Commit 790c57de1f for openssl.org

commit 790c57de1ff03a75508bd1aadf76d5dd3f7dc4a8
Author: Georgy Karataev <georgyk@openssl.org>
Date:   Thu Jul 23 12:00:21 2026 +0200

    ci: allow ct-validation-daily to be dispatched against a PR head SHA

    Additive: schedule and bare-manual runs unchanged. Adds validated,
    fail-closed pr/head_sha/check_run_id inputs so a caller can dispatch against
    an exact commit; run-name echoes them back for correlation.

    Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

    Reviewed-by: Milan Broz <mbroz@openssl.org>
    Reviewed-by: Norbert Pocs <norbertp@openssl.org>
    MergeDate: Mon Jul 27 10:16:54 2026
    (Merged from https://github.com/openssl/openssl/pull/32053)

diff --git a/.github/workflows/ct-validation-daily.yml b/.github/workflows/ct-validation-daily.yml
index 18d8911fcb..36d1762b8b 100644
--- a/.github/workflows/ct-validation-daily.yml
+++ b/.github/workflows/ct-validation-daily.yml
@@ -40,13 +40,53 @@ on:
   schedule:
     - cron: '45 03 * * *'
   workflow_dispatch:
+    inputs:
+      pr:
+        description: 'PR number (leave empty for a bare manual run against the default branch)'
+        required: false
+        type: string
+      head_sha:
+        description: 'Exact commit SHA to check out (required when pr is set)'
+        required: false
+        type: string
+      check_run_id:
+        description: 'Check-run id to report completion back to (required when pr is set)'
+        required: false
+        type: string
+
+# Pinned run-name contract with images/openssl-ci-bot/main.py's format_run_name()/
+# parse_run_name() -- the completed-run handler parses check_run_id back out of
+# this exact format string, so keep both sides identical on any change.
+run-name: >-
+  ${{ github.event.inputs.pr && format('ci-dispatch pr={0} head={1} check_run_id={2}', github.event.inputs.pr, github.event.inputs.head_sha, github.event.inputs.check_run_id) || github.workflow }}
+
+concurrency:
+  group: ${{ github.workflow }}-${{ github.event.inputs.pr || github.run_id }}
+  cancel-in-progress: true

 permissions:
   contents: read

 jobs:
+  validate-dispatch-inputs:
+    # Defense-in-depth on the untrusted-code boundary, in addition to the
+    # dispatching service's own validation: fail closed on malformed inputs
+    # before anything checks out a ref or runs.
+    if: github.repository == 'openssl/openssl' && github.event.inputs.pr != ''
+    runs-on: ubuntu-latest
+    steps:
+      - name: Validate pr / head_sha / check_run_id
+        run: |
+          [[ "${{ github.event.inputs.pr }}" =~ ^[0-9]+$ ]] || { echo "::error::pr must be numeric"; exit 1; }
+          [[ "${{ github.event.inputs.check_run_id }}" =~ ^[0-9]+$ ]] || { echo "::error::check_run_id must be numeric"; exit 1; }
+          [[ "${{ github.event.inputs.head_sha }}" =~ ^[0-9a-f]{40}$ ]] || { echo "::error::head_sha must be a 40-character hex commit SHA"; exit 1; }
+
   ct-validation:
-    if: github.repository == 'openssl/openssl'
+    needs: [validate-dispatch-inputs]
+    if: |
+      github.repository == 'openssl/openssl' &&
+      always() &&
+      (needs.validate-dispatch-inputs.result == 'success' || needs.validate-dispatch-inputs.result == 'skipped')
     strategy:
       fail-fast: false
       matrix:
@@ -78,6 +118,9 @@ jobs:
       - uses: actions/checkout@v6
         with:
           persist-credentials: false
+          # Bare-manual/schedule triggers omit head_sha, in which case checkout
+          # falls back to its own default (github.sha) unchanged.
+          ref: ${{ github.event.inputs.head_sha || github.sha }}

       - name: Install valgrind
         # On Debian/Ubuntu the main 'valgrind' package includes