Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
126 commits
Select commit Hold shift + click to select a range
6887ea1
test(discovery): add bounded smart capture path
masarray Sep 16, 2026
c7da2e9
test(discovery): route capture build to smart path
masarray Sep 16, 2026
f131501
test(discovery): enable smart capture route before compile
masarray Sep 16, 2026
6fa3b7b
test(discovery): pin ARIEC61850 smart discovery PR
masarray Sep 16, 2026
9743459
ci(test): build smart discovery field-capture executable
masarray Sep 16, 2026
f543ded
fix(test): support Windows PowerShell smart route patch
masarray Sep 16, 2026
c3dc8c3
fix(test): preserve reviewed engine ancestry in capture pin
masarray Sep 16, 2026
6f06881
perf(discovery): index smart projection and guard reentry
masarray Sep 16, 2026
97d4f23
perf(discovery): reuse smart authority and expose phase timings
masarray Sep 16, 2026
688f930
fix(discovery): disambiguate cached phase timers
masarray Sep 16, 2026
42d6401
ci(discovery): harden R2 provenance and critical-path invariants
masarray Sep 16, 2026
38fa850
perf(discovery): harden association-scoped authority lifecycle
masarray Sep 16, 2026
33526f6
perf(discovery): bind smart authority to active MMS association
masarray Sep 16, 2026
fddcd10
build(discovery): install explicit smart authority reset on reconnect
masarray Sep 16, 2026
ca388a5
ci(discovery): enforce authority lifecycle invalidation in R2 build
masarray Sep 16, 2026
445d3c9
perf(discovery): serialize R3 smart capture on MMS operation gate
masarray Sep 16, 2026
7399811
test(discovery): pin PR134 R3 single-flight engine
masarray Sep 16, 2026
1b375f5
ci(discovery): validate R3 single-flight field build
masarray Sep 16, 2026
c82cdbd
fix(discovery): keep MMS gate held through shared directory flight
masarray Sep 16, 2026
54cd4c3
test(discovery): mark R4 authoritative control inventory
masarray Sep 17, 2026
439da95
test(discovery): pin R4 authoritative control inventory engine
masarray Sep 17, 2026
b75d0fa
ci(discovery): verify R4 control inventory reuse
masarray Sep 17, 2026
b1e5c93
perf(discovery): route control to smart inventory authority
masarray Sep 17, 2026
aa694ef
ci(discovery): verify explicit control inventory reuse
masarray Sep 17, 2026
58b1830
test(discovery): pin explicit control inventory reuse engine
masarray Sep 17, 2026
5c22f11
P0-5c bind smart discovery flight to association generation
masarray Sep 17, 2026
03e01fb
P0-5c make association flight creation atomic
masarray Sep 17, 2026
d8631e5
P0-5c coalesce full enrichment into one association flight
masarray Sep 17, 2026
a292486
P0-5c invalidate association flight on connect and dispose
masarray Sep 17, 2026
7dcc16c
P0-5c lock association single-flight regression contracts
masarray Sep 17, 2026
63b2c83
P0-5c pin ARSAS to P0-5b engine head
masarray Sep 17, 2026
5d5dbf3
P0-5c verify association single-flight against P0-5b engine
masarray Sep 17, 2026
42c8f54
P0-5c preserve field-proven ancestry in smart discovery pin
masarray Sep 17, 2026
72617d9
test(discovery): add P0-5d physical PCAP proof verifier
masarray Sep 17, 2026
9ba2fa6
docs(discovery): define P0-5d physical capture proof contract
masarray Sep 17, 2026
c794ad9
test(discovery): lock P0-5d wire-proof contract
masarray Sep 17, 2026
ee06c49
refactor(discovery): replace P0-5d verifier with testable proof path
masarray Sep 17, 2026
bc20bd6
test(discovery): add testable P0-5d physical PCAP verifier
masarray Sep 17, 2026
a103f2f
docs(discovery): keep P0-5d proof contract clean-room safe
masarray Sep 17, 2026
218be6b
ci(discovery): execute P0-5d wire-proof regressions
masarray Sep 17, 2026
8d0e6bb
fix(p0-5d): make duplicate sums strict-mode safe
masarray Sep 17, 2026
748b3a6
feat(p0-5e): derive golden request budget from physical proof
masarray Sep 17, 2026
035d749
feat(p0-5e): enforce same-IED hard request budget
masarray Sep 17, 2026
ea557d0
test(p0-5e): define same-IED golden semantic target
masarray Sep 17, 2026
442e172
fix(p0-5e): clarify indexed RCB family target
masarray Sep 17, 2026
3ff7d23
test(p0-5e): lock golden capture budget contract
masarray Sep 17, 2026
2358c5b
docs(p0-5e): define golden capture budget lock workflow
masarray Sep 17, 2026
a17e64e
ci(p0-5e): prove golden hard-budget lock behavior
masarray Sep 17, 2026
b72d023
ci(p0-5e): package golden lock tools and fix P0-5d harness
masarray Sep 17, 2026
ac24307
test(discovery): bind golden lock to raw capture and build manifest
masarray Sep 17, 2026
a2dcb72
test(discovery): enforce build and semantic provenance in golden acce…
masarray Sep 17, 2026
e9d3148
test(discovery): lock P0-5e capture and build provenance
masarray Sep 17, 2026
2c692ed
ci(discovery): verify P0-5e golden provenance binding
masarray Sep 17, 2026
e93c089
ci(discovery): migrate P0-5e budget fixtures to provenance contract
masarray Sep 17, 2026
971d4c5
docs(discovery): document P0-5e provenance hardening
masarray Sep 17, 2026
c92061c
fix(discovery): make P0-5e writer parse on Windows PowerShell
masarray Sep 17, 2026
59b14e1
P0-5f emit zero-traffic repeat-run discovery evidence
masarray Sep 17, 2026
97e3efd
P0-5f bind fresh association discovery to repeat-run evidence
masarray Sep 17, 2026
62d237b
P0-5f define physical repeat-run stability authority
masarray Sep 17, 2026
eabb9b2
P0-5f bind each physical repeat run into immutable evidence bundle
masarray Sep 17, 2026
3cdc5b0
fix(scl): acquire live FCDA evidence during RCB export
masarray Sep 17, 2026
b13a863
P0-5f finalize golden stability from three independent repeat bundles
masarray Sep 17, 2026
96253e4
fix(scl): use engine dataset model contract
masarray Sep 17, 2026
d66b3d1
test(scl): guard live FCDA evidence acquisition before export
masarray Sep 17, 2026
0b4c668
fix(scl): preserve authoritative empty live DatSet binding
masarray Sep 17, 2026
1d12d8a
test(scl): guard authoritative empty live DatSet binding
masarray Sep 17, 2026
f7c6b25
P0-5f enforce independent association stability
masarray Sep 17, 2026
8e1a670
P0-5f add repeat-run stability regression contract
masarray Sep 17, 2026
7e084a1
P0-5f add repeat-run stability CI gate
masarray Sep 17, 2026
674a8a4
P0-5f document physical repeat-run finalization
masarray Sep 17, 2026
8bfbfeb
P0-5f add physical finalization authority gate
masarray Sep 17, 2026
f7451e7
P0-5f lock physical finalization authority contract
masarray Sep 17, 2026
e0a0736
P0-5f document physical authority promotion
masarray Sep 17, 2026
66decfc
P0-5f prove fixture promotion is rejected
masarray Sep 17, 2026
1096950
P0-5f fix Windows PowerShell workflow interpolation
masarray Sep 17, 2026
04a2bf0
P0-5g add fail-closed production promotion switch
masarray Sep 17, 2026
80c223a
P0-5g gate smart route behind explicit promotion
masarray Sep 17, 2026
b25ba82
P0-5g add production promotion target contract
masarray Sep 17, 2026
0511d59
P0-5g add production readiness verifier
masarray Sep 17, 2026
5ff9886
P0-5g add physical-authority promotion writer
masarray Sep 17, 2026
ae51568
P0-5g add production promotion regression contract
masarray Sep 17, 2026
91d9c2c
P0-5g document production promotion and merge gates
masarray Sep 17, 2026
27027e9
P0-5g add production promotion guard workflow
masarray Sep 17, 2026
48e02f0
P0-5g harden engine discovery-critical compatibility set
masarray Sep 17, 2026
d7b3033
P0-5g fix full-history checkout for promotion guard
masarray Sep 17, 2026
2314ca7
P0-5g keep release notes clean-room neutral
masarray Sep 17, 2026
92339d7
P0-5g bind production switch to exact promotion authority
masarray Sep 17, 2026
31aaa78
P0-5g regress promotion authority hash binding
masarray Sep 17, 2026
3c37bb0
P0-5g require exact promotion authority binding
masarray Sep 17, 2026
2f5e489
P0-5g lock new promotion binding contract in tests
masarray Sep 17, 2026
311df48
P0-5g bind authority to exact target and engine lock
masarray Sep 17, 2026
aa647e3
P0-5g regress target and lock provenance binding
masarray Sep 17, 2026
85d9fa5
P0-5g normalize empty git diff results under StrictMode
masarray Sep 17, 2026
df1985a
P0-5g require complete physical authority provenance
masarray Sep 17, 2026
646b9e5
P0-5g fail closed on incomplete physical authority provenance
masarray Sep 17, 2026
ee56251
P0-5g regress physical authority provenance validation
masarray Sep 17, 2026
b425cc9
P0-5g allow fail-closed props without promotion bindings
masarray Sep 17, 2026
73a4ec6
P0-5g regress fail-closed optional promotion bindings
masarray Sep 17, 2026
ae945d9
P0-5g add fail-closed mainline readiness gate
masarray Sep 17, 2026
01c4ddd
P0-5g require dedicated mainline readiness gate
masarray Sep 17, 2026
8ee7c62
P0-5g lock dedicated mainline gate contract
masarray Sep 17, 2026
d688f74
P0-5g persist blocked mainline readiness evidence
masarray Sep 17, 2026
65473aa
P0-5g assert auditable blocked mainline evidence
masarray Sep 17, 2026
3851234
fix(discovery): compare readiness repository heads explicitly
masarray Sep 17, 2026
5e0fe68
fix(discovery): build fail-closed ARSAS against evidence engine pin
masarray Sep 17, 2026
76500b5
test(discovery): define P0-5h mainline merge contract
masarray Sep 17, 2026
e73a716
test(discovery): add P0-5h merge execution manifest
masarray Sep 17, 2026
b85e7c9
test(discovery): lock P0-5h merge method
masarray Sep 17, 2026
f7c7332
test(discovery): add P0-5h post-merge production verifier
masarray Sep 17, 2026
8dd33c1
test(discovery): bind P0-5h manifest to merge commit method
masarray Sep 17, 2026
bb6fb3a
test(discovery): allow tracked P0-5h merge manifest after physical au…
masarray Sep 17, 2026
48b0088
test(discovery): add P0-5h merge execution regressions
masarray Sep 17, 2026
fbdc16e
test(discovery): close P0-5h self-reference gap
masarray Sep 17, 2026
0678228
test(discovery): separate validated and live ARSAS merge heads
masarray Sep 17, 2026
f3e799c
test(discovery): verify validated ARSAS ancestry after merge
masarray Sep 17, 2026
fd40fee
test(discovery): cover P0-5h live merge head resolution
masarray Sep 17, 2026
405b653
test(discovery): add P0-5h merge execution guard
masarray Sep 17, 2026
f9fd7f9
test(discovery): add P0-5h post-merge production verification
masarray Sep 17, 2026
78beeb6
docs(discovery): add P0-5h merge and post-merge protocol
masarray Sep 17, 2026
62fec61
test(discovery): add P0-5h live merge preflight
masarray Sep 17, 2026
eeed677
test(discovery): cover P0-5h live execution preflight
masarray Sep 17, 2026
5027f05
test(discovery): validate P0-5h live merge preflight
masarray Sep 17, 2026
608abc7
docs(discovery): document P0-5h live merge preflight
masarray Sep 17, 2026
5f8184b
fix(discovery): retain bounded semantic enrichment
masarray Sep 17, 2026
2877088
test(discovery): lock bounded semantic enrichment
masarray Sep 17, 2026
0c1c91a
fix(discovery): checkout pinned engine in P0-5h guard
masarray Sep 17, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
288 changes: 288 additions & 0 deletions .github/workflows/smart-discovery-capture-build.yml

Large diffs are not rendered by default.

188 changes: 188 additions & 0 deletions .github/workflows/smart-discovery-golden-budget-lock.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,188 @@
name: Smart Discovery Golden Budget Lock

on:
pull_request:
workflow_dispatch:

jobs:
verify-golden-lock:
name: Verify P0-5e evidence-derived hard budget
runs-on: windows-latest
steps:
- name: Checkout ARSAS branch
shell: powershell
run: |
$ref = if ($env:GITHUB_HEAD_REF) { $env:GITHUB_HEAD_REF } else { $env:GITHUB_REF_NAME }
git clone --quiet --depth 1 --branch $ref "https://github.com/$env:GITHUB_REPOSITORY.git" ArIED61850Tester

- name: Validate P0-5e production target remains evidence-gated
shell: powershell
run: |
$targetPath = '.\ArIED61850Tester\evidence\smart-discovery-golden-target.json'
$target = Get-Content $targetPath -Raw | ConvertFrom-Json
if ($target.Phase -ne 'P0-5e' -or $target.Status -ne 'awaiting-fresh-physical-budget-lock') {
throw 'P0-5e target state is invalid.'
}
if ($null -ne $target.BudgetAuthority.BudgetValues) {
throw 'Production hard budget must not be populated by CI fixture values.'
}
if ($target.DeviceIdentity -ne 'AA1E1F06R4' -or
$target.SemanticTarget.LogicalDevices -ne 32 -or
$target.SemanticTarget.LogicalNodes -ne 119 -or
$target.SemanticTarget.SemanticLeaves -ne 4925 -or
$target.SemanticTarget.DataSets -ne 2 -or
$target.SemanticTarget.OrderedFcdaMembers -ne 58 -or
$target.SemanticTarget.LogicalReportControls -ne 32 -or
$target.SemanticTarget.RuntimeReportControlInstances -ne 34) {
throw 'P0-5e same-IED semantic target changed unexpectedly.'
}

- name: Execute P0-5e golden budget fixtures
shell: powershell
run: |
$writer = '.\ArIED61850Tester\scripts\new-smart-discovery-golden-lock.ps1'
$verifier = '.\ArIED61850Tester\scripts\verify-smart-discovery-golden-lock.ps1'
$target = '.\ArIED61850Tester\evidence\smart-discovery-golden-target.json'
foreach ($required in @($writer, $verifier, $target)) {
if (-not (Test-Path $required -PathType Leaf)) { throw "P0-5e source missing: $required" }
}

foreach ($script in @($writer, $verifier)) {
$tokens = $null
$errors = $null
[System.Management.Automation.Language.Parser]::ParseFile($script, [ref]$tokens, [ref]$errors) | Out-Null
if ($errors.Count -ne 0) { throw "PowerShell parse failure in $script" }
}

$results = '.\ArIED61850Tester\TestResults'
New-Item -ItemType Directory -Force $results | Out-Null
$capture = Join-Path $results 'p0-5e-fixture.pcapng'
[IO.File]::WriteAllBytes($capture, [Text.Encoding]::UTF8.GetBytes('CI fixture only - not physical evidence'))

$proofPath = Join-Path $results 'P0-5D-fixture-golden-source.json'
$proof = [ordered]@{
SchemaVersion = 1
Phase = 'P0-5d'
Verdict = 'PASS'
AcceptanceFailures = @()
ArsasCapture = [ordered]@{
Capture = 'fixture'
ClientIp = '192.0.2.10'
ServerIp = '192.0.2.20'
RequestTcpStreams = @('0')
ConfirmedRequests = 4
ConfirmedResponsesOrErrors = 4
ServiceCounts = [ordered]@{
GetNameList = 2
GetVariableAccessAttributes = 2
}
DuplicateSemanticRequests = 0
DuplicateGetNameListRequests = 0
DuplicateGvaRequests = 0
DuplicateDetails = @()
SecondGetNameListSweepDetected = $false
PeakOutstandingRequests = 3
NegotiatedMaxOutstandingCalling = 10
InvokeIdReuseWhileOutstanding = 0
OrphanResponses = 0
UnansweredRequestsAtCaptureEnd = 0
}
}
$proof | ConvertTo-Json -Depth 12 | Set-Content $proofPath -Encoding utf8

$arsasCommit = (git -C .\ArIED61850Tester rev-parse HEAD).Trim().ToLowerInvariant()
$engineCommit = '4467124775d8d9d76f3db194f9fbfd97144767a8'
$manifest = Join-Path $results 'SMART-CAPTURE-BUILD.txt'
@(
'ARSAS smart discovery field-capture build',
"ARSAS commit: $arsasCommit",
"ARIEC61850 commit: $engineCommit",
'Engine PR: 134'
) | Set-Content $manifest -Encoding utf8

$lockPath = Join-Path $results 'P0-5E-fixture-golden.lock.json'
& $writer `
-ProofJson $proofPath `
-CapturePath $capture `
-DeviceIdentity 'AA1E1F06R4' `
-ArsasCommit $arsasCommit `
-EngineCommit $engineCommit `
-TargetPath $target `
-BuildManifestPath $manifest `
-OutputPath $lockPath `
-AllowFixtureEvidence

$lock = Get-Content $lockPath -Raw | ConvertFrom-Json
if ($lock.Status -ne 'locked' -or
$lock.SchemaVersion -ne 2 -or
$lock.HardRequestBudget.MaxConfirmedRequests -ne 4 -or
$lock.HardRequestBudget.MaxServiceRequests.GetNameList -ne 2 -or
$lock.HardRequestBudget.MaxServiceRequests.GetVariableAccessAttributes -ne 2 -or
$lock.GoldenSource.CaptureSha256 -notmatch '^[0-9a-f]{64}$' -or
$lock.GoldenSource.ProofSha256 -notmatch '^[0-9a-f]{64}$' -or
$lock.GoldenSource.BuildManifestSha256 -notmatch '^[0-9a-f]{64}$' -or
$lock.GoldenSource.SemanticTargetSha256 -notmatch '^[0-9a-f]{64}$') {
throw 'P0-5e lock writer did not derive the expected fixture budget/provenance.'
}

$acceptPath = Join-Path $results 'P0-5E-fixture-accept-pass.json'
& $verifier `
-LockPath $lockPath `
-ProofJson $proofPath `
-DeviceIdentity 'AA1E1F06R4' `
-CandidateArsasCommit $arsasCommit `
-CandidateEngineCommit $engineCommit `
-TargetPath $target `
-OutputJson $acceptPath
$accept = Get-Content $acceptPath -Raw | ConvertFrom-Json
if ($accept.Verdict -ne 'PASS') { throw 'P0-5e golden fixture should pass its own lock.' }

$growthProofPath = Join-Path $results 'P0-5D-fixture-growth.json'
$growth = Get-Content $proofPath -Raw | ConvertFrom-Json
$growth.ArsasCapture.ConfirmedRequests = 5
$growth.ArsasCapture.ServiceCounts.GetVariableAccessAttributes = 3
$growth | ConvertTo-Json -Depth 12 | Set-Content $growthProofPath -Encoding utf8
$growthAcceptPath = Join-Path $results 'P0-5E-fixture-growth-rejected.json'
& $verifier `
-LockPath $lockPath `
-ProofJson $growthProofPath `
-DeviceIdentity 'AA1E1F06R4' `
-CandidateArsasCommit $arsasCommit `
-CandidateEngineCommit $engineCommit `
-TargetPath $target `
-OutputJson $growthAcceptPath `
-NoFailExit
$growthAcceptance = Get-Content $growthAcceptPath -Raw | ConvertFrom-Json
if ($growthAcceptance.Verdict -ne 'FAIL' -or
-not (@($growthAcceptance.AcceptanceFailures) -match 'Confirmed request budget exceeded')) {
throw 'P0-5e failed to reject confirmed-request growth.'
}

$serviceProofPath = Join-Path $results 'P0-5D-fixture-unexpected-service.json'
$serviceGrowth = Get-Content $proofPath -Raw | ConvertFrom-Json
$serviceGrowth.ArsasCapture.ServiceCounts | Add-Member -NotePropertyName Read -NotePropertyValue 1
$serviceGrowth | ConvertTo-Json -Depth 12 | Set-Content $serviceProofPath -Encoding utf8
$serviceAcceptPath = Join-Path $results 'P0-5E-fixture-unexpected-service-rejected.json'
& $verifier `
-LockPath $lockPath `
-ProofJson $serviceProofPath `
-DeviceIdentity 'AA1E1F06R4' `
-CandidateArsasCommit $arsasCommit `
-CandidateEngineCommit $engineCommit `
-TargetPath $target `
-OutputJson $serviceAcceptPath `
-NoFailExit
$serviceAcceptance = Get-Content $serviceAcceptPath -Raw | ConvertFrom-Json
if ($serviceAcceptance.Verdict -ne 'FAIL' -or
-not (@($serviceAcceptance.AcceptanceFailures) -match "Unexpected MMS service 'Read'")) {
throw 'P0-5e failed to reject an unexpected MMS service.'
}

- name: Upload P0-5e regression evidence
if: always()
uses: actions/upload-artifact@v4
with:
name: ARSAS-p0-5e-golden-budget-fixtures
path: ArIED61850Tester\TestResults\P0-5E-*.json
if-no-files-found: warn
retention-days: 14
157 changes: 157 additions & 0 deletions .github/workflows/smart-discovery-golden-provenance.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,157 @@
name: Smart Discovery Golden Provenance

on:
pull_request:
workflow_dispatch:

jobs:
verify-provenance:
name: Verify P0-5e capture build and target provenance
runs-on: windows-latest
steps:
- name: Checkout ARSAS branch
shell: powershell
run: |
$ref = if ($env:GITHUB_HEAD_REF) { $env:GITHUB_HEAD_REF } else { $env:GITHUB_REF_NAME }
git clone --quiet --depth 1 --branch $ref "https://github.com/$env:GITHUB_REPOSITORY.git" ArIED61850Tester

- name: Execute P0-5e provenance fixtures
shell: powershell
run: |
$writer = '.\ArIED61850Tester\scripts\new-smart-discovery-golden-lock.ps1'
$verifier = '.\ArIED61850Tester\scripts\verify-smart-discovery-golden-lock.ps1'
$target = '.\ArIED61850Tester\evidence\smart-discovery-golden-target.json'
foreach ($required in @($writer, $verifier, $target)) {
if (-not (Test-Path $required -PathType Leaf)) { throw "Missing P0-5e provenance source: $required" }
}

foreach ($script in @($writer, $verifier)) {
$tokens = $null
$errors = $null
[System.Management.Automation.Language.Parser]::ParseFile($script, [ref]$tokens, [ref]$errors) | Out-Null
if ($errors.Count -ne 0) { throw "PowerShell parse failure in $script" }
}

$results = '.\ArIED61850Tester\TestResults'
New-Item -ItemType Directory -Force $results | Out-Null
$capture = Join-Path $results 'p0-5e-provenance-fixture.pcapng'
[IO.File]::WriteAllBytes($capture, [Text.Encoding]::UTF8.GetBytes('CI fixture only - never physical authority'))

$arsasCommit = (git -C .\ArIED61850Tester rev-parse HEAD).Trim().ToLowerInvariant()
$engineCommit = '4467124775d8d9d76f3db194f9fbfd97144767a8'
$manifest = Join-Path $results 'SMART-CAPTURE-BUILD.txt'
@(
'ARSAS smart discovery field-capture build',
"ARSAS commit: $arsasCommit",
"ARIEC61850 commit: $engineCommit",
'Engine PR: 134'
) | Set-Content $manifest -Encoding utf8

$proofPath = Join-Path $results 'P0-5D-provenance-source.json'
$proof = [ordered]@{
SchemaVersion = 1
Phase = 'P0-5d'
Verdict = 'PASS'
AcceptanceFailures = @()
ArsasCapture = [ordered]@{
Capture = 'fixture'
ClientIp = '192.0.2.10'
ServerIp = '192.0.2.20'
RequestTcpStreams = @('0')
ConfirmedRequests = 4
ConfirmedResponsesOrErrors = 4
ServiceCounts = [ordered]@{
GetNameList = 2
GetVariableAccessAttributes = 2
}
DuplicateSemanticRequests = 0
DuplicateGetNameListRequests = 0
DuplicateGvaRequests = 0
DuplicateDetails = @()
SecondGetNameListSweepDetected = $false
PeakOutstandingRequests = 3
NegotiatedMaxOutstandingCalling = 10
InvokeIdReuseWhileOutstanding = 0
OrphanResponses = 0
UnansweredRequestsAtCaptureEnd = 0
}
}
$proof | ConvertTo-Json -Depth 12 | Set-Content $proofPath -Encoding utf8

$lockPath = Join-Path $results 'P0-5E-provenance.lock.json'
& $writer `
-ProofJson $proofPath `
-CapturePath $capture `
-DeviceIdentity 'AA1E1F06R4' `
-ArsasCommit $arsasCommit `
-EngineCommit $engineCommit `
-TargetPath $target `
-BuildManifestPath $manifest `
-OutputPath $lockPath `
-AllowFixtureEvidence

$lock = Get-Content $lockPath -Raw | ConvertFrom-Json
if ($lock.SchemaVersion -ne 2 -or
$lock.GoldenSource.BuildManifestSha256 -notmatch '^[0-9a-f]{64}$' -or
$lock.GoldenSource.SemanticTargetSha256 -notmatch '^[0-9a-f]{64}$' -or
$lock.GoldenSource.RawCaptureReverified) {
throw 'Fixture lock did not carry expected P0-5e provenance metadata.'
}

$acceptPath = Join-Path $results 'P0-5E-provenance-pass.json'
& $verifier `
-LockPath $lockPath `
-ProofJson $proofPath `
-DeviceIdentity 'AA1E1F06R4' `
-CandidateArsasCommit $arsasCommit `
-CandidateEngineCommit $engineCommit `
-TargetPath $target `
-OutputJson $acceptPath
$accept = Get-Content $acceptPath -Raw | ConvertFrom-Json
if ($accept.Verdict -ne 'PASS') { throw 'Exact build/target fixture should pass the golden provenance lock.' }

$wrongArsas = '1111111111111111111111111111111111111111'
$mismatchPath = Join-Path $results 'P0-5E-provenance-arsas-mismatch.json'
& $verifier `
-LockPath $lockPath `
-ProofJson $proofPath `
-DeviceIdentity 'AA1E1F06R4' `
-CandidateArsasCommit $wrongArsas `
-CandidateEngineCommit $engineCommit `
-TargetPath $target `
-OutputJson $mismatchPath `
-NoFailExit
$mismatch = Get-Content $mismatchPath -Raw | ConvertFrom-Json
if ($mismatch.Verdict -ne 'FAIL' -or
-not (@($mismatch.AcceptanceFailures) -match 'Candidate ARSAS commit differs')) {
throw 'P0-5e did not reject ARSAS build identity drift.'
}

$alteredTarget = Join-Path $results 'altered-target.json'
$changed = Get-Content $target -Raw | ConvertFrom-Json
$changed.SemanticTarget.LogicalNodes = 120
$changed | ConvertTo-Json -Depth 12 | Set-Content $alteredTarget -Encoding utf8
$targetMismatchPath = Join-Path $results 'P0-5E-provenance-target-mismatch.json'
& $verifier `
-LockPath $lockPath `
-ProofJson $proofPath `
-DeviceIdentity 'AA1E1F06R4' `
-CandidateArsasCommit $arsasCommit `
-CandidateEngineCommit $engineCommit `
-TargetPath $alteredTarget `
-OutputJson $targetMismatchPath `
-NoFailExit
$targetMismatch = Get-Content $targetMismatchPath -Raw | ConvertFrom-Json
if ($targetMismatch.Verdict -ne 'FAIL' -or
-not (@($targetMismatch.AcceptanceFailures) -match 'Semantic target hash differs')) {
throw 'P0-5e did not reject semantic-target authority drift.'
}

- name: Upload P0-5e provenance evidence
if: always()
uses: actions/upload-artifact@v4
with:
name: ARSAS-p0-5e-golden-provenance-fixtures
path: ArIED61850Tester\TestResults\P0-5E-*.json
if-no-files-found: warn
retention-days: 14
Loading
Loading