Repository navigation
ci(p3a): establish reproducible Windows portable build identity - #448
Conversation
|
CI-P3A final acceptance on exact head
No runtime, IEC 61850 authority, physical evidence, installer semantics or release publication authority changed in P3A. |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7b2a0a9d98
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| portableSha256 = $portableHash | ||
| portableSizeBytes = (Get-Item $singleExePath).Length | ||
| deterministicManagedBuild = $true | ||
| reproducibleNativeLinkRequested = $true |
There was a problem hiding this comment.
Report reproducible linking only when it occurred
When callers supply -ArdIrecBridgePath, or when build-ardirec-bridge.ps1 reuses its existing destination DLL, this publish invocation never links the bridge with /Brepro; nevertheless, the emitted identity unconditionally attests that reproducible native linking was requested. This can make an arbitrary or stale bridge appear to carry reproducible-build provenance in evidence later used for cross-run acceptance. Derive this field from the actual bridge-build path, or verify/rebuild the bridge before setting it to true.
AGENTS.md reference: AGENTS.md:L11-L17
Useful? React with 👍 / 👎.
Closes #447
What changes
/Brepro) for the pinned ArdIrec bridge.Deterministic=trueandContinuousIntegrationBuild=true.ARSAS-*-portable-build-identity.jsoncontaining source, ARIEC61850, ArdIrec lock, native bridge and portable EXE SHA-256/size evidence.Safety boundary
P3A does not authorize binary reuse yet. P2F's binary-reuse prohibition remains until the two independent CI lanes actually produce identical bridge and portable hashes on matching inputs.
Acceptance
All existing CI green; canonical and Field Capture identities show exact matching source/engine/ArdIrec commits; bridge SHA-256 identical; portable EXE SHA-256 identical. If hashes still differ, P3B is blocked and the identity evidence will locate the remaining nondeterminism.