AEROSIM-TS-45
Bind CI success to the immutable candidate head
The workflow records and reports the exact candidate commit and cannot publish a successful aggregate result until every required gate for that commit passes.
- Verified flow state
- Done
- Owner
- AeroSim Architecture and Delivery
- Feature
- AEROSIM-FT-51
- Component
- Gitea Actions — exact-head result gate
- Repository
- corp-v1-aerosim/corp-v1-aerosim
Delivery scope
Capture github.event.pull_request.head.sha or github.sha once as CANDIDATE_SHA, checkout that detached commit, verify HEAD before every gate and aggregation, and emit a machine-readable ci-result.json tied to that exact SHA. Primary files: .gitea/workflows/application-validation.yaml, scripts/verify-ci-head.mjs, tests/ci/exact-head-gate.test.mjs.
Implementation contract
Implementation artifacts
- .gitea/workflows/application-validation.yaml
- scripts/verify-ci-head.mjs
- tests/ci/exact-head-gate.test.mjs
Inputs
- Gitea event payload and checked-out git HEAD
- Required job conclusions for lint, typecheck, test, and build
Outputs
- ci-result.json {candidateSha,observedHead,gates,aggregate:"success"}
- Successful exact-head status only when candidateSha equals observedHead and all four gates passed
Failure boundaries
- Fail on missing/malformed candidate SHA, branch-name checkout, HEAD mismatch, absent conclusion, or any non-success conclusion.
- A newer branch tip cannot replace the event SHA or inherit results from an earlier workflow run.
Excluded scope
- Merge authorization, release tagging, artifact publication, and GitOps selection are not granted by this CI result.
Verification steps
- node --test tests/ci/exact-head-gate.test.mjs
- Evaluate fixtures for matching SHA, moved branch, stale result SHA, skipped gate, and missing gate; only matching all-pass may produce aggregate success.
Traceability
Dependencies
- AEROSIM-TS-44Canonical ID: TASK-0044
UI/UX applicability
non_visual
This Task owns technical or behavioral acceptance and does not claim direct visual conformance to the approved UI/UX package.
Acceptance evidence
Verified delivery: application PR #67 reviewed head 7ac9a7c65df6e1999b0fe1e9d5db3b4c6611b7fc passed exact-head required validation task 2171 and merged as db785b57a2c9928c893f412b5de27b21ec042652. The merged workflow binds each gate and aggregate result to one immutable candidate SHA. Recovery follow-up PR #69 reviewed head 15926e672528b730c8c83f54fce8c56653d8bfba added explicit manual dispatch, passed exact-head validation, and merged as 5a7caf344ccce1d1cf18182487bc6577139ed67b. Release completion verified on product 1.0.0.0 at GitOps revision 5d3712d89dfbf7dacd993348e55f497d126c7bf9 with Argo Synced/Healthy, exact image digests, authenticated API/database access, and three-world configured-flight acceptance.
Current evidence boundary
No current implementation, acceptance, release, or deployment evidence is claimed for this planned Task. Any prior implementation may be used only as prototype and discovery evidence.