 merged ->
- added 11 commits that reference this issue
on Oct 6, 2026 1 remaining item
- added 4 commits that reference this issue
on Oct 6, 2026 masarray commented
on Oct 7, 2026 OwnerAuthorMore actions2026-10-07 recovery checkpoint — P1.2 merged / P1.3 active
Accepted lineage: #140, #141, #142, #143, and #145 (P1.2) are merged.
- P1.2 merge commit on main:
0a08767df0352b0311fdcf5d31a9782ccba1a13b - P3-H P1.2: IEC 61869-9 variant, dataset and scaling authority #145 exact-head 13/13 workflows green, merged with lease
2a524f97f2554b61199e811248450ecd64ba64c4. - P3-H P1.2: IEC 61869-9 variant, dataset and scaling authority #144 closed completed after P1.2 merge.
New narrow post-P1.2 node:
- P3-H P1.3: fail-closed SCL nofASDU provenance and round-trip #147 — P1.3 SCL nofASDU provenance; implementation PR P3-H P1.3: fail-closed SCL nofASDU provenance #148 Draft
- base:
main@0a08767df0352b0311fdcf5d31a9782ccba1a13b - branch:
hardening/smv-p1-3-nofasdu-provenance - exact head:
76749d5718affb738a45cd6845c120ce9363da0f - Changes: explicit invalid nofASDU is non-deployable, omitted retains default one; compiler/exporter/workspace equivalence fail closed; regressions cover omitted/valid 1/2/invalid 0/text/overflow/empty.
- Do not merge P3-H P1.3: fail-closed SCL nofASDU provenance #148 until exact-head CI passes. Never repeat/rebuild P1.2 or override concurrent work.
Remaining broader milestones: #33 interoperability breadth; #21 hardware TX timing evidence; #36 compiled-profile physical 4000/4800 acceptance; #24 parent P3. Keep open pending their independent acceptance evidence.
- P1.2 merge commit on main:
masarray commented
on Oct 7, 2026 OwnerAuthorMore actionsRecovery checkpoint — 2026-10-07 P1.3 MERGED / P3-A1 next
Accepted host standards lineage
- P3-H P0: centralize Process Bus VLAN invariants #140 P0 VLAN; P3-H P0.1: encoder-produced deterministic SV WirePlan #141 P0.1 WirePlan; P3-H P1: separate SV sampling and Ethernet frame cadence #142 P1 timing; P3-H P1.1: explicit SV profile-family and transport authority #143 P1.1 profile-family; P3-H P1.2: IEC 61869-9 variant, dataset and scaling authority #145 P1.2 IEC 61869-9 host authority — previously merged.
- P3-H P1.3: fail-closed SCL nofASDU provenance #148 P1.3 fail-closed SCL
nofASDU: exact head76749d5718affb738a45cd6845c120ce9363da0f, 15/15 pull_request workflows completed SUCCESS, six-file parser/model/compiler/exporter/workspace/test diff audited, merged with expected-head lease. - New main HEAD / merge commit:
bdd895ae8641dbf3d9c5c6509e3eb94f78802b8d. Verified PR P3-H P1.3: fail-closed SCL nofASDU provenance #148 merged and Issue P3-H P1.3: fail-closed SCL nofASDU provenance and round-trip #147 CLOSED/completed. No runtime realtime/codecs or new authorities were introduced.
First unaccepted node — existing #146 / #36 (do not recreate)
- Existing PR P3-A1: canonical binary SV device-profile envelope #146 P3-A1 versioned binary host->device envelope: branch
hardening/smv-p1-3-device-profile-binaryexact headdeda183bfb5ffa97bbc5bb009004bfc3d7904f98, 7 changed files. Retargeted base tomain@bdd895ae...; GitHub reports mergeable/clean, Draft retained. - Prior 14/14 PR P3-A1: canonical binary SV device-profile envelope #146 CI successes were created before this new base. They must not be claimed as fresh post-P1.3 integration tests. Need non-destructive lease-protected current-main integration, ensure the combined
tests/test_scl.cppretains P1.3 malformed nofASDU negative cases AND P3-A1 device-envelope cases, then new exact-head full CI on the combined tree. - Fail-closed enum-value review item documented in PR P3-A1: canonical binary SV device-profile envelope #146, no competing implementation. No new branch or force push.
- P3-A: vendor-neutral SCL-driven SV interoperability profile foundation #33 remains OPEN (acceptance audit logged, issue comment #6028307824): binary contract + embedded decode/transport and physical interoperability remain; host profile semantics alone do not close it.
- P2: deterministic ESP32-P4 Sampled Values publisher and timing evidence #21 remains OPEN (source-level timing-authority reconnaissance logged, comment #6028393351): existing
ptp_lab_task.cppEMAC timestamp TX helper must be reused/adapted for SV correlation; canonicalapp_main.cppstill uses regularesp_eth_transmit(), without actual TX hardware timestamps. No unproven timing claim. - P3-A1: compiled SV device profile and deterministic ESP32-P4 activation #36 and P3: standards-first SCL-driven SV profiles and IEC/IEEE 61850-9-3 PTP synchronization #24 remain OPEN. Keep this P3-H: SMV standards invariants, deterministic WirePlan and recovery orchestration #139 recovery umbrella OPEN.
Safe continuation
- Read current live main and P3-A1: canonical binary SV device-profile envelope #146 head/mergeability; coordinate with concurrent thread before modifying its branch.
- Complete P3-A1: canonical binary SV device-profile envelope #146 review and obtain fresh current-main integration CI on a lease-protected updated head; merge only if tests and policy pass. Do not duplicate binary schema/CRC authority.
- Add bounded embedded decoder/transport activation via P3-A1: compiled SV device profile and deterministic ESP32-P4 activation #36, then physical 4000/4800/independent capture and EMAC-TX timing under P2: deterministic ESP32-P4 Sampled Values publisher and timing evidence #21.
- Preserve standards validity vs device deployability, source intent vs observed evidence, single transport-failure and time authority, and no XML/heap/scans in realtime TX.
Recovery rule: never go back to P0–P1.3 unless a verified regression requires it. Accepted main =
bdd895ae8641dbf3d9c5c6509e3eb94f78802b8dat this checkpoint.- added 2 commits that reference this issue
on Oct 7, 2026 masarray commented
on Oct 7, 2026 OwnerAuthorMore actionsRecovery P3-A1 checkpoint — 2026-10-07 (post P1.3 accepted)
- Accepted main remains
bdd895ae8641dbf3d9c5c6509e3eb94f78802b8d(P3-H P1.3: fail-closed SCL nofASDU provenance #148 P1.3 merged / P3-H P1.3: fail-closed SCL nofASDU provenance and round-trip #147 closed). - Active P3-A1: canonical binary SV device-profile envelope #146 P3-A1 host binary device-profile contract: same existing Draft PR and branch
hardening/smv-p1-3-device-profile-binary, now483bd90e64891a62d474e94729b1a6a1b7c5f5a2. Integrated main by a two-parent fast-forward merge commit with branch-head expected-SHA lease (no force push). GitHub compare: ahead 5 / behind 0, seven original files in diff. - Cumulative regressions retained: P1.3 negative nofASDU source provenance in
tests/test_scl.cppand P3-A1 device-profile binary SCL tests. Existing V1 codec hardened: reject unknown enum values rather than alias to unicast; decode into temporary validated object, commit output only on success. Tests cover CRC-valid malformed late leaf descriptor, empty rejected output, 3 invalid enum cases; golden valid bytes remain expected unchanged. - New exact-head CI triggered for
483bd90e.... Not yet accepted; previous 14/14 green was ondeda183...and must not be reused. - P3-A1: compiled SV device profile and deterministic ESP32-P4 activation #36 firmware-side design gate documented in issue comment #6028615348. Device needs only a bounded adapter from the same compiled binary contract into existing
RuntimePublisherProfileand STOPPED-onlyruntime_profile_commit(), not a second scheduler/clock/state machine. Do not confuse binary config decode with Sampled Values wire packet decode. - Keep P3-A1: canonical binary SV device-profile envelope #146 Draft, P3-A: vendor-neutral SCL-driven SV interoperability profile foundation #33/P3-A1: compiled SV device profile and deterministic ESP32-P4 activation #36/P2: deterministic ESP32-P4 Sampled Values publisher and timing evidence #21/P3-H: SMV standards invariants, deterministic WirePlan and recovery orchestration #139 OPEN until their independent host, device, and physical evidence gates are met. Next action: inspect exact-head PR CI for P3-A1: canonical binary SV device-profile envelope #146, repair red tests if any, then merge only after all required gates green and current main checked.
- Accepted main remains
masarray commented
on Oct 7, 2026 OwnerAuthorMore actionsRecovery checkpoint supplement — active #146 CI fix
The prior recovery comment for #146 lists head
483bd90e64891a62d474e94729b1a6a1b7c5f5a2. That commit is now superseded after exact-head Windows/MSVC CI revealed test-onlyC4244fromstd::fill(..., 0U)in the new malformed-profile regression. The prior head was not merged.Current authoritative PR #146 head:
ba131a2481f8fe70f318488a4234fe2a21525cd1, same branchhardening/smv-p1-3-device-profile-binary, same current main basebdd895ae8641dbf3d9c5c6509e3eb94f78802b8d. Fix:std::uint8_t{0U}prevents narrowing warning in MSVC, retains identical byte semantics. Full exact-head pull_request CI is re-running. Keep Draft/unmerged pending acceptance. No duplicate branch, no fast rollback, no native hot-path changes.masarray commented
on Oct 7, 2026 OwnerAuthorMore actions2026-10-07 P3-A1 milestone — host contract merged, embedded Draft PR #149
Accepted dependency: PR #146 merged after 14/14 exact-head green, now
main@879f84b9b9791ebe700b9f000a0292afb083dc80. Host binary V1 schema/CRC/transactional decode and P1.3 malformed nofASDU regressions are now on main.Firmware implementation: draft PR #149 on
hardening/smv-p3a1-esp32p4-binary-activation, exact headb438d7e40538bfd54fc4e583b6558284a240d4b3(ahead 3, behind 0). No competingRuntimePublisherProfile, clock, scheduler, SV packet encoder or active-state authority introduced.- Firmware links the same
SvDeviceProfileBinaryCodecthrougharstack_process_bus; adapter validates complete V1 envelope and narrows to the currently supported 4I+4V single-ASDUSmpPerSecINT32/Quality layout and SmvOpts, or refuses unsupported IEC-valid profiles. - New fixed-bound transfer-only
BinaryProfileStagingreceives 48-byte maximum HEX chunks (fits legacy 192-byte console) with increasing transaction ID and strict sequential offsets.PROFILE BINBEGIN/BINCHUNK/BINCOMMIT/BINABORTcannot produce partial activation: only successful binary CRC/schema/layout and STOPPED gate reach existingruntime_profile_commit(). - START abandons uncommitted text/binary staging; console's existing textual PROFILE route remains unchanged.
PROFILE-BINARY-V1advertised in IDENTIFY and firmware manifest for capability negotiation, while protocol version remains 1.- Host-sim regression includes valid 4800/4I4V, CRC rejection, unsupported IEC 61869-9/mismatched layout/options/rate, truncated/duplicate/out-of-order/oversize chunks, and replay ID rejection. No vendor identifiers or proprietary fixtures.
- Fresh exact-head PR CI triggered on
b438d7e40538bfd54fc4e583b6558284a240d4b3, not accepted yet. Do not merge until C++ Windows/Linux, embedded, PTP and release gates pass. This tranche provides software decode/activation path only; hardware 4000/4800 TX/jitter/relay interoperability and GUI binary transport migration remain independent acceptance requirements. Keep P3-A1: compiled SV device profile and deterministic ESP32-P4 activation #36/P3-A: vendor-neutral SCL-driven SV interoperability profile foundation #33/P2: deterministic ESP32-P4 Sampled Values publisher and timing evidence #21 OPEN.
- Firmware links the same
masarray commented
on Oct 7, 2026 OwnerAuthorMore actionsRecovery checkpoint — 2026-10-07 P3-A1 host and embedded accepted
PR #146 merged after exact-head 14/14 green ->
main@879f84b9b9791ebe700b9f000a0292afb083dc80. PR #149 merged after exact-head 9/9 green -> current main6255d88fe7216dbfa93999a27364958c853c6ca0, ESP32-P4 bounded binary V1 decoder + chunked console staging + existing STOPPED-only atomic runtime activation. Accepted merge SHA and main verified. No duplicate SV clock/scheduler/packet or active-profile authority. Post-merge push CI still running; do not claim verified until completion. Keep #36/#33/#21 OPEN: GUI binary transport migration/ACK proof and physical 4000/4800 egress timing/interop evidence remain. Full gate and technical boundary recorded in #36 comment #6030206107.masarray commented
on Oct 7, 2026 OwnerAuthorMore actionsRecovery checkpoint #36 → GUI binary bench PR #150 active, exact head
83dbf331f68c14e0364d7be810a4b834f8d36af6, base accepted main6255d88fe7216dbfa93999a27364958c853c6ca0. Canonical C++->binary, per-chunk ACK, readback generation validation, portable Windows artifact workflow; full details #36 comment #6030507405. CI in progress. Keep #150 Draft, #36/#33/#21 open. Firmware board-test artifact is available via main Actions run 37566223094. Do not create parallel binary codec or duplicate active-profile state.masarray commented
on Oct 7, 2026 OwnerAuthorMore actionsRecovery correction — 2026-10-07
Earlier recovery notes pointing to PR #150/browser GUI are superseded. #150 is closed unmerged. Native PR #151 is the only active P3-A1 host integration, exact head
8cebd21a46eb8232571f2dd0648c2a14aaafee11, base6255d88fe7216dbfa93999a27364958c853c6ca0. Product authority is Qt/C++ ARStack Studio and acceptance artifact is the Windows installer + bundled matching firmware. Detailed corrected architecture and state-machine boundary recorded in #36 comment #6033472809. Do not create/revive a browser deployment path.masarray commented
on Oct 7, 2026 OwnerAuthorMore actionsMerged native Studio checkpoint: PR #151 ->
main@9e70a4937874e3e1752b725264fe5a2008aa8fb0. Exact release candidate run 37599444383 succeeded and produced native Windows installer artifact #11473055522 with matching bundled ESP32-P4 firmware; tree identity with main verified. Full hashes/evidence in #36 comment #6035184160. Web PR #150 remains closed/superseded. Physical bench gates remain open.
Purpose
Harden the existing Sampled Values / Process Bus implementation without creating a second protocol authority or restarting the already-completed P2/P3 work.
This issue is a continuation/recovery anchor for #24, #33 and #36 on the current
mainbaselinec7238d3a8ff86b30b397164c5fcbed820562b3e0.Non-negotiable architecture rules
Recovery / multi-thread protocol
When a thread/session loses context, do not restart from old milestones.
Recovery sequence:
NORTH_STAR.mdanddocs/SMV_INJECTOR_STATUS.md;mainhead and compare against the last accepted PR head;Parallel threads must own separate phases/files where practical. A later PR must rebase/re-evaluate against current main before merge; never force an older implementation over newer accepted progress.
P0 — standards invariant hardening
P0.1 — deterministic WirePlan / patch metadata
Follow-up PR after P0:
find_fixed_field();P1 — timing/profile semantic model
P2+ later gates
Acceptance discipline
A code PR is not accepted merely because it compiles. Require:
Parent roadmap: #24
Profile foundation: #33
Compiled device profile: #36
Timing evidence: #21