Skip to content

XMSG / COSMOS handoff - 2026-08-09

Full path: E:\Dev\Ronny\NDInsight\SINTRAN\XMSG\DOC\HANDOFF-2026-08-09.md Branch 5000x. 733 tests green, zero build errors, at commit db9153b.

Previous handoff: SINTRAN\XMSG\DOC\HANDOFF-2026-08-07.md.


Read this first

D100 / HDLC1 is RESERVED by the owner as of this session. Nothing live was run against it, and nothing should be until he says go. Everything below is offline work.

Two real defects were found today, both by the same route: a value modelled as "derived from X" that was actually a constant, and vice versa. Both were caught by finding a capture where the coincidence broke.


Commits

Commit What
bb6175a APPEND-REMOTE-BATCH builder, byte-checked against the 2026-07-31 capture
2b43b62 No-copy sweep + the FA read-path conversation-word defect
1f648e8 The confirm trailing word is a constant, not a system number
db9153b One header-checksum stamper, one chat send

Defect 1 - the conversation word survived in one more place

d8e5f36 (2026-08-08) fixed the FA server to stamp the ECHOED conversation word rather than the constant 0x0002 on replies, short acknowledgements and the close. It missed the file-READ data messages: FaServer still passed FaExchangeCodec.ResponderConversation.

A read on any conversation other than 0x0002 therefore sent data carrying a word the client never issued - the same thing that hung a live terminal.

Two reasons it survived a whole day:

  • Its comment justified the constant with "the captured data messages carry 07F0 0002" - that capture is the one session whose letter happened to carry 0x0002.
  • FaReadFileWiringTests.TheFragmentsReassembleIntoTheFileContent asserted the constant. The fixture's letter is already 0x0004 on purpose, so the test was one identifier away from catching the bug it was written for.

Rule for next time: when a value turns out to be echoed rather than constant, grep every remaining use of the constant. Fixing the sites you happen to be debugging is not finishing.

Defect 2 - the confirmation's trailing word is a constant

Word 3 of the connection confirmation was built from the client's node number, modelled as "the system number byte, 0x64 = 100 in every capture". Every real confirmation:

server D100 0x64, client D102 0x66  ->  07D2 0002 0046 6400
server D100 0x64, client D102 0x66  ->  07D2 0002 0055 6400
server D100 0x64, client D102 0x66  ->  07D2 0002 004D 6400
server D102 0x66, client D103 0x67  ->  07D2 0008 003F 6400

The last line settles it - neither end is node 100 and the word is still 0x6400. Against D103 we were emitting 6700, which no real machine has ever sent.

The owner killed this model faster than the captures did: an ND system number is 16 bits, so a one-byte field could never hold one. That check needs no capture at all. It is saved as memory check-field-width-against-the-thing.

Now FaExchangeCodec.ConfirmTrailingWord = 0x6400, meaning UNKNOWN, reproduced because it is what every real machine emits. Write-up: SINTRAN\XMSG\DOC\XMSG-FA-CONFIRM-TRAILING-WORD-IS-CONSTANT-2026-08-09.md.


The no-copy sweep

Four read-only audit agents over builders, node/session, transports and tests. What was real:

Was Now
FA 8-byte envelope written by hand at 4 sites FaExchangeCodec.WriteEnvelope
FromHex in 12 private test copies, 3 different behaviours Xmsg.TestSupport.TestHex
Two BigEndian classes picked by namespace nesting one, in the outer namespace
Checksum args hand-packed at 9 sites, 2 hardcoding the subtype XmsgEnvelope.StampChecksum(header)
ChatClient.SendToServer = ChatServer.SendTo ChatWire.Send

Reported as not duplication and deliberately left alone: golden capture bytes repeated across 5-7 test files (independent cross-layer verification), the two FakeLink classes (self-documented as different on purpose), SintranDatagramRelay's checksum call (verifies a raw span, does not stamp a header), and the Hub/Ethernet RETH framing (a recorded trade-off in Xmsg.Hub.csproj).

Clean across all test projects: zero FluentAssertions, zero LINQ, zero foreach.

One audit finding was REJECTED. An agent flagged TadServer.cs:505 and :552 echoing Flags 1 as the FA-confirm defect class. Not changed: TAD connect works live and there is no capture showing the FA rule transfers. Logged as task #32 with a measurement recipe so it gets settled from captures rather than by anyone's opinion.


Open tasks

# State
#30 APPEND-REMOTE-BATCH builder done and byte-verified. Never sent to a live machine.
#31 FA sessions do not survive a runner restart - needs a capture of what a real server answers for an unknown conversation. Do NOT invent one.
#18 Confirm the close no longer draws XEIMA from D100. Confirm only.
#23 FA 0x0D and 0x01 - blocked, no known operator command drives either.
#32 LOW PRIO - validate the TadServer Flags 1 echo against every captured scenario.
#33 NEW - folder-watch file sync daemon, VS Code to SINTRAN and back.
#34 NEW - chat: SINTRAN RT server, SINTRAN clients, channels, aliases. Blocked on #33.

#30, #18 and #23 all need D100.


The two new features, in short

#33 sync daemon. Watch local folders, push to SINTRAN, pull compiler output back, set the parity bit per extension, fire APPEND-REMOTE-BATCH to compile. The point is a fast edit -> build -> see-the-listing loop in VS Code for ASM / PLANC / NPL. Depends on #30 for the trigger.

#34 chat. SRC/Xmsg.Chat already holds a working C# client and server over XMSG - read it before designing anything. Missing: a SINTRAN RT-program server, a SINTRAN client, C# clients against a REAL server, cross-machine, multiple channels, aliases defaulting to the SINTRAN user name. The owner wants it after #33, because #33 is what makes writing the SINTRAN-side program bearable.


Traps that cost time today

  • A failed build with green tests. dotnet build failed on doc-comment errors while dotnet test --no-build happily reported 733 passing off the stale DLLs. Always read the build result before believing a test result.
  • An agent's confident wrong claim. One reported HexBytes.FromHex as whitespace-blind. It strips nothing. Routing the whitespace-stripping test copies to it would have made capture literals with line breaks start throwing. Agents' findings need checking.
  • fa-edge-cases.pcapng is 1785 frames of which only 14 are XMSG; the rest is unrelated loopback TCP noise. Filter on hdlc_lapb in tshark, and note the dissector is installed globally - passing -X lua_script: loads it twice and errors.