Skip to content

ci(maintenance): verify exact source SHA in four discovery guards - #414

Closed
masarray wants to merge 1 commit into
mainfrom
maintenance/ci-exact-checkout-20260926
Closed

masarray wants to merge 1 commit into
mainfrom
maintenance/ci-exact-checkout-20260926

Conversation

@masarray

@masarray masarray commented Sep 26, 2026 •

Copy link
Copy Markdown
Owner

Root cause

Four Smart Discovery PR workflows used git clone --depth 1 --branch $GITHUB_HEAD_REF. That checkout can follow the branch as it moves and is not guaranteed to be the exact commit/merge candidate associated with the workflow run; its synthetic evidence files subsequently record whichever commit was cloned.

Change

  • Use the repository's existing actions/checkout@v7 pattern for all four workflows, retaining their ArIED61850Tester working directory and existing test/artifact paths.
  • Fail closed if git rev-parse HEAD is not the exact GITHUB_SHA supplied for this run. For pull_request this is the GitHub-provided merge candidate; for workflow_dispatch it is the selected triggering commit.
  • Disable persisted checkout credentials. Preserve pinned-engine fetch/verification and every existing validation and packaging step.

Baseline and isolation

Base main 9d081f54fc6466d13c099e8a94a020c487a36703; head 06b0ed315893cb13b61ae8346fa383ccfe22fa37. Exact diff: four workflow YAML files, one commit; no application source, build scripts, evidence values, engine locks or release workflows modified. This is separate from maintenance PR #413 and SCL correctness PR #374. The already published v1.6.40 artifacts remain unchanged.

Validation and merge gate

  • Exact four-file diff verified. All four affected workflows completed the Verify exact candidate revision step successfully.
  • 8/8 workflow runs passed at head 06b0ed315893cb13b61ae8346fa383ccfe22fa37, including Build ARSAS and Smart Discovery Field Capture Build.
  • Merge Execution Guard reported 1,315 tests passed, zero failures and skips. The two trusted-SCL and five pre-existing facade warning sites on this independent branch are unchanged and are not part of this CI refactor.
  • No auto-merge. Repository DCO sign-off must be satisfied by an authorized contributor; no substitute sign-off is asserted here.

Tracks maintainability issue #380.

Copy link
Copy Markdown
Owner Author

Combined with #413 and #415 in draft integration PR #416 (#416). The exact four source blobs were reproduced unchanged; on the combined head all four candidate-SHA verification steps and 9/9 workflows passed. Keep this source PR open for traceability; avoid separate merge if #416 becomes the signed-off integration vehicle.

Copy link
Copy Markdown
Owner Author

Superseded by consolidated PR #416, merged to main as e7b43508fb3b2bf5fbda7be8ed8425da74bb9766. Verified that this PR's exact changed-file blob SHAs are present in #416's merged tree; no separate merge of this source PR is necessary. Closing this draft to prevent duplicate integration. This does not imply any new physical IED acceptance or release promotion.

@masarray masarray closed this Sep 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant