#!/usr/bin/env bash # Revision preflight guard: verify the script being executed matches origin/master # Usage: revision-preflight.sh # Returns 0 if match, 1 if mismatch (prints both revisions) set -euo pipefail SCRIPT="${1:?Usage: revision-preflight.sh }" CLONE="${2:?Usage: revision-preflight.sh }" # Compute sha256 of the script being executed EXEC_SHA=$(sha256sum "$SCRIPT" | cut -d' ' -f1) # Compute sha256 of the merged origin/master version # Extract to a temp file to avoid pipe issues TMPFILE=$(mktemp) trap 'rm -f "$TMPFILE"' EXIT # Try to extract the file from origin/master if git -C "$CLONE" show "origin/master:$(basename "$SCRIPT")" > "$TMPFILE" 2>/dev/null; then MASTER_SHA=$(sha256sum "$TMPFILE" | cut -d' ' -f1) else echo "⚠️ revision-preflight: could not resolve origin/master revision for $(basename "$SCRIPT")" >&2 exit 0 # Warn but don't block if git show fails fi if [[ -z "$MASTER_SHA" || "$MASTER_SHA" == "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" ]]; then echo "⚠️ revision-preflight: could not resolve origin/master revision for $(basename "$SCRIPT")" >&2 exit 0 # Warn but don't block if git show fails fi if [[ "$EXEC_SHA" != "$MASTER_SHA" ]]; then echo "⚠️ revision-preflight: MISMATCH detected" >&2 echo " Executed: $EXEC_SHA ($(basename "$SCRIPT"))" >&2 echo " Merged: $MASTER_SHA (origin/master:$(basename "$SCRIPT"))" >&2 exit 1 else echo "✅ revision-preflight: $SCRIPT matches origin/master ($EXEC_SHA)" >&2 exit 0 fi