This is the short implementation contract for choosing the correct ARStack online-model path.
Read this first when changing connection or model-discovery code. Detailed wire evidence lives in:
MMS_DISCOVERY_WIRE_PROFILE.md— build the model from the live MMS endpoint;SCL_ASSISTED_MMS_CONNECT_PROFILE.md— use a trusted CID/SCL model and perform only the online validation + initial snapshot work that is still needed.
Do we already have a trusted, selected CID/SCL model for this IED?
NO
|
v
LIVE DISCOVERY
1. associate
2. GetNameList(Domain,VMD)
3. enumerate NamedVariables with continuation
4. probe LN-root TypeSpecification
5. perform selected semantic Reads
6. discover DataSets when enabled
7. build canonical model
8. run shared InitialFcReadPlanner
9. keep association online
YES
|
v
SCL-ASSISTED CONNECT
1. parse/select IED + AccessPoint locally
2. resolve endpoint + association context from SCL where available
3. associate
4. GetNameList(Domain,VMD)
5. validate online domains against SCL
6. DO NOT repeat full NamedVariable discovery by default
7. DO NOT repeat GVAA/type discovery by default
8. DO NOT rebuild DataSets from MMS by default
9. run shared InitialFcReadPlanner
10. map nested MMS Data through the canonical SCL/model type tree
11. keep association online
Both paths converge here:
Canonical model
|
v
InitialFcReadPlanner
- enumerate only FC roots that exist for each LN
- deterministic ordering
- compatibility default: <= 10 variable references per Read
- batching limit is NOT the same setting as max outstanding services
|
v
InitialSnapshotRuntime
- one confirmed Read outstanding at a time by default
- wait response before next request
- COTP EOT reassembly before upper-layer decode
- map nested MMS Data against canonical model/type tree
- preserve per-reference failures as diagnostics
- leave association established after successful synchronization
It may use:
GetNameList
GetVariableAccessAttributes
GetNamedVariableListAttributes
Read
because the structural model is not already trusted locally.
The observed reference sequence for one controlled capture was:
1 x GetNameList(Domain,VMD)
120 x Read
0 x GetVariableAccessAttributes
0 x GetNamedVariableListAttributes
Those exact counts are capture-specific. The generalized rule is what matters: validate online identity, then read the live snapshot from the SCL-derived model instead of rediscovering the model.
Minimum discovery/connect paths are read-only. Do not silently add:
Write
control
GI
RCB reservation/enable
dynamic DataSet mutation
file-service mutation
Mutating or operational services require an explicit separate workflow.
SCL-assisted mode must not silently reinterpret a mismatched device.
missing expected domain -> mark unavailable + diagnostic
extra online domain -> report as extra evidence; do not auto-merge
missing FC root -> mark read unavailable/failed; preserve local model
broad mismatch -> stop or explicitly offer full live discovery fallback
- SCL is the structural source of truth in SCL-assisted mode.
- Live MMS evidence validates and populates runtime state; it does not silently rewrite SCL identity.
- Full live discovery is for the case where the model must be learned from the endpoint.
- Both paths reuse the same canonical initial FC-root read planner.
maxVariableReferencesPerReadandmaxOutstandingConfirmedRequestsare separate controls.- Compatibility-first initial reads are sequential.
- COTP segmentation/reassembly is mandatory before MMS decode.
- Association addressing should come from the selected SCL engineering context when available.
- Keep the association open after successful initial synchronization.
- Capture-specific counts and identifiers are regression evidence, not universal IEC 61850 constants.