Skip to content

G2.6 Smart Dynamic RCB: guarded normal runtime with MMS fallback - #230

Draft
masarray wants to merge 97 commits into
g2.5-a2.1-command-bound-witnessfrom
g2.6-smart-dynamic-rcb
Draft

G2.6 Smart Dynamic RCB: guarded normal runtime with MMS fallback#230
masarray wants to merge 97 commits into
g2.5-a2.1-command-bound-witnessfrom
g2.6-smart-dynamic-rcb

Conversation

@masarray

@masarray masarray commented Aug 24, 2026

Copy link
Copy Markdown
Owner

Goal

Make Smart Dynamic RCB work in the normal ARSAS monitoring path without repeated commissioning/shadow hotkeys and without conflating guarded runtime operation with ProductionEligible certification.

Normal operator workflow:

Open SCL -> Connect IED -> Start Monitor

No Ctrl+Shift+S, Ctrl+Shift+A, or requalification is required for normal Smart Dynamic operation.

Physical basis already proven

The field IED has already demonstrated:

  • exact URCB AA1C1F08R4ADD/LLN0.RP.A_URCB01 activation and DataSet binding;
  • RptEna=true;
  • later NO-GI spontaneous reason=data-change InformationReport on Q0;
  • command-bound correlated DataSet indexes [0,1];
  • healthy association and complete cleanup/restore;
  • re-subscription across deliberate reconnect in the later shadow collector.

The strict shadow/certification path remains fail-closed where report-side q/t is absent. This PR does not bypass that separate certification boundary.

The persisted profile remains InformationReportProven; normal runtime never promotes or saves it.

ARIEC engine

ARSAS now pins merged ARIEC61850 PR #102:

main @ 0965f67fe912355b3b29fc8123872a68d4064b04

PR #100 remains the native stored-DataChange guarded planner. PR #101 introduced the first legacy compatibility seam. The physical P1.5 field run then exposed that the persisted legacy chain is broader than the later A3 dchg proof, so PR #102 adds the P1.5b subset-scoped planner.

P1.5b — broader persisted chain, narrower physical dchg scope

The exact persisted legacy InformationReportProven chain remains six members, in order:

  1. AA1C1F08R4Q0/CSWI1$ST$Pos$stVal
  2. AA1C1F08R4Q0/XCBR1$ST$Pos$stVal
  3. AA1C1F08R4Q0/CSWI1$ST$Beh$stVal
  4. AA1C1F08R4Q0/CSWI1$ST$Health$stVal
  5. AA1C1F08R4Q0/CSWI1$ST$Loc$stVal
  6. AA1C1F08R4Q0/CSWI1$ST$LocKey$stVal

The later deterministic A3 field run proved an actual NO-GI spontaneous dchg report only for the ordered subset:

  1. AA1C1F08R4Q0/CSWI1$ST$Pos$stVal
  2. AA1C1F08R4Q0/XCBR1$ST$Pos$stVal

The A3 transaction used temporary DataSet AA1C1F08R4ADD/LLN0.AR_G25A_4E20EC7E, correlated indexes [0,1], verified reason=data-change, GI disabled, healthy association, and complete monitor/proof-field/fresh-association cleanup.

P1.5b therefore does not rewrite the six-member GI-classified persisted report proof into DataChange. The broader chain remains unchanged qualification evidence; only the two-member later physical dchg subset may receive guarded dynamic runtime authority.

See docs/G2_6_P1_5B_SUBSET_COMPATIBILITY.md.

Exact compatibility manifest

ARSAS hard-binds the reviewed field evidence to:

  • stable identity ied:AA1C1F08R4;
  • fingerprint sha256:50c691318c6d6a16b68b121ac48627c26e6e32b937836d559dca1b9eb559f0d9;
  • profile revision e5f7fe9b93524f8019ff7cd01f042fc1827ef32e8b930262a2eafbf20ef357c0;
  • exact URCB AA1C1F08R4ADD/LLN0.RP.A_URCB01;
  • exact six-member persisted activation/report/envelope sequence;
  • exact two-member ordered physical dchg subset;
  • actual InformationReport, dchg reason, GI disabled, exact mapping, healthy association and cleanup.

This is not a wildcard migration.

ARIEC P1.5b authorization gates

MmsGuardedDynamicReportLegacySubsetCompatibilityPolicy requires:

  • supported schema;
  • current identity compatibility;
  • InformationReportProven or stronger persisted state;
  • successful persisted activation + actual InformationReport chain;
  • legacy stored report kind exactly GeneralInterrogation;
  • exact activation/report RCB and DataSet equality;
  • exact full activation/report member-sequence equality;
  • full persisted report sequence inside the accepted envelope;
  • complete separate physical NO-GI dchg evidence;
  • exact current stable identity / fingerprint / profile revision;
  • exact RCB match;
  • nonempty unique dchg members;
  • dchg members as an ordered subset of both the persisted successful report sequence and accepted envelope.

MmsGuardedDynamicReportLegacySubsetRuntimePlanner then restricts automatic dynamic planning to only that later-proven subset, with at most one exact dynamic RCB. Static reporting keeps precedence and everything outside the proven dchg subset remains static/polling as applicable.

ARSAS normal-runtime integration

NativeIec61850Client loads the identity-compatible qualification profile read-only.

Dispatch is now:

  1. no guarded context -> capability-aware static/polling planner;
  2. persisted report kind already DataChange -> existing guarded planner;
  3. reviewed GI-classified legacy chain -> P1.5b subset planner;
  4. any mismatch -> fail closed.

The same PlanId-bound original context is retained through fresh execution revalidation. The exact P1.5b registry is resolved again before use; planning is not indefinite write permission.

No in-memory DataChange rewrite is performed for the broader legacy profile.

Smart Auto static -> dynamic recovery

Static recovery still:

  • preserves the same PlanId-bound context;
  • excludes the failed static RCB;
  • requires proven cleanup after any static mutation;
  • may use only the exact P1.5b-authorized dynamic RCB/subset;
  • re-enters normal StartHybridReportMonitorAsync for fresh availability/revalidation;
  • cannot substitute an arbitrary free RCB.

Runtime fallback

MMS validation remains beside report acquisition. Missing/unverified report delivery degrades affected points to MMS fallback. A real dynamic activation failure opens the existing per-device process-lifetime dynamic-write circuit breaker to prevent a repeated mutation loop.

Certification boundary

P1.5b does not:

  • save or mutate the persisted profile;
  • call MarkProductionEligible;
  • broaden the dchg evidence from two members to six;
  • substitute another free RCB;
  • bypass fresh capability/availability checks;
  • relax strict shadow q/t acceptance.

P1.5b guarded runtime != ProductionEligible certification.

Field objective after exact-head CI

  1. Open SCL and connect normally.
  2. Start Monitor — no commissioning hotkey.
  3. Verify diagnostics say P1.5b subset compatibility accepted.
  4. Verify dynamicURCB > 0 for exact AA1C1F08R4ADD/LLN0.RP.A_URCB01 and only the Q0 CSWI/XCBR dchg subset.
  5. Verify dynamic DataSet bind and RptEna=true.
  6. Exercise an approved Q0 OPEN/CLOSE and verify spontaneous data-change updates plus MMS reconciliation.
  7. Disconnect/reconnect and verify fresh revalidation/re-arm without repeated mutation.
  8. Any failure must fall back to static/MMS, not loop writes.

Keep this PR draft and unmerged until that normal-runtime field run is reviewed cleanly.

Copy link
Copy Markdown
Owner Author

G2.6 independent polling q/t increment is implemented and exact-head CI is green at ae1e6b6bf9e86da7e01cd57b13b4fdd762f22017.

Implementation boundary:

  • isolated read-only MMS polling association derives exact bounded q/t siblings from each proven process member;
  • companion must resolve exactly in the live MMS directory under the same FC and must not be a control/report attribute;
  • at most one q read + one t read per successful primary-value observation;
  • q uses ARIEC Iec61850QualityDecoder;
  • t is accepted only from decoded physical Iec61850UtcTime, normalized to UTC;
  • no host read-time fallback, no report-copy, no TimeOfEntry fallback;
  • missing/read-failed/undecodable metadata remains missing and strict acceptance stays fail-closed.

Exact-head validation:

  • Build ARSAS #1458: success; build 0 errors; regression tests 602/602 passed; portable publish + smoke test passed.
  • Windows installer #408: success, including solution build/test and silent install/uninstall validation.
  • IO List #401: success.
  • SV evidence #570: success.

PR remains draft and unmerged. InformationReportProven remains authoritative; ProductionEligible and production automatic dynamic reporting remain OFF. Next evidence gate is the physical two-phase Ctrl+Shift+S shadow run.

@masarray masarray changed the title G2.6 Smart Auto + physical shadow verification: guarded dynamic reporting recovery G2.6 Smart Dynamic RCB: guarded normal runtime with MMS fallback Aug 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant