Skip to content

chore(maintenance): inventory workflow and script consumers reproducibly #78

chore(maintenance): inventory workflow and script consumers reproducibly

chore(maintenance): inventory workflow and script consumers reproducibly #78

name: Smart Discovery Post-Merge Production Verification
on:
push:
branches:
- main
workflow_dispatch:
jobs:
post-merge-production:
name: Verify R10 convergence authority on main
runs-on: windows-latest
steps:
- name: Checkout ARSAS main
uses: actions/checkout@v7
with:
fetch-depth: 1
- name: Verify R10 physical convergence authority
shell: powershell
run: |
$target = Get-Content .\evidence\interoperability-reference-target.json -Raw | ConvertFrom-Json
$lock = Get-Content .\engines\ARIEC61850.lock.json -Raw | ConvertFrom-Json
if ($target.status -ne 'physical-retest-passed-merge-ready' -or
-not [bool]$target.promotion.physicalRetestPassed -or
[bool]$target.promotion.physicalRetestRequired -or
-not [bool]$target.promotion.mergeAllowedAfterPhysicalRetest) {
throw 'R10 physical convergence authority is not in the accepted post-merge state.'
}
$r10 = $target.physicalEvidence.arsasR10
foreach ($edition in @($r10.reuseEdition2, $r10.reuseEdition1)) {
if ([int]$edition.failedReads -ne 0 -or
[int]$edition.projectionErrors -ne 0 -or
[int]$edition.cacheLoss -ne 0 -or
[int]$edition.reportBackedRuntimePoints -ne 58 -or
[int]$edition.unresolvedRuntimePoints -ne 0 -or
-not [bool]$edition.actualInformationReportObserved) {
throw 'R10 trusted-SCL reuse proof regressed.'
}
}
if ($lock.commit -ne $target.activeStack.engineModelAndScl.mainMerge -or
$lock.commit -ne $r10.testedArtifact.engineMergedMain) {
throw 'ARSAS engine lock no longer matches the R10 merged engine authority.'
}
"ENGINE_REPOSITORY=$($lock.repository)" | Out-File $env:GITHUB_ENV -Encoding utf8 -Append
"ENGINE_COMMIT=$($lock.commit)" | Out-File $env:GITHUB_ENV -Encoding utf8 -Append
- name: Checkout exact merged ARIEC61850 authority
shell: powershell
run: |
git clone --quiet --filter=blob:none --no-checkout "https://github.com/$env:ENGINE_REPOSITORY.git" ..\ARIEC61850
git -C ..\ARIEC61850 fetch --quiet --depth 1 origin $env:ENGINE_COMMIT
git -C ..\ARIEC61850 checkout --quiet --detach $env:ENGINE_COMMIT
$actual = (git -C ..\ARIEC61850 rev-parse HEAD).Trim().ToLowerInvariant()
if ($actual -ne $env:ENGINE_COMMIT) {
throw "R10 engine authority mismatch. Expected $env:ENGINE_COMMIT, got $actual."
}
- name: Setup .NET 8
uses: actions/setup-dotnet@v6
with:
dotnet-version: 8.0.x
- name: Validate and test merged engine authority
shell: powershell
run: |
# Keep the exact R10 physical-tested engine commit. Post-merge acceptance
# validates the immutable commit identity plus full restore/build/test.
dotnet restore ..\ARIEC61850\ARIEC61850.sln
dotnet build ..\ARIEC61850\ARIEC61850.sln -c Release --no-restore
dotnet test ..\ARIEC61850\tests\AR.Iec61850.Tests\AR.Iec61850.Tests.csproj -c Release --no-build --no-restore
- name: Build and test ARSAS main
shell: powershell
run: |
dotnet restore .\ArIED61850Tester.sln
dotnet build .\ArIED61850Tester.sln -c Release --no-restore
dotnet test .\tests\ARSAS.Tests\ARSAS.Tests.csproj -c Release --no-build --no-restore
- name: Write R10 post-merge evidence
if: always()
shell: powershell
run: |
New-Item -ItemType Directory -Force .\TestResults | Out-Null
$target = Get-Content .\evidence\interoperability-reference-target.json -Raw | ConvertFrom-Json
[ordered]@{
schemaVersion = 1
sourceCommit = $env:GITHUB_SHA
engineCommit = $env:ENGINE_COMMIT
convergenceStatus = $target.status
physicalRetestPassed = [bool]$target.promotion.physicalRetestPassed
ed2ProjectionErrors = [int]$target.physicalEvidence.arsasR10.reuseEdition2.projectionErrors
ed2CacheLoss = [int]$target.physicalEvidence.arsasR10.reuseEdition2.cacheLoss
ed1ProjectionErrors = [int]$target.physicalEvidence.arsasR10.reuseEdition1.projectionErrors
ed1CacheLoss = [int]$target.physicalEvidence.arsasR10.reuseEdition1.cacheLoss
reportBackedRuntimePoints = 58
} | ConvertTo-Json -Depth 5 | Set-Content .\TestResults\R10-post-merge-production.json
- name: Upload R10 post-merge attestation
if: always()
uses: actions/upload-artifact@v7
with:
name: ARSAS-r10-post-merge-production
path: .\TestResults\R10-post-merge-production.json
if-no-files-found: error
retention-days: 30