# 协议能力验收矩阵（L1-L4）

本文替代原“已完成协议与特性”清单，不再使用二元的“完成/未完成”口径，而是按验收阶段记录每项能力当前到达的层级。尚未达到 L1 的事项继续保留在 `protocol-feature-pending.md`。

## 阶段定义

- `L1 模块设计实现`：已完成模块拆分、数据结构、编解码、离线 fixture/单元测试或最小 CLI/Facade 接口。
- `L2 实机验证`：已在真实 PROFINET 网卡和真实设备上验证成功路径、异常路径、超时和状态收敛。
- `L3 仿真验证`：已在仿真器、协议回放或可重复实验环境中稳定验证。
- `L4 形式化验证`：关键不变量、状态机或边界条件具备形式化证明、模型检查或可机检契约。

## 当前结论

- 当前仓库已经形成较完整的 `L1` 能力面，覆盖 DCP、GSD 摘要、PD/MRP 离线解析、统一报告，以及 `alarm/rpc/ar/io/record/profidrive/snmp/lldp/dhcp` 九个新模块。
- 当前仓库尚未形成系统化的 `L2/L3/L4` 验收闭环。DCP live 通道“代码已接通”不等于“已完成实机验收”。
- 因此原文件名 `protocol-feature-completed.md` 容易误导为“全部完成”。改名为 `protocol-feature-acceptance.md` 更准确，也更便于后续持续回填。

## 设备发现与基础能力

| 能力 | L1 模块设计实现 | L2 实机验证 | L3 仿真验证 | L4 形式化验证 | 主要证据 |
| --- | --- | --- | --- | --- | --- |
| DCP Identify/Get/Set/Response 编解码与 CLI | 已完成 | 部分通过 (2026-06-06 Identify/Get/Set-IP @VTS-EX-CA0400；2026-06-08 Identify @VTS-EX-CA0600；2026-06-09 Set-IP/scan 回读 @VTS-EX-CA0600) | 已补 (fixture_dcp_identify, fixture_dcp_set_name_roundtrip, fixture_dcp_set_ip_roundtrip) | 已补 (dcp_block_length, dcp_service_id, dcp_block_error) | `dcp/*.mbt`, `simulation/replay.mbt`, `simulation/fixtures_batch3.mbt`, `verification/contracts_extended.mbt`, `verification/contracts_batch3.mbt`, `docs/live-regression-checklist.md` |
| DCP live scan/get/set 通道 | 已接通 | 部分通过 (2026-06-06 实机 scan + set-ip 192.168.3.10 ping 通；2026-06-09 Realtek scan + set-ip 192.168.1.20 + scan 回读；中文接口名待修) | 已补 (fixture_dcp_set_name_roundtrip/fixture_dcp_set_ip_roundtrip) | 已补 (dcp_block_error) | `scan_native.mbt`, `ffi/rawnet/*`, `simulation/fixtures_batch3.mbt`, `verification/contracts_batch3.mbt`, `docs/live-regression-checklist.md` |
| GSD 最小摘要解析 | 已完成 | 范围外 | 已补 (fixture_dcp_gsd_consistency) | 已补 (gsd_vendor_id, gsd_device_id, dns_compatible_name) | `gsd/summary.mbt`, `simulation/fixtures_batch3.mbt`, `verification/contracts_batch3.mbt` |
| GSD 深层类型解析（DataType/IOData/Module/DAP/Parameter/Certification） | 已完成 | 范围外 | 已补 (fixture_dcp_gsd_consistency) | 已补 (gsd_vendor_id, gsd_device_id, dns_compatible_name) | `gsd/detail.mbt`, `verification/contracts_batch3.mbt` |
| DCP 响应与 GSD 一致性校验 | 已完成 | 部分通过 (2026-06-08 CA0600 live scan 与 GSD `VendorID/DeviceID` 一致，严格 overall 因 vendor_name/station_name 差异未通过) | 已补 (fixture_dcp_gsd_consistency) | 已补 (dns_compatible_name) | `gsd_native.mbt`, `simulation/fixtures_batch3.mbt`, `verification/contracts_batch3.mbt`, `docs/live-regression-checklist.md` |
| 标准行为基线摘要 | 已完成 | 范围外 | 范围外 | 范围外 | `profinet_master.mbt`, `PN-Profiles-2742-d25-Nov25_review` |

## 离线记录、诊断与可观测性

| 能力 | L1 模块设计实现 | L2 实机验证 | L3 仿真验证 | L4 形式化验证 | 主要证据 |
| --- | --- | --- | --- | --- | --- |
| PDPortDataReal / PDPortDataCheck 摘要 | 已完成 | 范围外 | 已补 (fixture_pd_port_data_read) | 已补 (mau_type, iod_index_range) | `profinet_master.mbt`, `simulation/fixtures_batch2.mbt`, `verification/contracts_batch2.mbt`, `testdata/pd/*` |
| PDPortStatistic / PDInterfaceDataReal / PDevData / PDRealData 摘要 | 已完成 | 范围外 | 已补 (fixture_pd_port_statistic_read) | 已补 (mau_type, iod_index_range, iod_slot/subslot) | `profinet_master.mbt`, `simulation/fixtures_batch3.mbt`, `verification/contracts_batch3.mbt` |
| PDPortMRPDataReal / PDPortMRPLCDataReal / PDInterfaceMRPDataReal 摘要 | 已完成 | 范围外 | 已补 (fixture_pd_port_mrp_read) | 已补 (mrp_role, mrp_ring_state) | `profinet_master.mbt`, `simulation/fixtures_batch3.mbt`, `verification/contracts_batch3.mbt` |
| Link state / autonegotiation 离线契约 | 已完成 | 范围外 | 已补 (fixture_link_state_autoneg) | 已补 (link_state, autoneg_settle_time) | `profinet_master.mbt`, `simulation/fixtures_batch4.mbt`, `verification/contracts_batch4.mbt` |
| LogBookData 离线摘要 | 已完成 | 范围外 | 已补 (fixture_logbook_data_read) | 已补 (logbook_entry_count, logbook_entry_size, pnio_error_decode) | `profinet_master.mbt`, `simulation/fixtures_batch4.mbt`, `verification/contracts_batch4.mbt` |
| baseline-report / probeability / extensions 报告 | 已完成 | 范围外 | 范围外 | 范围外 | `profinet_master.mbt`, `cmd/main/main.mbt` |

## 新增协议模块

| 模块 / 能力 | L1 模块设计实现 | L2 实机验证 | L3 仿真验证 | L4 形式化验证 | 主要证据 |
| --- | --- | --- | --- | --- | --- |
| Alarm / AlarmCR | 已完成 | 阻塞于真实 AlarmNotification（2026-06-12 CA0400 `0xCF81FD02` Instance closed 已定位并修复为 ApplicationReady.rsp 端序问题；修复后 alarm 4ms 有限回归 `data_exchange`，但仍未现场触发可 ACK 的 AlarmNotification DATA） | 已补 (fixture_alarm_pull) | 已补 (pnio_status_length, alarm_type) | `alarm/alarm.mbt`, `simulation/fixtures_extended.mbt`, `verification/contracts_extended.mbt`, `verification/contracts_batch2.mbt`, `docs/live-regression-checklist.md` |
| RPC / DCE | 已完成 | 部分通过 (2026-06-06 CA0400 Connect/Release；2026-06-09 CA0600 Connect/Write/PrmEnd/AppReady，兼容 byte-swapped Control opnum `0x0400`；2026-06-12 CA0400 AppReady.rsp 已按设备 big-endian `drep=000000` 请求镜像 header/NDR 端序，pcap 无 CLRPC Reject) | 已补 (fixture_rpc_connect) | 已补 (rpc_header_length, rpc_packet_type) | `rpc/rpc.mbt`, `simulation/fixtures_batch2.mbt`, `verification/contracts_extended.mbt`, `verification/contracts_batch2.mbt`, `docs/live-regression-checklist.md` |
| AR / IOCR 建链数据结构 | 已完成 | 部分通过 (2026-06-06 CA0400 Connect.rsp OK；2026-06-09 CA0600 IOCR Input `0x8000` / Output `0x8001` 后进入 data_exchange) | 已补 (fixture_connect_ar) | 已补 (ar_state_transition) | `ar/ar.mbt`, `simulation/replay.mbt`, `verification/contracts.mbt`, `docs/live-regression-checklist.md` |
| IO 数据交换模型 | 已完成 (`rpc-b4-io-write` 支持固定 TEL1 输出字持续写入；`rpc-b4-update-io` 支持运行中切换模块输出数据；`rpc-b4-read-io` 支持持续采样当前输入 IO；`rpc-b4*` 省略 `finite-cycle-count` 时 continuous 运行；RT 时钟 Phase 1 已输出名义周期与发送间隔观测字段；Phase 2 已提供 `--clock monotonic-ms`、IOCR 同步周期 `--period-us` 与本地发送周期 `--rt-period-us`；Phase 3 已提供 `--clock highres` native 微秒时钟后端；Windows IoT 专项路径已提供 `--win-rt` 优先级与 CPU affinity 开关) | 部分通过 (2026-06-06 CA0400 RT 数据交换；2026-06-09 CA0600 VLAN-tagged RT 数据交换，256 sent / 124 rx，DataStatus `0x0035`，输出字切换已实机验证；2026-06-10 CA0600 AppReady 后持续读取当前 IO，256 sent / 118 rx / 7 samples；2026-06-11 CA0400 `rpc-b4-io-write --clock highres` 写入 `0,800,0,0,0` 进入 `data_exchange`，512 output write sent，默认构建 pcap output write 平均间隔 2864.8us、release 构建 2769.1us、Windows IoT `--win-rt --win-rt-mask 0x1` 构建 2857.9us、input 平均约 2000us；2026-06-12 CA0400 `--period-us 4000` 同步 IOCR 为 32/4 并进入 `data_exchange`，pcap output write 平均 4000.0us、input 平均 4003.6us；2ms highres/WinRT 输出仍未达到名义周期) | 已补 (fixture_io_cyclic) | 已补 (frame_id_rt_range, ether_type_profinet) | `io/io.mbt`, `cmd/main/rpc_connect.mbt`, `cmd/main/rpc_connect_wbtest.mbt`, `simulation/fixtures_extended.mbt`, `verification/contracts_extended.mbt`, `docs/live-regression-checklist.md`, `docs/rt-clock-plan.md`, `docs/pcap/rpc_b4_io_write_highres_20260611.stats.txt`, `docs/pcap/rpc_b4_io_write_highres_release_20260611.stats.txt`, `docs/pcap/rpc_b4_io_write_highres_winrt_20260611.stats.txt`, `docs/pcap/rpc_b4_io_write_highres_4ms_20260612.stats.txt` |
| Record Read / Write 在线协议壳 | 已完成 (`modify-iam1` 便捷写入入口已补；CA0600 startup Write index `1234` 已通过 b4 路径验证) | 部分通过 (2026-06-07 CA0400 I&M0 Read / I&M1 Write；2026-06-09 CA0600 startup Write index `1234` OK；CA0600 I&M1 专项 live 写入未执行) | 已补 (fixture_record_read_im0) | 已补 (dcp_block_length reuse) | `record/record.mbt`, `cmd/main/main.mbt`, `cmd/main/rpc_connect.mbt`, `simulation/fixtures_extended.mbt`, `docs/live-regression-checklist.md` |
| PROFIdrive 参数访问 | 已完成 | 待实机验收 | 已补 (fixture_profidrive_read_pnu) | 已补 (drive_state_transition, profidrive_stw1/zsw1) | `profidrive/profidrive.mbt`, `simulation/fixtures_extended.mbt`, `verification/contracts.mbt`, `verification/contracts_batch2.mbt` |
| PROFIdrive 控制器应用层（状态机/电报/扩展PNU） | 已完成 | 部分通过 (2026-06-09 CA0600 TEL1 输出字可在 RT 数据交换中由 `0,0,0,0,0` 切换到 `0,0,0x03E8,0,0`；驱动状态响应仍需专项验收) | 已补 (fixture_profidrive_pzd_telegram1) | 已补 (pro_state_transition, profidrive_stw1/zsw1) | `profidrive/controller.mbt`, `simulation/fixtures_batch2.mbt`, `verification/contracts.mbt`, `verification/contracts_batch2.mbt`, `docs/live-regression-checklist.md` |
| SNMPv1 编码与消息构建 | 已完成 | 待实机验收 | 已补 (fixture_snmp_get_sysdescr) | 已补 (snmp_community_length) | `snmp/snmp.mbt`, `simulation/fixtures_extended.mbt`, `verification/contracts_extended.mbt` |
| LLDP TLV 与邻居提取 | 已完成 | 待实机验收 | 已补 (fixture_lldp_capture) | 已补 (lldp_mandatory_tlvs) | `lldp/lldp.mbt`, `simulation/fixtures_extended.mbt`, `verification/contracts_extended.mbt` |
| DHCP 消息编解码与 Discover | 已完成 | 待实机验收 | 已补 (fixture_dhcp_discover) | 已补 (dhcp_magic_cookie) | `dhcp/dhcp.mbt`, `simulation/fixtures_extended.mbt`, `verification/contracts_extended.mbt` |
| Security Profiles（PRO帧/SecurityData/AEAD算法/SecurityMode） | 已完成 | 待实机验收 | 已补 (fixture_security_handshake) | 已补 (security_nonce/tag/session_id) | `security/security.mbt`, `simulation/fixtures_batch2.mbt`, `verification/contracts_batch2.mbt` |
| Root facade 集成 | 已完成 | 待实机验收 | 已补 (fixture_facade_onboard) | 已补 (facade_onboard_steps) | `profinet_master.mbt`, `simulation/fixtures_batch4.mbt`, `verification/contracts_batch4.mbt` |

## RT/AR 后续验收入口（L1/L2 推进中）

本节只为 `docs/rt-pitfalls-and-lessons.md` 的后续细节建立验收入口，不把这些项宣称为已完成 L2 能力。达到 L1 的条目可在当前状态中记录离线证据；缺实机、抓包或物理触发条件时仍保持 Blocked。

| ID | 能力 / 缺口 | L1 目标 | L2 目标 | L3/L4 目标 | 当前状态 |
| --- | --- | --- | --- | --- | --- |
| RT-001 | 控制器侧 consumer DHT 看门狗 | 已补：本端 AppReady 后按首个有效 input 启动 DHT 监视，超时输出 `rt_local_dht_expired`、超时/elapsed us、最后 input 周期/时间，并触发 Release.req best-effort；`cmd/main` 白盒覆盖 timeout 换算和边界过期 | 实机制造 input 中断或断链，证明本端按 DHT 主动退出 | 后续可补 replay/pcap fixture 覆盖 input 停止边界 | Blocked：L1 代码与离线验证已完成，缺 L2 实机 input 中断证据 |
| RT-002 | DHF mandatory 范围与 CLI 覆盖 | 已补：自动 factor 优先 ≤`0x00FF`，支持 `--data-hold-factor` / `--data-hold-ms`，拒绝低于 `0x0003`、超出 Data-RTC 上限和互斥覆盖；日志输出 DHF 来源/factor/有效 DHT | 极小周期与显式 factor 在设备上有通过/拒绝证据 | 白盒覆盖 Data-RTC mandatory cap、explicit optional factor、ms 换算和不可关闭 | Blocked：L1 代码与离线验证已完成，缺 L2 实机 optional factor 证据 |
| RT-003 | DataStatus 位级解析 | 已补：`decode_data_status` 输出 State/Redundancy/DataValid/ProviderState/StationProblemIndicator/Ignore；`rpc-b4*` 首帧、最终摘要和 input sample 均带位级诊断 | `0x35`、`0x15` 等实机状态可解释并回填 | 白盒覆盖典型位组合，`decode_io_cyclic_frame_hex` 支持离线解码 | Blocked：L1 代码与离线验证已完成，缺 L2 新实机日志 |
| RT-004 | ALPMI/ALPMR 报警状态机 | 已补：ALPMR/responder 状态跟踪 send_seq、重复 DATA、out-of-sequence、pending ACK、ACK sent/fail，并在 `rpc-b4-alarm` 输出 `rt_alarm_state_*` | 真实 Pull/Plug/AlarmNotification DATA + ACK 抓包 | 白盒覆盖首个通知、重复通知、下一序号、乱序和 ACK 失败计数 | Blocked：L1 代码与离线验证已完成，缺 L2 真实告警触发 |
| RT-005 | RT output VLAN priority | 已补：默认 output VLAN TCI `0xC000`（PCP 6 / DEI 0 / VID 0）可观测；`--rt-output-vlan-pcp` / `--rt-output-vlan-tci` 可互斥覆盖，Connect.req output IOCRTagHeader 与实际 output Ethernet tag 同步；`rpc-b4*` / `pcap-baseline` 输出 VLAN 诊断字段 | pcap 证明本端 output VLAN 标记 | 白盒覆盖默认 PCP 6、显式 PCP 5、原始 TCI、互斥参数和 Ethernet tag 字节 | Blocked：L1 代码与离线验证已完成，缺 L2 本端 output pcap |
| RT-006 | IOCR Phase/Sequence 契约 | 已补：`ar` 暴露 `IOCRBlockReq::phase_valid`、`sequence_is_random` 与 sequence label；CA400 自定义周期 `reduction_ratio=1` 仍保持 Phase=1 / Sequence=0 | 自定义周期不违反设备接收约束，实机 Connect.rsp 和后续 data_exchange 通过 | 已补：`check_iocr_phase_valid` 覆盖 Phase=0 与 Phase>ReductionRatio 失败；`check_iocr_sequence_random` 覆盖当前随机序策略 | Blocked：L4 契约与离线验证已完成，缺 L2 自定义周期实机证据 |
| RT-007 | UDP-RTC DHF 范围差异 | 换算函数按 Data-RTC / UDP-RTC 分支设计 | 未来 UDP-RTC 实机验证 | 契约覆盖 0x1E00 vs 0xF000 上限 | Deferred |
| RT-008 | monotonic-ms 长跑位宽口径 | 已补：RT 摘要和 pcap CLI 意图摘要输出 counter bits、wrap window、wrap risk、long-run role/recommendation；`monotonic-ms` 标为 comparison-only，长跑推荐 `highres` | 范围外；仅在需要时做 24.8 天级长跑风险验证 | 白盒覆盖 highres 推荐口径与 monotonic-ms `32-bit-ms-wrap-around-24.8d` 风险字段 | Done |

## 当前口径说明

- 进入本文件的最低门槛是达到 `L1`，也就是“模块设计实现已经落地并可离线验证”。
- 若要对外宣称“协议能力已验收完成”，建议至少达到 `L2`；若要形成稳定回归基线，建议达到 `L3`。
- `L4` 初步形成契约层：`verification/contracts.mbt` 和 `verification/contracts_extended.mbt` 已覆盖 AR/Drive/PRO 状态迁移、帧长/帧类型、DCP 分块/服务码、LLDP 强制 TLV、DHCP magic cookie、SNMP community 长度、PROFIsafe CRC 长度等不变量。更强的 MoonBit 形式化证明（依赖 Why3/proof 层）仍待后续引入。
---

## 协议细节参考

以下按模块整理各能力对应的 PROFINET 规范出处和关键协议细节，便于后续 L2/L3/L4 验收时查阅。

### GSD 摘要解析

**规范出处** — GSDML Specification V2.50 (Order No. 2.352)

当前 `gsd/summary.mbt` 仅提取 `DeviceIdentity`（VendorID/DeviceID）、`Family`（MainFamily/ProductFamily）、`ModuleInfo`（OrderNumber）和 `DeviceAccessPointItem`（ID/DNS_CompatibleName），对应 GSDML Spec 的：

| GSDML 章节 | 内容 | 当前实现 |
| --- | --- | --- |
| §8.8 DeviceIdentity | VendorID, DeviceID, InfoText, OrderNumber | ✅ VendorID/DeviceID |
| §8.9 Family | MainFamily, ProductFamily | ✅ |
| §10.2 DeviceAccessPointItem | ID, DNS_CompatibleName, PhysicalSlots, MinDeviceInterval, ModuleIdentNumber, CertificationInfo | ✅ ID/DNS_CompatibleName |
| §10.3 CertificationInfo | ConformanceClass, ApplicationClass, NetloadClass | ✅ `GsdCertificationInfo` in `gsd/detail.mbt` |
| §11.2 ModuleItem | ModuleIdentNumber, PhysicalSubslots, ModuleInfo | ✅ `GsdModuleInfo` in `gsd/detail.mbt` |
| §12.2 SubmoduleItem | SubmoduleIdentNumber, IOData (Input/Output/DataItem), RecordDataList | ✅ `GsdSubmoduleInfo` in `gsd/detail.mbt` |
| §12.2.5 IOData | Input/Output 数据长度、DataItem (TextId, DataType, UseAsBits) | ✅ `GsdIOData`, `GsdDataItem` in `gsd/detail.mbt` |
| §13 RecordData | ParameterRecordDataItem (Index, Length, TransferSequence), Const/Ref | ✅ `GsdParameter`, `GsdParameterMember` in `gsd/detail.mbt` |
| §7 数据类型 | Unsigned8..64, Integer8..64, Float32/64, OctetString, VisibleString, TimeStamp 等 | ✅ `GsdDataType` (18 variants) in `gsd/detail.mbt` |
| §15 ChannelDiag | ChannelDiagItem (ChannelNumber, ErrorType), ExtChannelDiagItem | ✅ `GsdChannelDiagItem`, `GsdExtChannelDiagItem` in `gsd/detail.mbt` |
| §16 ChannelProcessAlarm | ChannelProcessAlarmItem, ExtChannelProcessAlarmItem | ✅ `GsdChannelProcessAlarmItem`, `GsdExtChannelProcessAlarmItem` in `gsd/detail.mbt` |
| §17 UnitDiagType | UnitDiagTypeItem (UserStructureIdentifier) | ✅ `GsdUnitDiagTypeItem`, `GsdUnitDiagRef` in `gsd/detail.mbt` |

已完成：§7, §10.3, §11.2, §12.2, §12.2.5, §13, §15, §16, §17 均已在 `gsd/detail.mbt` 中通过 `GsdDeviceDetail` 建模。

### DCP 编解码

**规范出处** — PN-AL-Services (Order No. 2.712) §4.3, PN-AL-Protocol (Order No. 2.722) §4.3

当前实现覆盖：
- DCP Identify Multicast 请求/响应（NameOfStation、IP 参数、设备属性）
- DCP Get 请求/响应
- DCP Set 请求/响应（NameOfStation、IP 参数写入）
- 选项/子选项编码：IP (0x01), Device Properties (0x02), DHCP (0x03), Control (0x05), All Selector (0xFF)
- 响应 Block 拆分、错误码解析

### Alarm / AlarmCR

**规范出处** — PN-AL-Protocol §6.2 (AlarmCR), PN-AL-Services §5.2.6 (Alarm notification)

| 协议要素 | 说明 | 当前实现 |
| --- | --- | --- |
| AlarmCRBlockReq | 建链时协商告警通道：alarm_cr_type, lt (0x8892), rta_timeout_factor, rta_retries, max_alarm_data_length | ✅ 编解码 |
| AlarmCRBlockRes | 控制器返回 alarm_cr_status, local_alarm_reference | ✅ 编解码 |
| AlarmNotification-PDU | AlarmType (0x01-0x1F), API, SlotNumber, SubslotNumber, ModuleIdentNumber, SubmoduleIdentNumber, AlarmSpecifier, UserStructureIdentifier, AlarmPayload | ✅ 编解码 |
| RTA DATA/ACK/ERR | PDUType.Version / Type 拆分；DATA=0x11、ACK=0x13、ERR=0x14；ERR-RTA-PDU 解析 PNIOStatus | ✅ 编解码；实机已记录 `0xCF81FD02` = RTA abort / Instance closed，并定位为旧 AppReady.rsp 端序不匹配后的关闭结果 |
| AlarmAck-PDU | 确认告警消息：AlarmType, API, Slot, Subslot, AlarmSpecifier；RTA 传输 ACK 使用 `PDUType=0x13`、`VarPartLen=0` | ✅ 离线编解码；真实 AlarmNotification DATA 未触发，L2 ACK 路径仍待实机 |
| Alarm 类型枚举 | Diagnostic (0x01), Process (0x02), Pull (0x03), Plug (0x04), Status (0x05), Update (0x06), Redundancy (0x07), Controlled/Released by Supervisor (0x08-0x09), PlugWrong (0x0A), ReturnOfSubmodule (0x0B), DiagnosticDisappears (0x0C), MCRMismatch (0x0D), PortDataChanged (0x0E), SyncDataChanged (0x0F), IsochrOneModeProblem (0x10), NetworkComponentProblem (0x11), TimeDataChanged (0x12), UploadAndStorage (0x1E), PullModule (0x1F) | ✅ 完整常量集 |

### RPC / DCE-RPC

**规范出处** — PN-AL-Protocol §5 (DCE/RPC), IEC 61158-6-10

| 协议要素 | 说明 | 当前实现 |
| --- | --- | --- |
| RPC Header | version=4, packet_type (Request=0/Response=2/FaultPDU=3), flags (idempotent, broadcast, no_fack), serial/frag, server_boot_time | ✅ 编解码 |
| Activities | activity_uuid, object_uuid (PNIO device / controller object), interface_uuid | ✅ |
| PNIO Interface UUID | `DEA00001-6C97-11D1-8271-00A02442DF7D` | ✅ |
| Opnum | Connect=0, Release=1, Read=2, Write=3, Control=4, ReadImplicit=5 | ✅ 常量 |
| Fragment / Reassembly | fragment_num, alloc_hint, serial_high/low | ✅ 编解码 |

### AR / IOCR 建链

**规范出处** — PN-AL-Services §5.2.4 (AR), PN-AL-Protocol §6.1 (ARBlockReq/ARBlockRes)

| 协议要素 | 说明 | 当前实现 |
| --- | --- | --- |
| ARBlockReq | ar_type (IOCARSingle=0x0001), ar_uuid, session_key, cm_initiator_mac, cm_initiator_object_uuid, ar_properties, timeout_factor, initiator_udp_rt_port, station_name_length, cm_initiator_station_name | ✅ 编解码 |
| IOCRBlockReq | iocr_type (Input=1/Output=2), iocr_reference, lt, iocr_properties, data_length, frame_id, send_clock_factor, reduction_ratio, phase, sequence, data_hold_factor, api_count (API, slot_number, subslot_number, frame_offset) | ✅ 编解码 |
| ExpectedSubmoduleBlockReq | number_of_apis, api, slot_number, module_ident_number, subslot_number, submodule_ident_number, submodule_properties, data_description (type, length, length_iops, length_iocs) | ✅ 编解码 |
| ARBlockRes | session_key, cm_responder_mac, responder_udp_rt_port | ✅ 编解码 |
| IOCRBlockRes | iocr_type, iocr_reference, frame_id | ✅ 编解码 |

### IO 数据交换

**规范出处** — PN-AL-Protocol §7 (IO Data), IEC 61158-6-10 §4.11

| 协议要素 | 说明 | 当前实现 |
| --- | --- | --- |
| RT Frame | frame_id (0x8000-0xBFFF cyclic), cycle_counter (16-bit wrap), data_status, transfer_status | ✅ 编解码 |
| IOPS / IOCS | IO Provider Status / Consumer Status（Good=0x80, Bad=0x00） | ✅ |
| Substitution | data_hold 超时后使用 substitute values | ✅ 概念建模 |
| DataItem 布局 | 按 ExpectedSubmodule 配置偏移，对齐到 IOData / IOxS | ✅ 解析按偏移映射；CA0600 实机已覆盖 VLAN-tagged RT 帧；Connect.rsp 有明确 Input FrameID 时不再 fallback 接收其他 cyclic FrameID |

### Record Read / Write

**规范出处** — PN-AL-Services §5.2.5 (Record), PN-AL-Protocol §6.3

| 协议要素 | 说明 | 当前实现 |
| --- | --- | --- |
| IODReadReqHeader | seq_number, ar_uuid, api, slot_number, subslot_number, index, record_data_length | ✅ 编解码 |
| IODWriteReqHeader | 同 Read + additional, padding, record_data | ✅ 编解码 |
| IODReadResHeader | 包含 PNIOStatus (ErrCode, ErrDecode, ErrCode1, ErrCode2, AddValue1, AddValue2) | ✅ 编解码 |
| 常用 Index | 0xF820 PDPortDataReal, 0xF831 PDPortStatistic, 0xF840 PDInterfaceDataReal, 0xF841 PDRealData, 0xAFF0-0xAFF5 I&M0-5, 0x802B PDPortMRPDataReal | ✅ 常量集 |

### PROFIdrive 参数访问

**规范出处** — PROFIdrive Profile (IEC 61800-7-3), PD Controller Application V1.0

| 协议要素 | 说明 | 当前实现 |
| --- | --- | --- |
| Record Index | Base 0xB02E，通过 Record Read/Write 访问 | ✅ |
| Profile ID | 0x3A00 | ✅ |
| ParamRequest | request_id (Read=1, Write=2), axis, PNU, subindex, num_elements | ✅ 编解码 |
| ParamResponse | format, num_values, values (raw Bytes) | ✅ 编解码 |
| 标准 PNU | p967 ControlWord1, p968 StatusWord1, p1 SpeedSetpoint, p2 SpeedActual, p924 StationName, p964 VendorID, p965 DeviceID | ✅ 常量 |
| 控制器应用层 | DriveState 状态机 (S1→S2→S3→S4, AUS2/AUS3), STW1/ZSW1 位掩码, TelegramData (18 字段), encode/parse_telegram, speed_percent_a | ✅ `profidrive/controller.mbt` |
| 扩展 PNU | p922 TelegramSelection, p925 SignOfLifeTolerance, p930 OperatingMode, p944-952 故障缓冲区, p975 DOIdentification, p978 DOIdList, p979 SensorFormat | ✅ `profidrive/controller.mbt` |
| 故障处理 | stw1_fault_ack 位掩码 (0x0080), p944-952 故障缓冲区 PNU 常量 | ✅ `profidrive/controller.mbt` |

### SNMPv1

**规范出处** — RFC 1157 (SNMPv1), PN-AL-Services §5.3.3

| 协议要素 | 说明 | 当前实现 |
| --- | --- | --- |
| SNMP Message | version=0 (SNMPv1), community, PDU (GetRequest/GetResponse/SetRequest) | ✅ 编解码 |
| BER/TLV 编码 | ASN.1 基本类型：INTEGER, OCTET STRING, OID, SEQUENCE, NULL | ✅ |
| VarBindList | OID + Value 对列表 | ✅ |
| PROFINET 常用 OID | sysDescr (1.3.6.1.2.1.1.1), sysName (1.3.6.1.2.1.1.5), lldpRemTable (1.0.8802.1.1.2.1.4) 等 | ✅ 常量 |

### LLDP

**规范出处** — IEEE 802.1AB (LLDP), PN-Profiles §5.2.2

| 协议要素 | 说明 | 当前实现 |
| --- | --- | --- |
| LLDPDU | EtherType 0x88CC, TLV 链表 | ✅ 编解码 |
| Mandatory TLV | Chassis ID (type=1), Port ID (type=2), TTL (type=3), End of LLDPDU (type=0) | ✅ |
| Optional TLV | Port Description (type=4), System Name (type=5), System Description (type=6) | ✅ |
| PROFINET 组织专用 TLV | OUI=00-0E-CF, subtype: PortStatus (0x02), MRPPortStatus (0x04), ChassisMAC (0x05), PTCPStatus (0x06) | ✅ PROFINET OUI 识别 |

### DHCP

**规范出处** — RFC 2131 (DHCP), RFC 2132 (DHCP Options)

| 协议要素 | 说明 | 当前实现 |
| --- | --- | --- |
| DHCP Message | op (BOOTREQUEST=1/BOOTREPLY=2), htype=1, hlen=6, xid, ciaddr, yiaddr, siaddr, giaddr, chaddr, magic cookie (0x63825363) | ✅ 编解码 |
| Message Types (Option 53) | Discover=1, Offer=2, Request=3, Decline=4, Ack=5, Nak=6, Release=7, Inform=8 | ✅ |
| 常用 Options | SubnetMask (1), Router (3), DNS (6), HostName (12), RequestedIP (50), LeaseTime (51), ServerIdentifier (54), ParameterRequestList (55), End (255) | ✅ |

### Security Profiles

**规范出处** — PN-Security V2.5 (PN-Security-Profiles-2762)

| 协议要素 | 说明 | 当前实现 |
| --- | --- | --- |
| SecurityMode | Any (0x01), Protected (0x02) | ✅ 编解码 |
| ProtectionMode | AuthOnly (0x00), AuthEncrypt (0x01) | ✅ 编解码 |
| AEAD Algorithm | AES-128-GCM, AES-256-GCM, ChaCha20-Poly1305 及密钥长度 | ✅ 编解码 |
| SecurityData Header | protection_mode (1B), generation_number (1B), sequence_counter (4B), security_length (2B), 共 8 字节 PRO 帧安全头 | ✅ encode/parse |
| SecurityUtilization | Disabled, PRTLayer, ApplicationLayer, PRTAndApplication, Management, Full | ✅ 枚举 |
| Security Frame IDs | alarm_high_secure=0xFC41, alarm_low_secure=0xFE41 | ✅ 常量 |
| SXP Security Blocks | ReadSecurityReq (0x0723), ReadSecurityRsp (0x8723), WriteSecurityReq (0x0724), WriteSecurityRsp (0x8724) | ✅ 常量 |
