INNER CODE UNIT · Python
validate_lock
IvanMurzak/Unity-MCP · .github/scripts/chain_feed.py:736
def validate_lock(lock):
"""Refuse (exit 2) any lock whose scalars are not exactly the shape `lock.py` writes.
Runs in `build_context` straight after the JSON parse, BEFORE the lock hash, the node's sha,
the recipes or any writer reads a value — so a value that would change a shell command, a
git argv, a feed path, `$GITHUB_ENV` or `$GITHUB_OUTPUT` never reaches one:
* `nodes` keys — the node ids this file knows (`RECIPES`, which `recipes-check` pins to the
manifest); `follows` names one of them too;
* `sha` — exactly 40 lowercase hex (never an option-shaped `--upload-pack=...` git argv);
* `ws_version` — `<version>-ws.g<8 hex>`, and those 8 hex are the node's own `sha[:8]`
whenever the node carries a sha (`lock.ws_version_for`);
* `version` / `base_version` — a plain version (`_VERSION_RE`);
* `state` — one of `LOCK_STATES`; `ref` — a ref-name character set;
* `lock_hash` — `sha256:<64 hex>` when present.
"""
nodes = lock.get("nodes")
lock_hash = lock.get("lock_hash")