feat: add deterministic operating-point security validation - #86
qian-harvard merged 6 commits into
Conversation
operating_point.py sat at the repository root, which the wheel does not ship: it packages powermcp/ plus the force-included server directories. From a source checkout the import worked, so CI passed; from an installed wheel, `powermcp run pandapower` died with "ModuleNotFoundError: No module named 'operating_point'" -- taking down the whole pandapower server, a core, default-installed tool, not just the new one. It now lives beside audit.py in pandapower/, ships as powermcp/_servers/pandapower/operating_point.py, and imports through the server's own directory the same way audit does. Verified from a fresh venv with the built wheel installed: both tools register and run. The tool reports like its siblings and like audit_network: status "success" when the validation ran, "error" with a message when it could not (no network, no converged power flow, invalid limits), with the verdict in validation_status (ok, warning or error). The library keeps its own return shape; the tool translates at the boundary. Validator fixes: - Near-limit warnings are raised only for elements inside the band. The old margin/band < 0.05 test was also true for negative margins, so an element already violating was reported as near a limit too. - Out-of-service buses are skipped; pandapower gives them NaN by design. - 3-winding transformers are checked for loading and counted in losses. - Non-finite values serialize as null instead of a bare NaN token, which is not valid JSON. - The tool docstring states the prerequisite, the global-limit semantics and the envelope. Tests load the module by path and cover the fixes plus the tool itself: the no-network and could-not-run paths, the success envelope, limits reaching the validator, and registration. Reverting the envelope fails them. 19 pass; full suite with current main 495 passed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
I pushed a round of changes as Packaging blocker. Envelope. Same change as on #79, so the two validators speak one dialect with the rest of the server. Validator fixes:
Tests now load the module by path and cover the fixes plus the tool itself: no-network and could-not-run paths, the success envelope, limits reaching the validator, and registration. I checked that reverting the envelope fails them. 19 pass; the full suite with current Follow-ups, none blocking: an opt-in flag to honour per-element limits ( Thanks for two solid validation tools in a row. |
Adds a deterministic, solver-independent operating-point security validation layer for the pandapower MCP server.
Changes
Add operating_point.py for validation of an existing converged power-flow result.
Check bus voltage limits and line/transformer loading limits.
Report operating-point extrema, active/reactive losses, near-limit conditions, and deterministic violations.
Expose validate_operating_point as an MCP tool.
Return stable machine-readable statuses: ok, warning, error, and failed.
Ensure validation does not rerun a solver or mutate the network.
Add focused regression tests covering clean operation, voltage violations, line overloads, near-limit conditions, unsolved networks, invalid criteria, and non-mutation
Scope: This PR intentionally contains only the operating-point validation implementation, MCP exposure, and focused tests.