Skip to content

ProtectionAI v1.10.0

Latest

Choose a tag to compare

@Cwgtshome Cwgtshome released this 03 Aug 21:05

102 registered [WorkspaceView] modules (adds the Ed.2 Test Mode & Sim Flag module), 30 AI
copilot tools, 4 AI providers, 7 UI languages, 3,195 tests (3,079 at v1.9.0 — this release
adds 116). Ribbon: 17 tabs, 85 groups, 146 controls.

The release theme is instrument reach without dishonesty: more shapes, more instruments, more
standard surfaces — every new capability stating exactly what it is and refusing what it cannot
attest.

Added

  • Seven selectable test-set shapes for the simulator (TestSetProfiles), from a 3V/3I field
    set to a 12V/12I laboratory set, with a 6×64 A high-current variant and a 6V/9I three-winding
    shape between. Each profile states what the shape cannot do — no polarizing voltage on the
    three-phase set, one current triplet cannot drive both windings of a differential — because the
    point of rehearsing on the set you will carry to site is meeting its limits at the desk rather
    than at the substation. The shape is enforced, not decorative: an injection over the profile's
    range refuses. A Shape selector in Home → Hardware (visible only for simulator-type drivers)
    persists the choice, and changing shape re-arms the isolation gate exactly as a hardware swap
    would — a different shape is a different instrument.

  • Five rehearsal instrument classes in the test-set selector: CMC-class, F6-class, SMRT-class,
    DRTS-class and Mentor-class — the full qualified simulator wearing a per-vendor-class identity,
    so a demonstration or dry run can be staged around any vendor family an operator owns, with no
    hardware on the desk. The honesty is structural and test-pinned: every identity names itself
    simulated, the vendor's name appears only inside wording that denies being the product ("not a
    Doble product; no vendor protocol"), the Vendor field is always GridAPM, the isolation gate keys
    on the runtime type so a rehearsal set always receives the simulator acknowledgement, and the
    real vendor stubs stay stubs, out of the selector.

  • Full SCPI instrumentation on the generic SCPI driver, every addition template-gated —
    a capability exists exactly when its command templates are configured, and unconfigured
    operations keep refusing with the missing capability named. Measurement inputs return the
    instrument's magnitude only (angle, frequency and derived powers are NaN: a sequential query
    is not a coherent acquisition window and must not dress up as one). Polled binary sensing raises
    real contact events while never advertising device timestamps — the event states host-poll
    provenance, and pulse-ramp/pickup-dropout still refuse, now citing that exact gap. Trigger
    arming is manual-release only. An error-queue drain (SYST:ERR?) runs after every command
    batch, default ON, aborting with the SCPI error named verbatim — silent command rejection is how
    a wrong injection happens. Aux DC and operator-declared per-channel frequency complete the set.

  • The OMICRON CM Engine adapter extended strictly against a graded public-attestation table
    (docs/research/CMENGINE-COMMANDS.md): trip timing from the device's own event buffer —
    DeviceRelativeTimestampedBinaryInputs is now genuinely advertised, with its claim stated
    exactly (device-relative ordering and intervals: yes; disciplined absolute UTC: no) — plus
    binary outputs, aux DC, a time-driven sequencer (deliberately not claiming SegmentRamp:
    held states are not interpolated segments), and enumerate-then-choose amplifier
    routing/paralleling with no hardcoded configuration numbers. Commands whose public attestation
    is incomplete — binary-triggered sequencer advance above all — are explicitly not built; a wrong
    guess there mis-times a protection test. HIL qualification remains pending and every new surface
    says so.

  • The Ed.2 Test Mode & Sim Flag module (IEC 61850 tab) — the vendor-neutral relay-side test
    surface. Publishes simulation-flagged GOOSE with both wire forms of the marker set together
    (a frame carrying only one is reported INCONSISTENT, never resolved by preference), monitors
    received GOOSE for the simulation marker and the 13-bit quality test bit (absent quality reports
    "none", never "clear"), and stages a duplicated-control-block switchover check that records what
    was published and captured. It does not command the IED's mode — that is an MMS write this
    application does not yet have — and it says so on its intro card; on the built-in simulator the
    switchover verdict is NOT VERIFIABLE with the reason spelled out. Transport provenance is on an
    always-visible line.

  • docs/research/ — the evidence base for every driver-scope decision this release makes:
    VENDOR-PROTOCOLS.md (Doble, Megger, ISA/Altanova and EuroSMC verdicts: no public wire
    protocol exists for any of them; per-vendor routes to the real interface documentation, with
    document part numbers where they exist), CMENGINE-COMMANDS.md (the graded CM Engine
    attestation table), and STANDARD-SURFACES.md (no universal test-set control standard exists;
    the vendor-neutral strategy runs through relay-side Ed.2 testing features, interchange files and
    SCPI instruments, with five prioritized gaps — an IEC 61850-8-1 MMS/ACSI client first).

Fixes

  • A pulse-ramp test asserted a premise the machine can disprove. It went red under load in two
    independent runs; the product was correct — a process-wide stall holding a 60 ms pulse energized
    past a competing stage's 1.5 s operate time makes that stage operate, exactly as a real relay
    behaves against a real test set whose controlling PC stalled. The test now measures each pulse's
    actual energized span from its own run and asserts the quiet-competing-stage claim only when the
    run stayed under the operate time; the pickup value and rest behaviour remain unconditional.
    This is the second test-side defect in the repo's history (after the breaker-failure separation
    floor), against many product defects — the doctrine of assuming the product wrong first stands,
    with the distinguishing question recorded in docs/TESTING.md.

  • The OMICRON adapter's phasor and event-buffer commands moved to their attested forms
    (out:v(1:n):… rather than the unattested out:ana:v(…) prefix; inp:buf:sam(bin,1) rather
    than sam(bin,on)) — the previous forms appear nowhere in the public record.

Testing

116 tests cover the new behaviour: shape catalog and enforcement, the rehearsal honesty contract,
SCPI instrumentation (deterministic via an injectable poll clock), the OMICRON extension
(attested command strings asserted literally, event-buffer parsing to the microsecond), and the
Ed.2 protocol and switchover mathematics. The localization ratchet moved 1,906 → 1,934, fully
attributed to the new module's mandated house-idiom literals.


Installer

ProtectionAI-Setup.msi is a Windows Installer (MSI) package. It installs ProtectionAI in Program Files, creates a Start Menu shortcut, registers Apps & Features uninstall support, and supports in-place major upgrades. ProtectionAI.App.exe is the same application as a self-contained single-file executable, for people who cannot run an installer.

This release is not Authenticode code signed. Windows SmartScreen will warn you when you run it, and that warning is expected. The checks below prove integrity (the bytes are the bytes we built) and source binding (the signed manifest came from this repository, tag and commit). They are not a Windows trust decision and do not stop SmartScreen warning.

Artifact digests (SHA-256)

7070803dc4f391bafb4ee409f878a2efc5914ae91509f07b6b6740452ed91bd8  protectionai-1.10.0-cyclonedx.json
e91dc38d48c4ead4d3735945db9ed3674625f954f47278f17226046193abce60  protectionai-1.10.0-cyclonedx.json.sha256
de239f78a5145bfb17384cc16a3480966856a4c168453720acec567d6573124e  ProtectionAI-Setup.msi
9cbe3c71301bcb27ef973440ae1b061154d2034e247d32ac77f10924a4b0e6ec  ProtectionAI.App.exe

Published alongside the artifacts as SHA256SUMS, with a detached Sigstore signature (SHA256SUMS.sig), the ephemeral signing certificate (SHA256SUMS.pem) and a self-contained bundle (SHA256SUMS.cosign.bundle). The software bill of materials (protectionai-1.10.0-cyclonedx.json) and its checksum sidecar (protectionai-1.10.0-cyclonedx.json.sha256) are both attached and covered by the signed manifest.

1. Verify integrity — the files are what we built

PowerShell:

foreach ($line in Get-Content .\SHA256SUMS) {
  $expected, $name = $line -split '\s+', 2
  $actual = (Get-FileHash $name.Trim() -Algorithm SHA256).Hash.ToLower()
  "{0}  {1}" -f $(if ($actual -eq $expected) { "OK  " } else { "FAILED" }), $name.Trim()
}

POSIX shell:

sha256sum -c SHA256SUMS

2. Verify authenticity — the digest list itself is genuine

Step 1 only proves the files match the list. This proves the list was produced by this release workflow. Install cosign and run:

cosign verify-blob SHA256SUMS \
  --signature SHA256SUMS.sig \
  --certificate SHA256SUMS.pem \
  --certificate-identity https://github.com/Cwgtshome/ProtectionAI/.github/workflows/release.yml@refs/tags/v1.10.0 \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com \
  --certificate-github-workflow-repository Cwgtshome/ProtectionAI \
  --certificate-github-workflow-ref refs/tags/v1.10.0 \
  --certificate-github-workflow-sha d2f6c61b31de5e8dc9681fa03160dbb245aa0e82

Or with the bundle, which needs no separate certificate:

cosign verify-blob SHA256SUMS \
  --bundle SHA256SUMS.cosign.bundle \
  --certificate-identity https://github.com/Cwgtshome/ProtectionAI/.github/workflows/release.yml@refs/tags/v1.10.0 \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com \
  --certificate-github-workflow-repository Cwgtshome/ProtectionAI \
  --certificate-github-workflow-ref refs/tags/v1.10.0 \
  --certificate-github-workflow-sha d2f6c61b31de5e8dc9681fa03160dbb245aa0e82

Pin all five certificate constraints exactly as shown: identity, issuer, repository, ref and SHA. Together they reject a signature from another workflow, repository, tag or commit. There is no long-lived private key: the certificate above was issued to this workflow's OIDC identity, is valid for minutes, and the signing event is recorded in the public Rekor transparency log.

3. Build provenance — not available for this release

No GitHub-hosted SLSA build-provenance attestation was recorded, so gh attestation verify will not find one. GitHub's attestation store is not offered to user-owned private repositories on this plan, and the source repository is private.

What still holds: the signed SHA256SUMS manifest binds every shipped content file by digest, and the Sigstore certificate in step 2 binds that manifest to this repository, tag ref and exact source SHA against a public transparency log. What is missing is GitHub's separate SLSA predicate and attestation-store record; no SLSA level is claimed.

Built from Cwgtshome/ProtectionAI@d2f6c61. See docs/RELEASE-INTEGRITY.md for what each file is and why it exists.