Skip to content

P3-A1: native ARStack Studio binary profile deployment and installer candidate - #151

Merged
masarray merged 7 commits into
mainfrom
hardening/smv-p3a1-studio-binary-profile
Oct 7, 2026
Merged

masarray merged 7 commits into
mainfrom
hardening/smv-p3a1-studio-binary-profile

Conversation

@masarray

@masarray masarray commented Oct 7, 2026 •

Copy link
Copy Markdown
Owner

Tracks #36, #33 and recovery #139. Supersedes closed #150 (deprecated browser/WebSerial control path).

Correct product path

ARStack Studio Qt/C++ is the canonical operator surface and the Windows installer is the release artifact. This PR wires the accepted #146/#149 binary V1 profile contract into the native Studio pipeline:

SCL/CID -> native SclProfileModel -> SvPublisherProfile -> compile_esp32p4_device_profile -> SvDeviceProfileBinaryCodec -> native DeviceController -> ESP32-P4 firmware.

Changes

  • SclProfileModel exposes the canonical C++-encoded V1 bytes internally as QVariant/QByteArray; QML never owns CRC, layout or serialization.
  • DeviceController requires PROFILE-BINARY-V1 and replaces legacy text PROFILE BEGIN/ID/L2/SV batching with an explicit state machine:
    BINSTATUS -> stale BINABORT if needed -> BINBEGIN -> bounded 48-byte BINCHUNK + exact ACK -> BINCOMMIT -> PROFILE SHOW verification.
  • Studio only arms the profile after readback matches committed generation, svID, APPID, rate, smpCnt modulus and confRev.
  • Firmware adds read-only BINSTATUS so Studio can recover deterministically from abandoned staging across reconnect/app restart.
  • FirmwareManager and Studio identity contract require PROFILE-BINARY-V1, so an older v0.1.1 firmware is offered the bundled update rather than silently using the legacy bridge.
  • Native profile sync keeps the original 2.5 s per-step deadline; each validated binary ACK explicitly rearms that deadline. A stalled step fails boundedly instead of hiding behind one long transaction timeout.
  • CI source gate explicitly forbids returning DeviceController to textual PROFILE BEGIN and forbids a dependency on apps/smv_injector_gui.
  • Studio docs corrected: v0.1.1 is the latest public installer release.

Acceptance

Keep Draft until exact-head C++/Qt/ESP/security + ARStack Studio Release workflows are green. The desired test artifact is the existing arstack-studio-windows-x64 package containing ARStack-Studio-0.1.1-win-x64-setup.exe plus the matched firmware bundle. No web artifact is an acceptance output.

Physical 4000/4800 fps, canonical VLAN/multicast capture and hardware timestamp evidence remain separate bench acceptance gates.

Architecture audit after native-path correction

  • Base is current accepted main@6255d88fe7216dbfa93999a27364958c853c6ca0; branch is not rebasing over or reviving the deprecated browser path.
  • Diff does not touch realtime TX hot-loop, GPTimer scheduling, EMAC/PTP packet path, active RuntimePublisherProfile ownership, SCL parser semantics, or live signal banking.
  • QML remains presentation-only: requestProfileSync() carries no profile payload from QML; SmartSessionController reads the C++ SclProfileModel directly.
  • Binary envelope has one authority: SvDeviceProfileBinaryCodec is used by native Studio and firmware; there is no JS serializer/CRC/model.
  • Firmware staging remains transfer-only; active generation is still assigned exclusively by runtime_profile_commit() while STOPPED.
  • BINABORT/BINCOMMIT ACKs are transaction-bound; Studio rejects stale ACK identity and rearms a bounded deadline only on validated progress.
  • Existing public v0.1.1 firmware is a supported migration source: it can identify, then Studio requires the bundled capability update rather than silently falling back to text deployment.
  • Physical timing/interoperability remains a separate evidence gate; no CI result is promoted to hardware proof.

Release hygiene note: PR CI currently still packages version label 0.1.1; do not publish/tag this branch as a new public release under that same version. The CI artifact can be used as an exact-head bench candidate; semantic versioning for the next public release is a separate decision.

Expose C++-compiled device-profile bytes through SclProfileModel, require PROFILE-BINARY-V1 in native identity/firmware contracts, and add firmware BINSTATUS recovery introspection. No web control path.
Replace legacy text batch deployment in DeviceController with BINSTATUS recovery, stale-stage abort, transaction-exact chunk ACKs, BINCOMMIT, and PROFILE SHOW identity/generation verification. Increase bounded sync timeout for sequential acknowledgements.
Add explicit native C++/firmware source gate, keep browser control surface out of Studio build, and update Studio docs to the current v0.1.1 installer release.
Make BINABORT/BINCOMMIT acknowledgements transaction-exact and refresh the bounded Studio sync deadline only on validated protocol progress, preventing stale serial responses from completing a newer deployment.
Assert stale ACKs cannot arm or advance profile generation while allowing SmartSessionController to retain its production retry policy.
@masarray
masarray marked this pull request as ready for review October 7, 2026 09:31
@masarray
masarray merged commit 9e70a49 into main Oct 7, 2026
30 checks passed
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-07T09:32:15.764629Z 12592a9 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant