diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 0bf2019..27f6736 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -10,6 +10,10 @@ on: env: CARGO_TERM_COLOR: always RUST_VERSION: "1.96.0" + # Clone sibling repos at the same branch as this PR so cross-repo changes + # (e.g. RFL-128 contracts/ move) resolve consistently. Falls back to main + # on direct pushes (github.head_ref is empty) and for repos without the branch. + REFLECTIVE_SIBLING_REF: ${{ github.head_ref || 'main' }} jobs: ci: diff --git a/Cargo.toml b/Cargo.toml index 9eec2fd..1c7da1e 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -52,7 +52,7 @@ organism-intent = { path = "../bedrock-platform/organism/crates/intent organism-planning = { path = "../bedrock-platform/organism/crates/planning" } organism-runtime = { path = "../bedrock-platform/organism/crates/runtime" } application-storage = { path = "../bedrock-platform/helms/crates/application-storage" } -helm-module-contracts = { path = "../bedrock-platform/helms/crates/helm-module-contracts" } +helm-module-contracts = { path = "../bedrock-platform/helms/contracts/crates/helm-module-contracts" } helm-operator-control = { path = "../bedrock-platform/helms/crates/helm-operator-control" } prio-agent-ops = { path = "../bedrock-platform/helms/crates/prio-agent-ops" } arena-intent-cases = { path = "crates/intent-cases" } diff --git a/scripts/ci/checkout-reflective-siblings.sh b/scripts/ci/checkout-reflective-siblings.sh index d67d06f..263e102 100755 --- a/scripts/ci/checkout-reflective-siblings.sh +++ b/scripts/ci/checkout-reflective-siblings.sh @@ -17,10 +17,22 @@ set -euo pipefail workspace="${GITHUB_WORKSPACE:-$(git rev-parse --show-toplevel)}" +# REFLECTIVE_SIBLING_REF controls which branch siblings are cloned from (default: main). +# Validate to only allow chars legal in git branch names; reject anything else so a +# malformed value cannot be used for argument injection in the git clone call below. +_raw_ref="${REFLECTIVE_SIBLING_REF:-main}" +if [[ ! "$_raw_ref" =~ ^[a-zA-Z0-9/._-]+$ ]]; then + echo "warning: REFLECTIVE_SIBLING_REF='${_raw_ref}' contains disallowed characters; using main" >&2 + _raw_ref=main +fi +REFLECTIVE_SIBLING_REF="$_raw_ref" +unset _raw_ref + checkout_reflective_repo() { local repo="$1" local relative_path="$2" local dest="${workspace}/${relative_path}" + local sibling_ref="${REFLECTIVE_SIBLING_REF:-main}" if [[ -d "$dest/.git" ]]; then echo "ok: ${relative_path} already checked out" @@ -33,7 +45,18 @@ checkout_reflective_repo() { fi mkdir -p "$(dirname "$dest")" - echo "==> checkout Reflective-Lab/${repo} -> ${relative_path}" + + if [[ "$sibling_ref" != "main" ]]; then + echo "==> checkout Reflective-Lab/${repo}@${sibling_ref} -> ${relative_path}" + if GIT_TERMINAL_PROMPT=0 git clone --depth=1 --branch "$sibling_ref" --quiet \ + "https://github.com/Reflective-Lab/${repo}.git" "$dest" 2>/dev/null; then + return + fi + echo " (branch '${sibling_ref}' not found; falling back to main)" + rm -rf "$dest" + fi + + echo "==> checkout Reflective-Lab/${repo}@main -> ${relative_path}" GIT_TERMINAL_PROMPT=0 git clone --depth=1 --quiet "https://github.com/Reflective-Lab/${repo}.git" "$dest" }