Skip to content

P3-A1: compiled SV device profile and deterministic ESP32-P4 activation #36

Description

@masarray

Goal

Bridge the host-side SvPublisherProfile into the deterministic ESP32-P4 runtime so canonical Sampled Values behavior is no longer hard-coded in firmware.

This is the convergence point between P3-A0 profile correctness and the independent hardware-timing evidence track.

Binary profile contract

Define a versioned, bounded device representation containing only resolved runtime values:

  • schema version / total length / integrity check;
  • destination MAC;
  • APPID;
  • VLAN present / VID / PCP;
  • svID and optional DataSet reference policy;
  • confRev;
  • nofASDU;
  • sample rate / sample mode / derived publisher rate;
  • validated sample-counter policy/modulus;
  • resolved SmvOpts field-presence policy;
  • ordered fixed wire-leaf descriptors and payload size;
  • synchronization policy input, without claiming lock.

No XML, dynamic type traversal or manufacturer-specific identity is sent to the realtime hot path.

Host side

  • serialize a Class-A SvPublisherProfile into the versioned binary representation;
  • refuse serialization when counter policy or another mandatory runtime property is only a candidate/unresolved;
  • include deterministic canonical byte/golden-vector tests;
  • support local, private profile resolution without committing proprietary source files.

Device side

  • bounded profile decoder/validator;
  • reject unsupported schema versions, invalid lengths/checksums, invalid VLAN/rate/layout constraints and unresolved policy values;
  • atomically activate a validated profile;
  • allocate/build templates before realtime start;
  • no allocation/string/XML work in the per-sample TX path;
  • move current hard-coded MAC/APPID/VLAN/svID/confRev/rate/counter/layout constants behind the active profile;
  • integrate drift-free timer scheduling for rates that are not integer microseconds;
  • preserve truthful smpSynch until synchronization evidence exists.

Timing convergence

For each active profile correlate:

validated profile schedule
        -> RTOS timer deadline
        -> canonical TX submit
        -> EMAC HW TX timestamp
        -> evidence statistics

P3-A1 must not weaken or bypass the hardware timing evidence introduced by PR #26.

Acceptance families

  • 4000 events/s family: exact 250 us nominal cadence, validated counter policy, canonical identity/layout from profile;
  • 4800 events/s family: drift-free schedule, validated counter policy, canonical identity/layout from profile;
  • both sustain at least the existing P2 reliability baseline on physical hardware before the profile runtime is considered accepted;
  • profile switching is safe and atomic while TX is stopped/armed according to the runtime state machine.

Out of scope

  • PTP servo/lock promotion;
  • manufacturer presets;
  • active learn-from-capture overrides;
  • broad UI/scenario editing.

Those build on this device-profile foundation. Tracks #33, #21 and #24; observed fingerprint work is #35.

Activity

  1. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    2026-10-07 execution plan — software P3-A1 after #145

    Do not restart the host profile compiler. The remaining software gap is the device-envelope/integrity boundary.

    One binary authority

    Add a portable core type/codec, e.g. CompiledSvDeviceProfileV1, with an explicitly serialized byte order. Do not memcpy a C++ struct across host/device; padding, ABI and endianness must never become protocol.

    Envelope:

    magic
    schemaVersion
    headerLength
    totalLength
    flags
    payloadLength
    CRC32
    canonical payload...
    

    Payload carries only resolved runtime values already owned by SvPublisherProfile:

    • MAC / APPID / VLAN;
    • svID / optional DataSet reference;
    • confRev;
    • resolved frame cadence + nofASDU;
    • explicit validated counter policy/modulus;
    • SmvOpts presence flags;
    • ordered fixed wire-leaf descriptors + total payload size;
    • synchronization policy input only (never lock truth).

    Integrity

    Reuse the repository's existing CRC-32 algorithm semantics from the static BRCB checkpoint path, but move/share the primitive only if that can be done without creating a storage-specific dependency. CRC covers the canonical serialized profile with the CRC field zero/excluded by one documented rule.

    Host gate

    SvPublisherProfile -> CompiledSvDeviceProfileV1 must fail closed unless:

    • profile family is resolved;
    • timing needed by this target is resolved;
    • sample-counter policy is explicit;
    • all bounded field lengths fit;
    • channel wire widths/layout are target-supported;
    • optional fields unsupported by the target are rejected as device capability, not standard-invalid.

    Golden vectors must be byte-for-byte identical on GCC/Clang/MSVC.

    Device gate

    Decode into a temporary value, verify magic/version/length/CRC/all bounds first, then translate to the existing RuntimePublisherProfile. Only after full validation may runtime_profile_commit() swap generation atomically.

    The current textual PROFILE ... command transport may remain for development, but it must carry/assemble the same binary envelope or be demoted to a debug adapter. It must not remain a second semantic profile model.

    Realtime boundary

    No change to RUNNING hot path:

    • immutable snapshot;
    • prebuilt packet/WirePlan before timer start;
    • no XML/string/type traversal;
    • no CRC work per sample.

    Ordered delivery

    1. portable binary codec + malformed/golden tests;
    2. host compiler from Class-A profile;
    3. embedded bounded decoder + atomic commit adapter;
    4. Studio/legacy bridge sends canonical compiled bytes;
    5. 4000/4800 software regression;
    6. physical/timing acceptance stays with P2: deterministic ESP32-P4 Sampled Values publisher and timing evidence #21/P3-A1: compiled SV device profile and deterministic ESP32-P4 activation #36 and is not faked by software CI.

    Start implementation only from the exact post-#145 main SHA to avoid parallel profile-schema drift.

  2. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    2026-10-07 P3-A1 binary decoder integration boundary (reconnaissance; implementation remains gated)

    Existing #146 is now based on merged P1.3 main@bdd895ae8641dbf3d9c5c6509e3eb94f78802b8d, with latest hardening commit 483bd90e64891a62d474e94729b1a6a1b7c5f5a2 and new exact-head CI underway. Do not start firmware integration until #146 host binary golden/negative regressions are accepted.

    What decoder means: host->ESP32-P4 compiled device-profile binary envelope decoder, not a rewrite of existing SV wire-frame decode or MMS reporting.

    Inspection of current firmware owners:

    • main/runtime_profile.hpp/.cpp: canonical fixed RuntimePublisherProfile and runtime_profile_validate() / generation incrementing runtime_profile_commit() guarded by existing critical section.
    • main/profile_control.cpp: existing PROFILE BEGIN/ID/DATASET/L2/SV/COMMIT staging and STOPPED gate; do not add a second independent profile state machine.
    • main/app_main.cpp: existing deterministic WirePlan and TX failure authority remain unchanged.
    • include/ariec61850/sampled_values/esp32p4_profile_support.hpp: host classify_esp32p4_sv_profile limits current target to explicitly resolved generic/legacy profile, SmpPerSec, single ASDU, 4I+4V ordered INT32+Quality leaves, no unsupported refresh/security/SynchSrcID, resolved explicit counter modulus.

    Next bounded device-side decoder tranche (#36): reuse SvDeviceProfileBinaryCodec bounded verification of magic/version/length/CRC/ordered descriptors; translate only currently supported V1 fields into a temporary existing RuntimePublisherProfile; verify 16 leaves, eight INT32+Quality pairs, 64-byte payload, exact 1-ASDU SmpPerSec, integral bounded 4000/4800 cadence when requested, allowable SmvOpts, APPID/VLAN/MAC, bounded svID/DataSet, supported profile family, and no unsupported hidden fields. Reject unknown/unresolved variants explicitly as unsupported device capability, not invalid IEC. Perform validation and template preparation outside TX; gate the commit on STOPPED and call existing runtime_profile_commit(). Malformed input must leave active generation and stream identity unchanged. Provide negative CRC/schema/bounds/layout/enum tests plus atomic no-change-on-error tests. Retain legacy textual path until binary transfer and bridge ACK/generation evidence prove parity. Do not claim physical 4000/4800 or external interoperability from build alone.

    Do not duplicate: encoder CRC-32 implementation, SCL parser, transport-failure authority, PTP clock, scheduler, device profile state machine or packet WirePlan.

  3. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    Additional device transport constraint found (2026-10-07 source audit)

    embedded/esp32p4_smv_injector/main/live_control.cpp currently receives console commands using a fixed std::array<char, 192> line with an overflow-discard path. Therefore do not send the compiled binary envelope as one long HEX/Base64 text command: the maximum V1 envelope is bounded but can exceed this line capacity after textual encoding. A one-shot naive command would be truncated/rejected.

    The device integration tranche should use bounded chunked staging (or a framing-capable binary control transport) with explicit declared total length, sequential offsets/chunk limits, monotonic transaction identity or equivalent anti-mix guard, final envelope CRC/schema verification by the canonical SvDeviceProfileBinaryCodec, and then the existing STOPPED-only activation. Reject overflow, missing/duplicate/out-of-order chunks, invalid total length, stale transaction and CRC corruption without changing the active RuntimePublisherProfile generation. Use fixed storage and no heap in TX. Keep the current textual PROFILE bridge until atomic binary equivalence and ACK/readback tests pass.

  4. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    2026-10-07 P3-A1 milestone — host contract merged, embedded Draft PR #149

    Accepted dependency: PR #146 merged after 14/14 exact-head green, now main@879f84b9b9791ebe700b9f000a0292afb083dc80. Host binary V1 schema/CRC/transactional decode and P1.3 malformed nofASDU regressions are now on main.

    Firmware implementation: draft PR #149 on hardening/smv-p3a1-esp32p4-binary-activation, exact head b438d7e40538bfd54fc4e583b6558284a240d4b3 (ahead 3, behind 0). No competing RuntimePublisherProfile, clock, scheduler, SV packet encoder or active-state authority introduced.

    • Firmware links the same SvDeviceProfileBinaryCodec through arstack_process_bus; adapter validates complete V1 envelope and narrows to the currently supported 4I+4V single-ASDU SmpPerSec INT32/Quality layout and SmvOpts, or refuses unsupported IEC-valid profiles.
    • New fixed-bound transfer-only BinaryProfileStaging receives 48-byte maximum HEX chunks (fits legacy 192-byte console) with increasing transaction ID and strict sequential offsets. PROFILE BINBEGIN/BINCHUNK/BINCOMMIT/BINABORT cannot produce partial activation: only successful binary CRC/schema/layout and STOPPED gate reach existing runtime_profile_commit().
    • START abandons uncommitted text/binary staging; console's existing textual PROFILE route remains unchanged.
    • PROFILE-BINARY-V1 advertised in IDENTIFY and firmware manifest for capability negotiation, while protocol version remains 1.
    • Host-sim regression includes valid 4800/4I4V, CRC rejection, unsupported IEC 61869-9/mismatched layout/options/rate, truncated/duplicate/out-of-order/oversize chunks, and replay ID rejection. No vendor identifiers or proprietary fixtures.
    • Fresh exact-head PR CI triggered on b438d7e40538bfd54fc4e583b6558284a240d4b3, not accepted yet. Do not merge until C++ Windows/Linux, embedded, PTP and release gates pass. This tranche provides software decode/activation path only; hardware 4000/4800 TX/jitter/relay interoperability and GUI binary transport migration remain independent acceptance requirements. Keep P3-A1: compiled SV device profile and deterministic ESP32-P4 activation #36/P3-A: vendor-neutral SCL-driven SV interoperability profile foundation #33/P2: deterministic ESP32-P4 Sampled Values publisher and timing evidence #21 OPEN.
  5. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    2026-10-07 P3-A1 implementation acceptance — host + firmware merged

    Accepted sequence:

    1. PR P3-A1: canonical binary SV device-profile envelope #146 host compiled binary V1 envelope merged to main@879f84b9b9791ebe700b9f000a0292afb083dc80 after 14/14 exact-head pull_request workflows succeeded. Canonical magic/version/length/CRC32, bounded wire-leaf layout, transactional decode, golden bytes, invalid-enum and malformed nofASDU regressions.
    2. PR P3-A1: ESP32-P4 bounded binary decoder, staged transport and atomic profile activation #149 ESP32-P4 binary decoder and atomic activation, exact head b438d7e40538bfd54fc4e583b6558284a240d4b3, 9/9 exact-head pull_request workflows succeeded (C++, security, Embedded Profile, ESP32-P4 build, PTP Lab, release, control/BRCB/dynamic RCB). Merged with expected-head SHA, new main 6255d88fe7216dbfa93999a27364958c853c6ca0. Verified PR merged and main SHA.

    Implemented #36 software boundary: shared SvDeviceProfileBinaryCodec reused by ESP, bounded PROFILE BINBEGIN/BINCHUNK/BINCOMMIT/BINABORT using max 48-byte chunks (fits legacy 192-character console), sequential offsets and monotonic transaction IDs, no partial activation, fail-closed MAC/APPID/CRC/schema/layout/options/sampling validation, supported 4I+4V profile narrowing, START abort of incomplete staging, STOPPED-only reuse of existing runtime_profile_commit() / generation. PROFILE-BINARY-V1 advertised in IDENTIFY and firmware manifest. Legacy text PROFILE intact. No new clock/packet/RT scheduler or active-profile authority.

    Keep #36 OPEN: post-merge main push CI was still running at this checkpoint; binary auto-deployment in Studio/GUI and physical 4000/4800 continuous capture/EMAC hardware egress timestamp evidence have not been demonstrated. Do not close #33/#21 or claim protection-grade timing or IEC conformance until physical and interoperability acceptance. Next bounded gate is host GUI binary capability negotiation + transport ACK/readback equivalence + independent physical tests.

  6. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    P3-A1 GUI/board-test artifact milestone — 2026-10-07 (active PR #150)

    Accepted prerequisite: main 6255d88fe7216dbfa93999a27364958c853c6ca0 includes merged host binary contract #146 and ESP32-P4 bounded decoder/staging/STOPPED atomic activation #149; main post-merge 10/10 push CI succeeded. Stable firmware artifact: run 37566223094, artifact arstack-esp32p4-smv-firmware (raw merged ESP32-P4 image + manifest, 0x0, pre-v3), expiry 2026-10-21.

    Current unique active GUI integration: PR #150, branch feature/smv-gui-binary-bench-profile-deploy, exact head 83dbf331f68c14e0364d7be810a4b834f8d36af6. Draft and NOT MERGED until fresh exact-head CI green. Do not create another web GUI binary codec/transport branch.

    • Reuses C++ canonical compiler SvPublisherProfile -> CompiledSvDeviceProfile -> SvDeviceProfileBinaryCodec, exposing deviceProfileHex only when Class A + current device support ready; browser never computes its own SV binary structure or CRC.
    • WebSerial requires explicit IDENTIFY capability PROFILE-BINARY-V1 and baseline PROFILE SHOW generation. Sends <=48-byte chunks sequentially via BINBEGIN/BINCHUNK/BINCOMMIT, requiring transaction-exact bytes-received ACK for every chunk; no silent fallback on binary failure.
    • After COMMIT, PROFILE SHOW must match generation increase, svID, APPID, rate, smpCnt modulus, confRev before UI allows START. Legacy text remains only when old firmware explicitly advertises no binary capability. Prevents false-positive deployment status.
    • Separate Windows portable artifact pipeline SMV Injector GUI Bench: builds matched native C++ profile compiler, JS chunk/ACK negative tests, C++->binary CRC/length regression, packages run-portable.cmd + browser GUI as arstack-smv-injector-bench-windows-x64. Node/Python + Windows build still running at checkpoint.
    • Physical board/relay/canonical 4000/4800 traffic, real HW egress timestamps, and GUI ACK under hardware remain unproven until user bench captures. Keep P3-A1: compiled SV device profile and deterministic ESP32-P4 activation #36 / P3-A: vendor-neutral SCL-driven SV interoperability profile foundation #33 / P2: deterministic ESP32-P4 Sampled Values publisher and timing evidence #21 open.

    Next check: exact-head PR #150 complete CI, fix any issues without changing accepted firmware transport authority, then merge with expected SHA and link verified GitHub Actions artifact for board tests.

  7. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    P3-A1 GUI bench artifact produced — exact-head PR #150

    At 83dbf331f68c14e0364d7be810a4b834f8d36af6, SMV Injector GUI Bench run #37568178699 completed SUCCESS, publishing arstack-smv-injector-bench-windows-x64 artifact #11459656999, expiration 2026-10-21 03:48 UTC, containing native C++ profile compiler, portable localhost GUI/JS, run-portable.cmd. It passed C++ SCL→binary V1 header/CRC smoke, JS frame bounds, and simulated strict per-chunk ACK + readback match / reject without silent legacy downgrade.

    Firmware matching supported V1 protocol remains accepted main@6255d88fe7216dbfa93999a27364958c853c6ca0: ESP32-P4 firmware artifact run #37566223094, arstack-esp32p4-smv-firmware #11458906727, raw merged 0x0 image, pre-v3, manifest SHA256 contract.

    Important: #150 as a whole is still Draft pending remaining exact-head Security/C++/Control Interop gates; current GUI artifact is a bench candidate not a public stable release. It is not physical board evidence. After full CI, merge with expected-head and verify main artifact; retain #36 open until physical 4000/4800, canonical mirror/TAP capture, and evidence review.

  8. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    Correction — native ARStack Studio is the product authority (2026-10-07)

    The earlier #150 browser/WebSerial checkpoint was an architectural regression and is superseded. PR #150 is closed, unmerged, and must not be revived as the product path.

    Verified current product baseline:

    • latest public release: ARStack Studio v0.1.1
    • normal Windows artifact: ARStack-Studio-0.1.1-win-x64-setup.exe
    • canonical operator surface: apps/arstack_studio (Qt/C++/QML)
    • firmware update/recovery is bundled into Studio through the existing manifest + pinned espflash flow.

    Authoritative P3-A1 integration is now PR #151:
    #151
    exact head 8cebd21a46eb8232571f2dd0648c2a14aaafee11, base accepted main 6255d88fe7216dbfa93999a27364958c853c6ca0.

    Native implementation path:
    SclProfileModel -> SvPublisherProfile -> compile_esp32p4_device_profile -> SvDeviceProfileBinaryCodec -> DeviceController -> ESP32-P4.

    Studio now owns the V1 transfer state machine: BINSTATUS -> stale BINABORT if required -> BINBEGIN -> <=48-byte BINCHUNK + exact ACK -> BINCOMMIT -> PROFILE SHOW readback. It only arms after generation + svID + APPID + rate + counter modulus + confRev match. Firmware manifest and identity contracts require PROFILE-BINARY-V1. QML remains presentation-only; there is no browser/WebSerial dependency.

    Acceptance output for #151 is the existing ARStack Studio Windows release package/installer, with matched firmware bundled. No web artifact counts as acceptance. Keep #36 open until exact-head Studio Qt/Windows/ESP/release CI and physical board/capture evidence complete.

  9. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    Native integration architecture audit — PR #151

    Re-audited after correcting the earlier browser-path mistake. Verdict: directionally correct and strengthening ARStack, with the product authority remaining native ARStack Studio.

    Current exact head: 3bfe6445985a034fba7a76d60f13b3f13816dd25, base main@6255d88fe7216dbfa93999a27364958c853c6ca0, behind=0, Draft.

    Key invariants checked against NORTH_STAR / #139:

    • one C++ binary codec/schema authority; no browser/JS serializer;
    • no SCL/XML/string traversal or new allocation in realtime TX hot path;
    • no change to GPTimer/EMAC/PTP/live-signal hot path;
    • standards validity remains separate from ESP32-P4 deployability;
    • binary staging is transfer-only; RuntimePublisherProfile remains the single active authority;
    • STOPPED-only atomic commit remains intact;
    • no silent text fallback: old v0.1.1 firmware is identified then offered the bundled capability update;
    • stale BINABORT/BINCOMMIT ACKs are now transaction-bound and fail closed;
    • sync timeout is per validated protocol step, not one coarse 6 s transaction timer;
    • deterministic harness now locks stale-ACK rejection and progress deadline rearm.

    Remaining non-functional release hygiene: PR bench installer still carries 0.1.1 version naming. Do not publish/tag as a new public 0.1.1; choose next release version separately after physical acceptance. Exact-head CI reruns are required after the audit fixes.

  10. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    Native ARStack Studio board-test artifact accepted from merged PR #151

    Merged product baseline:

    Exact-head ARStack Studio Release run:
    https://github.com/masarray/arstack61850/actions/runs/37599444383

    Release workflow completed SUCCESS:

    • firmware/build-esp32p4 ✅
    • Windows x64 package ✅
    • Fresh Windows package smoke ✅
    • tagged publication skipped intentionally (PR candidate)

    Artifact:

    • arstack-studio-windows-x64 (#11473055522)
    • contains ARStack-Studio-0.1.1-win-x64-setup.exe
    • contains portable ZIP + SHA256SUMS.txt
    • installer SHA256: 0c7923837f81a274999fbae65b817b71a113e0e8ec7a751396c53ac563f1140e
    • portable SHA256: 399e46cd238bfee31ee119f99ef038a19db27fefbf6eb759fa8a84626eeaeac2
    • artifact expires 2026-10-21

    Bundled firmware inside portable/package was independently inspected:

    • firmware/arstack-esp32p4-smv-0.1.1.bin
    • firmware SHA256 41f71fe0341f12d043e5b238cf10bce4288688275074bfecca927ab3e713e4d9, matches manifest and bundled firmware SHA256SUMS
    • manifest requires PROFILE-BINARY-V1
    • bundled tools/espflash.exe present
    • target ESP32-P4, pre-v3, flash offset 0

    This is the native ARStack Studio GUI candidate, not the closed web path. It is suitable for physical bench testing. Physical 4000/4800 fps, VLAN/canonical capture, and hardware timing remain separate acceptance evidence.

    Post-merge main push CI at checkpoint: 8/12 green, 4 still running, 0 failed. Exact PR head had completed all pull_request gates before merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions