Split 3 of 4 of #1052 (channel-skew prevention). Part B — stub-freeze drift guard. Backstops Part A for the specific self-host caller stubs.
Blocked on Part A (#1253): this part also wires a job into .github/workflows/lint.yml. Implement it after #1253 merges so it rebases cleanly on A's lint.yml (avoids an add/add conflict). The dev-lead label is intentionally withheld until then.
Deliverable
- Treat the ring-0 caller stubs' trigger/
with: forwarding blocks like the template stubs — reuse the ALIGNED/DRIFTED byte-identity model from scripts/template_stub_drift.sh / scripts/fleet_stub_drift.sh: the forwarding block must match a committed baseline (tests/fixtures/caller-stub-freeze/*.block), so any edit fails CI unless it is an intentional, reviewed channel change.
scripts/caller_stub_freeze.sh + bats (tests/caller_stub_freeze.bats).
- Wire as a job in
.github/workflows/lint.yml.
Acceptance
- Editing a frozen stub's forwarding block fails CI; an intentional baseline update passes.
shellcheck clean; existing suites green.
Parent: #1052.
Split 3 of 4 of #1052 (channel-skew prevention). Part B — stub-freeze drift guard. Backstops Part A for the specific self-host caller stubs.
Deliverable
with:forwarding blocks like the template stubs — reuse the ALIGNED/DRIFTED byte-identity model fromscripts/template_stub_drift.sh/scripts/fleet_stub_drift.sh: the forwarding block must match a committed baseline (tests/fixtures/caller-stub-freeze/*.block), so any edit fails CI unless it is an intentional, reviewed channel change.scripts/caller_stub_freeze.sh+ bats (tests/caller_stub_freeze.bats)..github/workflows/lint.yml.Acceptance
shellcheckclean; existing suites green.Parent: #1052.