Skip to content

P3-H: SMV standards invariants, deterministic WirePlan and recovery orchestration #139

Description

@masarray

Purpose

Harden the existing Sampled Values / Process Bus implementation without creating a second protocol authority or restarting the already-completed P2/P3 work.

This issue is a continuation/recovery anchor for #24, #33 and #36 on the current main baseline c7238d3a8ff86b30b397164c5fcbed820562b3e0.

Non-negotiable architecture rules

  1. One standards authority. Generic Ethernet invariants live in the Ethernet/core layer; SV-profile rules live in the SV profile layer; ESP32-P4 only enforces device capability. Do not copy the same numeric rule into multiple layers unless it is a compile-time dependency boundary.
  2. SCL/configuration is engineering intent, not realtime work. No XML parsing, string/type resolution, heap allocation, packet rescanning, or logging is introduced into the deterministic TX hot path.
  3. Standard validity != device deployability. A profile may be standards-valid but unsupported by the current ESP32-P4 target. Reject as unsupported-device-capability rather than calling it invalid IEC.
  4. Observed wire facts != configured intent != conformance claim. Preserve the existing evidence boundary.
  5. No vendor branches. Vendor evidence may inform tests/profile capability data, but protocol code remains vendor-neutral.
  6. No silent fallback. Unsupported/ambiguous profile fields remain explicit and fail closed.

Recovery / multi-thread protocol

When a thread/session loses context, do not restart from old milestones.

Recovery sequence:

  1. read this issue and linked open/merged PR lineage;
  2. read NORTH_STAR.md and docs/SMV_INJECTOR_STATUS.md;
  3. inspect current main head and compare against the last accepted PR head;
  4. continue only the first unchecked phase whose dependencies are already merged/accepted;
  5. never rebuild an existing authority in a new helper/model if an equivalent canonical type already exists;
  6. each PR records exact base SHA, scope, non-goals, acceptance evidence and next node.

Parallel threads must own separate phases/files where practical. A later PR must rebase/re-evaluate against current main before merge; never force an older implementation over newer accepted progress.

P0 — standards invariant hardening

  • Introduce/reuse one canonical Ethernet VLAN validity rule: PCP 0..7, VID 0..4094; VID 4095 is reserved and must be rejected before encoding/deployment.
  • Fix SV profile compiler, embedded runtime validator and development control bridge so VID 4095 cannot pass an upstream gate and fail only inside the encoder.
  • Align any generic PTP Ethernet builder that still accepts VID 4095 with the same Ethernet invariant without changing the PTP runtime policy that intentionally disallows VID 0.
  • Preserve VID 0 for SV priority-tagged traffic.
  • Add boundary regression tests: VID 0 valid where allowed, 4094 valid, 4095 rejected.
  • No change to current proven 4I+4V wire bytes for valid configurations.

P0.1 — deterministic WirePlan / patch metadata

Follow-up PR after P0:

  • encoder-produced patch metadata for each ASDU;
  • no byte-pattern search such as find_fixed_field();
  • patch descriptors are offsets/widths produced while encoding, not rediscovered afterward;
  • structure must naturally scale to multi-ASDU without a second BER parser.

P1 — timing/profile semantic model

  • separate sampling rate, ASDU-per-frame, frame cadence, counter modulus and epoch policy;
  • retain current 1-ASDU 4I+4V target as a device capability, not the generic engine definition;
  • prepare explicit Generic IEC 61850-9-2 / Legacy 9-2LE / IEC 61869-9 profile-family rules without overclaiming conformance.

P2+ later gates

  • configurable IEC 61869-9 datasets/scaling;
  • deterministic multi-stream scheduler;
  • hardware TX timing evidence correlated with smpCnt;
  • process-bus admission planner;
  • PRP/HSR adapter layer;
  • independent multi-vendor interoperability/conformance evidence.

Acceptance discipline

A code PR is not accepted merely because it compiles. Require:

  • focused regression tests for the changed invariant;
  • existing C++/security/embedded CI remains green;
  • no golden-wire regression for valid reference frames;
  • exact-head evidence recorded in the PR;
  • physical evidence remains a separate gate when hardware behavior is claimed.

Parent roadmap: #24
Profile foundation: #33
Compiled device profile: #36
Timing evidence: #21

Activity

  1. self-assigned this
    on Oct 6, 2026
  2. masarray commented on Oct 6, 2026

    @masarray
    OwnerAuthor

    Recovery checkpoint — 2026-10-07 P1.1 / P1.2 handoff

    Accepted lineage:

    Current active node:

    • P1.1 explicit SV profile-family + transport authority — PR P3-H P1.1: explicit SV profile-family and transport authority #143
    • branch: hardening/smv-p1-1-profile-family
    • exact head: 5ded1506ddb58cf8b3f7eb2183abb501d9ab3e24
    • base: main@67cf57e01e3d53a98c66b10934f73c0eb1381d75
    • current main has not moved beyond the P1 merge; branch is ahead and not behind.

    P1.1 review hardening added after the originally green head:

    1. malformed explicit SampledValueControl@multicast no longer normalizes silently into deployable multicast=true;
    2. parser preserves a validity provenance bit while retaining the IEC default value only for inspection;
    3. profile compilation fails closed on malformed transport intent;
    4. canonical SCL export refuses to wash malformed transport input into a valid configuration;
    5. workspace semantic comparison includes the provenance bit.

    Therefore: do not merge #143 based on the previously green head 2cb0f8a.... Exact-head CI for 5ded1506... is the only acceptance authority. No failure observed at checkpoint time; workflows are running/queued.

    Next coordination node:

    P1.2 standards boundary recorded in #144:

    • published IEC 61869-9:2016 remains the conformance baseline;
    • AMD1 is still draft/CDV in 2026; SynchSrcID/slew-sync must not be claimed as published conformance;
    • rational variant authority must include recognized sample/frame families including F4800S2 and F14400S6;
    • standard scaling authority: Current 1 mA/count, Voltage 10 mV/count;
    • dataset semantics require resolvable AmpSv/VolSv measurement + corresponding Quality pairing;
    • vendor limits such as 24/32 channels remain device capability, never generic standard rules;
    • current ESP32-P4 remains non-deployable for IEC 61869-9 until explicit runtime capability is added/evidenced.

    Freeze/refresh rule:

    1. inspect P3-H P1.1: explicit SV profile-family and transport authority #143 exact-head CI and merge state;
    2. if P3-H P1.1: explicit SV profile-family and transport authority #143 is merged, read P3-H P1.2: IEC 61869-9 variant, dataset and scaling authority #144 and branch P1.2 from the exact post-P3-H P1.1: explicit SV profile-family and transport authority #143 main SHA;
    3. otherwise continue only P3-H P1.1: explicit SV profile-family and transport authority #143 review/fixes;
    4. never restart P0/P0.1/P1 or recreate profile-family authority.
  3. 1 remaining item

  4. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    2026-10-07 recovery checkpoint — P1.2 merged / P1.3 active

    Accepted lineage: #140, #141, #142, #143, and #145 (P1.2) are merged.

    New narrow post-P1.2 node:

    Remaining broader milestones: #33 interoperability breadth; #21 hardware TX timing evidence; #36 compiled-profile physical 4000/4800 acceptance; #24 parent P3. Keep open pending their independent acceptance evidence.

  5. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    Recovery checkpoint — 2026-10-07 P1.3 MERGED / P3-A1 next

    Accepted host standards lineage

    First unaccepted node — existing #146 / #36 (do not recreate)

    Safe continuation

    1. Read current live main and P3-A1: canonical binary SV device-profile envelope #146 head/mergeability; coordinate with concurrent thread before modifying its branch.
    2. Complete P3-A1: canonical binary SV device-profile envelope #146 review and obtain fresh current-main integration CI on a lease-protected updated head; merge only if tests and policy pass. Do not duplicate binary schema/CRC authority.
    3. Add bounded embedded decoder/transport activation via P3-A1: compiled SV device profile and deterministic ESP32-P4 activation #36, then physical 4000/4800/independent capture and EMAC-TX timing under P2: deterministic ESP32-P4 Sampled Values publisher and timing evidence #21.
    4. Preserve standards validity vs device deployability, source intent vs observed evidence, single transport-failure and time authority, and no XML/heap/scans in realtime TX.

    Recovery rule: never go back to P0–P1.3 unless a verified regression requires it. Accepted main = bdd895ae8641dbf3d9c5c6509e3eb94f78802b8d at this checkpoint.

  6. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    Recovery P3-A1 checkpoint — 2026-10-07 (post P1.3 accepted)

  7. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    Recovery checkpoint supplement — active #146 CI fix

    The prior recovery comment for #146 lists head 483bd90e64891a62d474e94729b1a6a1b7c5f5a2. That commit is now superseded after exact-head Windows/MSVC CI revealed test-only C4244 from std::fill(..., 0U) in the new malformed-profile regression. The prior head was not merged.

    Current authoritative PR #146 head: ba131a2481f8fe70f318488a4234fe2a21525cd1, same branch hardening/smv-p1-3-device-profile-binary, same current main base bdd895ae8641dbf3d9c5c6509e3eb94f78802b8d. Fix: std::uint8_t{0U} prevents narrowing warning in MSVC, retains identical byte semantics. Full exact-head pull_request CI is re-running. Keep Draft/unmerged pending acceptance. No duplicate branch, no fast rollback, no native hot-path changes.

  8. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    2026-10-07 P3-A1 milestone — host contract merged, embedded Draft PR #149

    Accepted dependency: PR #146 merged after 14/14 exact-head green, now main@879f84b9b9791ebe700b9f000a0292afb083dc80. Host binary V1 schema/CRC/transactional decode and P1.3 malformed nofASDU regressions are now on main.

    Firmware implementation: draft PR #149 on hardening/smv-p3a1-esp32p4-binary-activation, exact head b438d7e40538bfd54fc4e583b6558284a240d4b3 (ahead 3, behind 0). No competing RuntimePublisherProfile, clock, scheduler, SV packet encoder or active-state authority introduced.

    • Firmware links the same SvDeviceProfileBinaryCodec through arstack_process_bus; adapter validates complete V1 envelope and narrows to the currently supported 4I+4V single-ASDU SmpPerSec INT32/Quality layout and SmvOpts, or refuses unsupported IEC-valid profiles.
    • New fixed-bound transfer-only BinaryProfileStaging receives 48-byte maximum HEX chunks (fits legacy 192-byte console) with increasing transaction ID and strict sequential offsets. PROFILE BINBEGIN/BINCHUNK/BINCOMMIT/BINABORT cannot produce partial activation: only successful binary CRC/schema/layout and STOPPED gate reach existing runtime_profile_commit().
    • START abandons uncommitted text/binary staging; console's existing textual PROFILE route remains unchanged.
    • PROFILE-BINARY-V1 advertised in IDENTIFY and firmware manifest for capability negotiation, while protocol version remains 1.
    • Host-sim regression includes valid 4800/4I4V, CRC rejection, unsupported IEC 61869-9/mismatched layout/options/rate, truncated/duplicate/out-of-order/oversize chunks, and replay ID rejection. No vendor identifiers or proprietary fixtures.
    • Fresh exact-head PR CI triggered on b438d7e40538bfd54fc4e583b6558284a240d4b3, not accepted yet. Do not merge until C++ Windows/Linux, embedded, PTP and release gates pass. This tranche provides software decode/activation path only; hardware 4000/4800 TX/jitter/relay interoperability and GUI binary transport migration remain independent acceptance requirements. Keep P3-A1: compiled SV device profile and deterministic ESP32-P4 activation #36/P3-A: vendor-neutral SCL-driven SV interoperability profile foundation #33/P2: deterministic ESP32-P4 Sampled Values publisher and timing evidence #21 OPEN.
  9. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    Recovery checkpoint — 2026-10-07 P3-A1 host and embedded accepted

    PR #146 merged after exact-head 14/14 green -> main@879f84b9b9791ebe700b9f000a0292afb083dc80. PR #149 merged after exact-head 9/9 green -> current main 6255d88fe7216dbfa93999a27364958c853c6ca0, ESP32-P4 bounded binary V1 decoder + chunked console staging + existing STOPPED-only atomic runtime activation. Accepted merge SHA and main verified. No duplicate SV clock/scheduler/packet or active-profile authority. Post-merge push CI still running; do not claim verified until completion. Keep #36/#33/#21 OPEN: GUI binary transport migration/ACK proof and physical 4000/4800 egress timing/interop evidence remain. Full gate and technical boundary recorded in #36 comment #6030206107.

  10. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    Recovery checkpoint #36 → GUI binary bench PR #150 active, exact head 83dbf331f68c14e0364d7be810a4b834f8d36af6, base accepted main 6255d88fe7216dbfa93999a27364958c853c6ca0. Canonical C++->binary, per-chunk ACK, readback generation validation, portable Windows artifact workflow; full details #36 comment #6030507405. CI in progress. Keep #150 Draft, #36/#33/#21 open. Firmware board-test artifact is available via main Actions run 37566223094. Do not create parallel binary codec or duplicate active-profile state.

  11. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    Recovery correction — 2026-10-07

    Earlier recovery notes pointing to PR #150/browser GUI are superseded. #150 is closed unmerged. Native PR #151 is the only active P3-A1 host integration, exact head 8cebd21a46eb8232571f2dd0648c2a14aaafee11, base 6255d88fe7216dbfa93999a27364958c853c6ca0. Product authority is Qt/C++ ARStack Studio and acceptance artifact is the Windows installer + bundled matching firmware. Detailed corrected architecture and state-machine boundary recorded in #36 comment #6033472809. Do not create/revive a browser deployment path.

  12. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    Merged native Studio checkpoint: PR #151 -> main@9e70a4937874e3e1752b725264fe5a2008aa8fb0. Exact release candidate run 37599444383 succeeded and produced native Windows installer artifact #11473055522 with matching bundled ESP32-P4 firmware; tree identity with main verified. Full hashes/evidence in #36 comment #6035184160. Web PR #150 remains closed/superseded. Physical bench gates remain open.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions