Repository navigation
P3-A1: compiled SV device profile and deterministic ESP32-P4 activation #36
Description
Activity
masarray commented
on Oct 7, 2026 OwnerAuthorMore actions2026-10-07 execution plan — software P3-A1 after #145
Do not restart the host profile compiler. The remaining software gap is the device-envelope/integrity boundary.
One binary authority
Add a portable core type/codec, e.g.
CompiledSvDeviceProfileV1, with an explicitly serialized byte order. Do not memcpy a C++ struct across host/device; padding, ABI and endianness must never become protocol.Envelope:
magic schemaVersion headerLength totalLength flags payloadLength CRC32 canonical payload...Payload carries only resolved runtime values already owned by
SvPublisherProfile:- MAC / APPID / VLAN;
- svID / optional DataSet reference;
- confRev;
- resolved frame cadence + nofASDU;
- explicit validated counter policy/modulus;
- SmvOpts presence flags;
- ordered fixed wire-leaf descriptors + total payload size;
- synchronization policy input only (never lock truth).
Integrity
Reuse the repository's existing CRC-32 algorithm semantics from the static BRCB checkpoint path, but move/share the primitive only if that can be done without creating a storage-specific dependency. CRC covers the canonical serialized profile with the CRC field zero/excluded by one documented rule.
Host gate
SvPublisherProfile -> CompiledSvDeviceProfileV1must fail closed unless:- profile family is resolved;
- timing needed by this target is resolved;
- sample-counter policy is explicit;
- all bounded field lengths fit;
- channel wire widths/layout are target-supported;
- optional fields unsupported by the target are rejected as device capability, not standard-invalid.
Golden vectors must be byte-for-byte identical on GCC/Clang/MSVC.
Device gate
Decode into a temporary value, verify magic/version/length/CRC/all bounds first, then translate to the existing
RuntimePublisherProfile. Only after full validation mayruntime_profile_commit()swap generation atomically.The current textual
PROFILE ...command transport may remain for development, but it must carry/assemble the same binary envelope or be demoted to a debug adapter. It must not remain a second semantic profile model.Realtime boundary
No change to RUNNING hot path:
- immutable snapshot;
- prebuilt packet/WirePlan before timer start;
- no XML/string/type traversal;
- no CRC work per sample.
Ordered delivery
- portable binary codec + malformed/golden tests;
- host compiler from Class-A profile;
- embedded bounded decoder + atomic commit adapter;
- Studio/legacy bridge sends canonical compiled bytes;
- 4000/4800 software regression;
- physical/timing acceptance stays with P2: deterministic ESP32-P4 Sampled Values publisher and timing evidence #21/P3-A1: compiled SV device profile and deterministic ESP32-P4 activation #36 and is not faked by software CI.
Start implementation only from the exact post-#145 main SHA to avoid parallel profile-schema drift.
- added 5 commits that reference this issue
on Oct 7, 2026 masarray commented
on Oct 7, 2026 OwnerAuthorMore actions2026-10-07 P3-A1 binary decoder integration boundary (reconnaissance; implementation remains gated)
Existing #146 is now based on merged P1.3
main@bdd895ae8641dbf3d9c5c6509e3eb94f78802b8d, with latest hardening commit483bd90e64891a62d474e94729b1a6a1b7c5f5a2and new exact-head CI underway. Do not start firmware integration until #146 host binary golden/negative regressions are accepted.What decoder means: host->ESP32-P4 compiled device-profile binary envelope decoder, not a rewrite of existing SV wire-frame decode or MMS reporting.
Inspection of current firmware owners:
main/runtime_profile.hpp/.cpp: canonical fixedRuntimePublisherProfileandruntime_profile_validate()/ generation incrementingruntime_profile_commit()guarded by existing critical section.main/profile_control.cpp: existingPROFILE BEGIN/ID/DATASET/L2/SV/COMMITstaging and STOPPED gate; do not add a second independent profile state machine.main/app_main.cpp: existing deterministic WirePlan and TX failure authority remain unchanged.include/ariec61850/sampled_values/esp32p4_profile_support.hpp: hostclassify_esp32p4_sv_profilelimits current target to explicitly resolved generic/legacy profile,SmpPerSec, single ASDU, 4I+4V ordered INT32+Quality leaves, no unsupported refresh/security/SynchSrcID, resolved explicit counter modulus.
Next bounded device-side decoder tranche (#36): reuse
SvDeviceProfileBinaryCodecbounded verification of magic/version/length/CRC/ordered descriptors; translate only currently supported V1 fields into a temporary existingRuntimePublisherProfile; verify 16 leaves, eight INT32+Quality pairs, 64-byte payload, exact 1-ASDUSmpPerSec, integral bounded 4000/4800 cadence when requested, allowable SmvOpts, APPID/VLAN/MAC, bounded svID/DataSet, supported profile family, and no unsupported hidden fields. Reject unknown/unresolved variants explicitly as unsupported device capability, not invalid IEC. Perform validation and template preparation outside TX; gate the commit on STOPPED and call existingruntime_profile_commit(). Malformed input must leave active generation and stream identity unchanged. Provide negative CRC/schema/bounds/layout/enum tests plus atomic no-change-on-error tests. Retain legacy textual path until binary transfer and bridge ACK/generation evidence prove parity. Do not claim physical 4000/4800 or external interoperability from build alone.Do not duplicate: encoder CRC-32 implementation, SCL parser, transport-failure authority, PTP clock, scheduler, device profile state machine or packet WirePlan.
masarray commented
on Oct 7, 2026 OwnerAuthorMore actionsAdditional device transport constraint found (2026-10-07 source audit)
embedded/esp32p4_smv_injector/main/live_control.cppcurrently receives console commands using a fixedstd::array<char, 192> linewith an overflow-discard path. Therefore do not send the compiled binary envelope as one long HEX/Base64 text command: the maximum V1 envelope is bounded but can exceed this line capacity after textual encoding. A one-shot naive command would be truncated/rejected.The device integration tranche should use bounded chunked staging (or a framing-capable binary control transport) with explicit declared total length, sequential offsets/chunk limits, monotonic transaction identity or equivalent anti-mix guard, final envelope CRC/schema verification by the canonical
SvDeviceProfileBinaryCodec, and then the existing STOPPED-only activation. Reject overflow, missing/duplicate/out-of-order chunks, invalid total length, stale transaction and CRC corruption without changing the activeRuntimePublisherProfilegeneration. Use fixed storage and no heap in TX. Keep the current textual PROFILE bridge until atomic binary equivalence and ACK/readback tests pass.masarray commented
on Oct 7, 2026 OwnerAuthorMore actions2026-10-07 P3-A1 milestone — host contract merged, embedded Draft PR #149
Accepted dependency: PR #146 merged after 14/14 exact-head green, now
main@879f84b9b9791ebe700b9f000a0292afb083dc80. Host binary V1 schema/CRC/transactional decode and P1.3 malformed nofASDU regressions are now on main.Firmware implementation: draft PR #149 on
hardening/smv-p3a1-esp32p4-binary-activation, exact headb438d7e40538bfd54fc4e583b6558284a240d4b3(ahead 3, behind 0). No competingRuntimePublisherProfile, clock, scheduler, SV packet encoder or active-state authority introduced.- Firmware links the same
SvDeviceProfileBinaryCodecthrougharstack_process_bus; adapter validates complete V1 envelope and narrows to the currently supported 4I+4V single-ASDUSmpPerSecINT32/Quality layout and SmvOpts, or refuses unsupported IEC-valid profiles. - New fixed-bound transfer-only
BinaryProfileStagingreceives 48-byte maximum HEX chunks (fits legacy 192-byte console) with increasing transaction ID and strict sequential offsets.PROFILE BINBEGIN/BINCHUNK/BINCOMMIT/BINABORTcannot produce partial activation: only successful binary CRC/schema/layout and STOPPED gate reach existingruntime_profile_commit(). - START abandons uncommitted text/binary staging; console's existing textual PROFILE route remains unchanged.
PROFILE-BINARY-V1advertised in IDENTIFY and firmware manifest for capability negotiation, while protocol version remains 1.- Host-sim regression includes valid 4800/4I4V, CRC rejection, unsupported IEC 61869-9/mismatched layout/options/rate, truncated/duplicate/out-of-order/oversize chunks, and replay ID rejection. No vendor identifiers or proprietary fixtures.
- Fresh exact-head PR CI triggered on
b438d7e40538bfd54fc4e583b6558284a240d4b3, not accepted yet. Do not merge until C++ Windows/Linux, embedded, PTP and release gates pass. This tranche provides software decode/activation path only; hardware 4000/4800 TX/jitter/relay interoperability and GUI binary transport migration remain independent acceptance requirements. Keep P3-A1: compiled SV device profile and deterministic ESP32-P4 activation #36/P3-A: vendor-neutral SCL-driven SV interoperability profile foundation #33/P2: deterministic ESP32-P4 Sampled Values publisher and timing evidence #21 OPEN.
- Firmware links the same
- added a commit that references this issue
on Oct 7, 2026 masarray commented
on Oct 7, 2026 OwnerAuthorMore actions2026-10-07 P3-A1 implementation acceptance — host + firmware merged
Accepted sequence:
- PR P3-A1: canonical binary SV device-profile envelope #146 host compiled binary V1 envelope merged to
main@879f84b9b9791ebe700b9f000a0292afb083dc80after 14/14 exact-head pull_request workflows succeeded. Canonical magic/version/length/CRC32, bounded wire-leaf layout, transactional decode, golden bytes, invalid-enum and malformed nofASDU regressions. - PR P3-A1: ESP32-P4 bounded binary decoder, staged transport and atomic profile activation #149 ESP32-P4 binary decoder and atomic activation, exact head
b438d7e40538bfd54fc4e583b6558284a240d4b3, 9/9 exact-head pull_request workflows succeeded (C++, security, Embedded Profile, ESP32-P4 build, PTP Lab, release, control/BRCB/dynamic RCB). Merged with expected-head SHA, new main6255d88fe7216dbfa93999a27364958c853c6ca0. Verified PR merged and main SHA.
Implemented #36 software boundary: shared
SvDeviceProfileBinaryCodecreused by ESP, boundedPROFILE BINBEGIN/BINCHUNK/BINCOMMIT/BINABORTusing max 48-byte chunks (fits legacy 192-character console), sequential offsets and monotonic transaction IDs, no partial activation, fail-closed MAC/APPID/CRC/schema/layout/options/sampling validation, supported 4I+4V profile narrowing, START abort of incomplete staging, STOPPED-only reuse of existingruntime_profile_commit()/ generation.PROFILE-BINARY-V1advertised in IDENTIFY and firmware manifest. Legacy text PROFILE intact. No new clock/packet/RT scheduler or active-profile authority.Keep #36 OPEN: post-merge
mainpush CI was still running at this checkpoint; binary auto-deployment in Studio/GUI and physical 4000/4800 continuous capture/EMAC hardware egress timestamp evidence have not been demonstrated. Do not close #33/#21 or claim protection-grade timing or IEC conformance until physical and interoperability acceptance. Next bounded gate is host GUI binary capability negotiation + transport ACK/readback equivalence + independent physical tests.- PR P3-A1: canonical binary SV device-profile envelope #146 host compiled binary V1 envelope merged to
- added a commit that references this issue
on Oct 7, 2026 masarray commented
on Oct 7, 2026 OwnerAuthorMore actionsP3-A1 GUI/board-test artifact milestone — 2026-10-07 (active PR #150)
Accepted prerequisite: main
6255d88fe7216dbfa93999a27364958c853c6ca0includes merged host binary contract #146 and ESP32-P4 bounded decoder/staging/STOPPED atomic activation #149; main post-merge 10/10 push CI succeeded. Stable firmware artifact: run 37566223094, artifactarstack-esp32p4-smv-firmware(raw merged ESP32-P4 image + manifest, 0x0, pre-v3), expiry 2026-10-21.Current unique active GUI integration: PR #150, branch
feature/smv-gui-binary-bench-profile-deploy, exact head83dbf331f68c14e0364d7be810a4b834f8d36af6. Draft and NOT MERGED until fresh exact-head CI green. Do not create another web GUI binary codec/transport branch.- Reuses C++ canonical compiler
SvPublisherProfile -> CompiledSvDeviceProfile -> SvDeviceProfileBinaryCodec, exposingdeviceProfileHexonly when Class A + current device support ready; browser never computes its own SV binary structure or CRC. - WebSerial requires explicit
IDENTIFYcapabilityPROFILE-BINARY-V1and baselinePROFILE SHOWgeneration. Sends <=48-byte chunks sequentially via BINBEGIN/BINCHUNK/BINCOMMIT, requiring transaction-exact bytes-received ACK for every chunk; no silent fallback on binary failure. - After COMMIT,
PROFILE SHOWmust match generation increase, svID, APPID, rate, smpCnt modulus, confRev before UI allows START. Legacy text remains only when old firmware explicitly advertises no binary capability. Prevents false-positive deployment status. - Separate Windows portable artifact pipeline SMV Injector GUI Bench: builds matched native C++ profile compiler, JS chunk/ACK negative tests, C++->binary CRC/length regression, packages
run-portable.cmd+ browser GUI asarstack-smv-injector-bench-windows-x64. Node/Python + Windows build still running at checkpoint. - Physical board/relay/canonical 4000/4800 traffic, real HW egress timestamps, and GUI ACK under hardware remain unproven until user bench captures. Keep P3-A1: compiled SV device profile and deterministic ESP32-P4 activation #36 / P3-A: vendor-neutral SCL-driven SV interoperability profile foundation #33 / P2: deterministic ESP32-P4 Sampled Values publisher and timing evidence #21 open.
Next check: exact-head PR #150 complete CI, fix any issues without changing accepted firmware transport authority, then merge with expected SHA and link verified GitHub Actions artifact for board tests.
- Reuses C++ canonical compiler
masarray commented
on Oct 7, 2026 OwnerAuthorMore actionsP3-A1 GUI bench artifact produced — exact-head PR #150
At
83dbf331f68c14e0364d7be810a4b834f8d36af6, SMV Injector GUI Bench run #37568178699 completed SUCCESS, publishingarstack-smv-injector-bench-windows-x64artifact #11459656999, expiration 2026-10-21 03:48 UTC, containing native C++ profile compiler, portable localhost GUI/JS,run-portable.cmd. It passed C++ SCL→binary V1 header/CRC smoke, JS frame bounds, and simulated strict per-chunk ACK + readback match / reject without silent legacy downgrade.Firmware matching supported V1 protocol remains accepted
main@6255d88fe7216dbfa93999a27364958c853c6ca0: ESP32-P4 firmware artifact run #37566223094,arstack-esp32p4-smv-firmware#11458906727, raw merged 0x0 image, pre-v3, manifest SHA256 contract.Important: #150 as a whole is still Draft pending remaining exact-head Security/C++/Control Interop gates; current GUI artifact is a bench candidate not a public stable release. It is not physical board evidence. After full CI, merge with expected-head and verify main artifact; retain #36 open until physical 4000/4800, canonical mirror/TAP capture, and evidence review.
masarray commented
on Oct 7, 2026 OwnerAuthorMore actionsCorrection — native ARStack Studio is the product authority (2026-10-07)
The earlier #150 browser/WebSerial checkpoint was an architectural regression and is superseded. PR #150 is closed, unmerged, and must not be revived as the product path.
Verified current product baseline:
- latest public release: ARStack Studio v0.1.1
- normal Windows artifact:
ARStack-Studio-0.1.1-win-x64-setup.exe - canonical operator surface:
apps/arstack_studio(Qt/C++/QML) - firmware update/recovery is bundled into Studio through the existing manifest + pinned
espflashflow.
Authoritative P3-A1 integration is now PR #151:
#151
exact head8cebd21a46eb8232571f2dd0648c2a14aaafee11, base accepted main6255d88fe7216dbfa93999a27364958c853c6ca0.Native implementation path:
SclProfileModel -> SvPublisherProfile -> compile_esp32p4_device_profile -> SvDeviceProfileBinaryCodec -> DeviceController -> ESP32-P4.Studio now owns the V1 transfer state machine:
BINSTATUS -> stale BINABORT if required -> BINBEGIN -> <=48-byte BINCHUNK + exact ACK -> BINCOMMIT -> PROFILE SHOW readback. It only arms after generation + svID + APPID + rate + counter modulus + confRev match. Firmware manifest and identity contracts requirePROFILE-BINARY-V1. QML remains presentation-only; there is no browser/WebSerial dependency.Acceptance output for #151 is the existing ARStack Studio Windows release package/installer, with matched firmware bundled. No web artifact counts as acceptance. Keep #36 open until exact-head Studio Qt/Windows/ESP/release CI and physical board/capture evidence complete.
masarray commented
on Oct 7, 2026 OwnerAuthorMore actionsNative integration architecture audit — PR #151
Re-audited after correcting the earlier browser-path mistake. Verdict: directionally correct and strengthening ARStack, with the product authority remaining native ARStack Studio.
Current exact head:
3bfe6445985a034fba7a76d60f13b3f13816dd25, basemain@6255d88fe7216dbfa93999a27364958c853c6ca0, behind=0, Draft.Key invariants checked against NORTH_STAR / #139:
- one C++ binary codec/schema authority; no browser/JS serializer;
- no SCL/XML/string traversal or new allocation in realtime TX hot path;
- no change to GPTimer/EMAC/PTP/live-signal hot path;
- standards validity remains separate from ESP32-P4 deployability;
- binary staging is transfer-only; RuntimePublisherProfile remains the single active authority;
- STOPPED-only atomic commit remains intact;
- no silent text fallback: old v0.1.1 firmware is identified then offered the bundled capability update;
- stale BINABORT/BINCOMMIT ACKs are now transaction-bound and fail closed;
- sync timeout is per validated protocol step, not one coarse 6 s transaction timer;
- deterministic harness now locks stale-ACK rejection and progress deadline rearm.
Remaining non-functional release hygiene: PR bench installer still carries 0.1.1 version naming. Do not publish/tag as a new public 0.1.1; choose next release version separately after physical acceptance. Exact-head CI reruns are required after the audit fixes.
masarray commented
on Oct 7, 2026 OwnerAuthorMore actionsNative ARStack Studio board-test artifact accepted from merged PR #151
Merged product baseline:
main@9e70a4937874e3e1752b725264fe5a2008aa8fb0- PR P3-A1: native ARStack Studio binary profile deployment and installer candidate #151 merged from head
12592a9dad6bbf22c189ca4ff4a35176408b386d - PR merge-ref firmware source
f88e05e588fb399b73d0e05689b6ce1dc72bd4bd - merge-ref tree and final main merge tree are identical:
14007fa6bc5e718e74ea0bf5982511ed701b986f
Exact-head ARStack Studio Release run:
https://github.com/masarray/arstack61850/actions/runs/37599444383Release workflow completed SUCCESS:
- firmware/build-esp32p4 ✅
- Windows x64 package ✅
- Fresh Windows package smoke ✅
- tagged publication skipped intentionally (PR candidate)
Artifact:
arstack-studio-windows-x64(#11473055522)- contains
ARStack-Studio-0.1.1-win-x64-setup.exe - contains portable ZIP +
SHA256SUMS.txt - installer SHA256:
0c7923837f81a274999fbae65b817b71a113e0e8ec7a751396c53ac563f1140e - portable SHA256:
399e46cd238bfee31ee119f99ef038a19db27fefbf6eb759fa8a84626eeaeac2 - artifact expires 2026-10-21
Bundled firmware inside portable/package was independently inspected:
firmware/arstack-esp32p4-smv-0.1.1.bin- firmware SHA256
41f71fe0341f12d043e5b238cf10bce4288688275074bfecca927ab3e713e4d9, matches manifest and bundled firmware SHA256SUMS - manifest requires
PROFILE-BINARY-V1 - bundled
tools/espflash.exepresent - target ESP32-P4, pre-v3, flash offset 0
This is the native ARStack Studio GUI candidate, not the closed web path. It is suitable for physical bench testing. Physical 4000/4800 fps, VLAN/canonical capture, and hardware timing remain separate acceptance evidence.
Post-merge main push CI at checkpoint: 8/12 green, 4 still running, 0 failed. Exact PR head had completed all pull_request gates before merge.
Goal
Bridge the host-side
SvPublisherProfileinto the deterministic ESP32-P4 runtime so canonical Sampled Values behavior is no longer hard-coded in firmware.This is the convergence point between P3-A0 profile correctness and the independent hardware-timing evidence track.
Binary profile contract
Define a versioned, bounded device representation containing only resolved runtime values:
SmvOptsfield-presence policy;No XML, dynamic type traversal or manufacturer-specific identity is sent to the realtime hot path.
Host side
SvPublisherProfileinto the versioned binary representation;Device side
smpSynchuntil synchronization evidence exists.Timing convergence
For each active profile correlate:
P3-A1 must not weaken or bypass the hardware timing evidence introduced by PR #26.
Acceptance families
Out of scope
Those build on this device-profile foundation. Tracks #33, #21 and #24; observed fingerprint work is #35.