diff --git a/tools/ci/pre-push.sh b/tools/ci/pre-push.sh index c6364234..fa06a7f2 100755 --- a/tools/ci/pre-push.sh +++ b/tools/ci/pre-push.sh @@ -59,6 +59,7 @@ tree_checks() { run "shell inside .github/workflows parses (bash -n, the PowerShell 5.1 rule)" node tools/ci/check-workflow-shell.mjs run "PowerShell drive-reference check (\$name: in a double-quoted string)" bash tools/ci/ps-drive-ref-check.sh run "copied sources are re-stamped before a build" bash tools/ci/copied-sources-check.sh + run "the prover pair is built from the pinned node's exec types (prover-pair-check)" bash -c 'bash tools/ci/prover-pair-check.sh --self-test && bash tools/ci/prover-pair-check.sh' run "override params files parse with no duplicate key" bash tools/ci/override-json-check.sh run "second-engine playbooks log to a file and end their tree (C35)" bash tools/ci/second-engine-check.sh run "no playbook quits, pauses or resumes the installed app" bash -c 'bash tools/ci/playbook-quit-check.sh --self-test && bash tools/ci/playbook-quit-check.sh' diff --git a/tools/ci/prover-pair-check.sh b/tools/ci/prover-pair-check.sh new file mode 100755 index 00000000..f9222a80 --- /dev/null +++ b/tools/ci/prover-pair-check.sh @@ -0,0 +1,37 @@ +#!/usr/bin/env bash +# A release's prover pair is built from the same execution types as its node (7 October 2026, main's rule, the class of the +# igneum-pow pairing rule): the fleet's 14 standing provers cut a different state root from the 0.3.17 node on every segment +# because their pair came from another tree. The proving crate depends on vendor/igneum-node-exec/igneum/evm-types (and revm); +# the node ships from the fork commit in packaging/windows/node-source.pin. This check fails when the evm-types tree the prover +# is built against differs from the evm-types tree of the pinned node commit. +# +# tools/ci/prover-pair-check.sh compare (needs the fork worktree under vendor/ that holds the pinned commit) +# tools/ci/prover-pair-check.sh --self-test the comparison on two known trees +set -euo pipefail +HERE="$(cd "$(dirname "$0")/../.." && pwd)" +tree_of() { git -C "$1" rev-parse "$2:igneum/evm-types" 2>/dev/null || true; } +if [ "${1:-}" = "--self-test" ]; then + d=$(mktemp -d); trap 'rm -rf "$d"' EXIT + git -C "$d" init -q; mkdir -p "$d/igneum/evm-types"; echo a > "$d/igneum/evm-types/lib.rs"; git -C "$d" add -A; git -C "$d" -c user.name=t -c user.email=t@t commit -qm one + one=$(git -C "$d" rev-parse HEAD); echo b > "$d/igneum/evm-types/lib.rs"; git -C "$d" add -A; git -C "$d" -c user.name=t -c user.email=t@t commit -qm two; two=$(git -C "$d" rev-parse HEAD) + [ "$(tree_of "$d" "$one")" != "$(tree_of "$d" "$two")" ] || { echo "prover-pair: self-test FAILED (two different trees read equal)"; exit 1; } + [ "$(tree_of "$d" "$one")" = "$(tree_of "$d" "$one")" ] || { echo "prover-pair: self-test FAILED"; exit 1; } + echo "prover-pair: self-test ok"; exit 0 +fi +pin_file="$HERE/packaging/windows/node-source.pin" +[ -f "$pin_file" ] || { echo "prover-pair: no $pin_file (nothing pinned; skipped)"; exit 0; } +pin=$(head -1 "$pin_file" | awk '{print $1}') +exec_wt="$HERE/vendor/igneum-node-exec" +[ -d "$exec_wt" ] || { echo "prover-pair: no vendor/igneum-node-exec worktree (the prover's exec types); skipped"; exit 0; } +prover_tree=$(tree_of "$exec_wt" HEAD) +node_tree="" +for wt in "$HERE"/vendor/igneum-node-*; do + [ -d "$wt" ] || continue + t=$(tree_of "$wt" "$pin"); [ -n "$t" ] && { node_tree="$t"; break; } +done +[ -n "$node_tree" ] || { echo "prover-pair: the pinned node commit ${pin:0:8} is in no fork worktree under vendor/; cannot compare (skipped)"; exit 0; } +if [ "$prover_tree" != "$node_tree" ]; then + echo "prover-pair: FAIL: the prover's exec types (vendor/igneum-node-exec $(git -C "$exec_wt" rev-parse --short=8 HEAD), evm-types tree ${prover_tree:0:12}) differ from the pinned node's (${pin:0:8}, tree ${node_tree:0:12}); rebuild the prover pair against the node's tree before the inputs push and the DMG" + exit 1 +fi +echo "prover-pair: ok: the prover's exec types (evm-types tree ${prover_tree:0:12}) equal the pinned node's (${pin:0:8})"