diff --git a/.github/workflows/rcb-export-guard.yml b/.github/workflows/rcb-export-guard.yml index bbbf233b3..6adca0000 100644 --- a/.github/workflows/rcb-export-guard.yml +++ b/.github/workflows/rcb-export-guard.yml @@ -12,6 +12,7 @@ on: - "Services/RcbAvailabilityProbeService.cs" - "SaveSclWindow.xaml.cs" - "scripts/verify-rcb-export.ps1" + - "engines/ARIEC61850.lock.json" - ".github/workflows/rcb-export-guard.yml" pull_request: branches: [ main ] @@ -24,6 +25,7 @@ on: - "Services/RcbAvailabilityProbeService.cs" - "SaveSclWindow.xaml.cs" - "scripts/verify-rcb-export.ps1" + - "engines/ARIEC61850.lock.json" - ".github/workflows/rcb-export-guard.yml" workflow_dispatch: @@ -38,9 +40,25 @@ jobs: - name: Checkout ARSAS uses: actions/checkout@v7 - - name: Checkout ARIEC61850 engine + - name: Checkout pinned ARIEC61850 engine shell: powershell - run: git clone --quiet --depth 1 --branch main https://github.com/masarray/ARIEC61850.git ARIEC61850 + run: | + $lock = Get-Content .\engines\ARIEC61850.lock.json -Raw | ConvertFrom-Json + if ($lock.repository -ne 'masarray/ARIEC61850' -or + ([string]$lock.commit) -notmatch '^[0-9a-f]{40}$') { + throw 'Invalid ARIEC61850 integration lock.' + } + git clone --quiet --filter=blob:none --no-checkout "https://github.com/$($lock.repository).git" ARIEC61850 + if ($LASTEXITCODE -ne 0) { throw 'Engine clone failed.' } + git -C .\ARIEC61850 fetch --quiet --depth 1 origin $lock.commit + if ($LASTEXITCODE -ne 0) { throw 'Pinned engine fetch failed.' } + git -C .\ARIEC61850 checkout --quiet --detach $lock.commit + if ($LASTEXITCODE -ne 0) { throw 'Pinned engine checkout failed.' } + $actual = (git -C .\ARIEC61850 rev-parse HEAD).Trim().ToLowerInvariant() + if ($LASTEXITCODE -ne 0 -or $actual -ne ([string]$lock.commit).ToLowerInvariant()) { + throw "Pinned engine mismatch. Expected $($lock.commit), checked out $actual." + } + Write-Host "RCB export guard uses pinned ARIEC61850 $actual" - name: Verify RCB availability and export invariants id: guard