Merge ci-kill-widen cfc4f698 into master (gate: green on 8c8bfca0, recorded by tools/ci/pre-push.sh; landed on the box mirror under the exception declared by main: main's ruling, 7 Oct 2026 19:5x UK: the GitHub account is suspended, lanes land on the box mirror's master, the box gate stamp is the verdict; GitHub gets the fast-forward when it answers)

This commit is contained in:
igneum-labs 2026-10-09 07:18:00 +00:00
commit 17bf738c63
4 changed files with 86 additions and 24 deletions

View file

@ -15511,8 +15511,8 @@
"run_status": "FAIL",
"master_status": "PROPOSED / NOT RUN",
"run_id": "canary-202-20261009-01",
"evidence_path": "tools/ci/canary/1176efb9.json; build-1:/srv/canary/1176efb9/mini/00-verdict.txt; build-1:/srv/canary/1176efb9/lp-4090-11/fleet-block.json",
"updated": "2026-10-09T03:47:40.335Z",
"evidence_path": "tools/ci/canary/1176efb9.json; build-1:/srv/canary/1176efb9/mini/00-verdict.txt; build-1:/srv/canary/1176efb9/lp-4090-11/fleet-block.json; build-1:/srv/canary/1176efb9/lp-4090-43/00-verdict.txt",
"updated": "2026-10-09T07:18:00.541Z",
"evidence_record": {
"requirement_id": "INT-07",
"decision": "FAIL",
@ -15520,7 +15520,7 @@
"cell": "canary:fresh-install",
"manifest_sha": "5d53a591",
"run_id": "canary-202-20261009-01",
"evidence": "tools/ci/canary/1176efb9.json; build-1:/srv/canary/1176efb9/mini/00-verdict.txt; build-1:/srv/canary/1176efb9/lp-4090-11/fleet-block.json",
"evidence": "tools/ci/canary/1176efb9.json; build-1:/srv/canary/1176efb9/mini/00-verdict.txt; build-1:/srv/canary/1176efb9/lp-4090-11/fleet-block.json; build-1:/srv/canary/1176efb9/lp-4090-43/00-verdict.txt",
"in_progress": false,
"coverage": "partial: V6-12's clean-install half (one published object installed fresh, synced, mined, proved and paid on one host per artefact); the cross-host agreement half (node, pool, CPU verifier, each GPU host across activation) is harness:same-work's",
"release_identity": {
@ -15533,8 +15533,8 @@
},
"claim_impact": "INT-07's clean-install half on kit 2 reads FAIL on the fleet canary (the walk bound at the fifth cut); the mac block PASS stands as the Mac entry's evidence; no fleet, hive or windows entry publishes until a record reads PASS on its own block",
"reviewer": "",
"at": "2026-10-09T03:47:40.335Z",
"note": "mac PASS, fleet FAIL at sync (the walk bound at the reference chain's fifth cut under fix 2), hive and windows pending | Kit 2 (tip 1176efb9, node 5d53a591): the mac block PASS under tools/ci/canary-check.sh (the project's macOS machine: synced from empty in 2,016 s, 18 blocks in five minutes at 12.65 MH/s, 0 refusals, shard n/a on Apple silicon, the tip inside ten of the age-adjusted feed, quit in 4 s); the fleet block FAIL at sync (lp-4090-11, 04:04 UK: a fresh 2.0.2 node walls at the reference chain's fifth cut under fix 2's walk bound, 'passed 7200 blocks (2 x epoch_blocks) without meeting a block this executor holds a record of'; the kit ran clean; build-1:/srv/canary/1176efb9/lp-4090-11/fleet-block.json); the hive block reads about 05:30 UK, the windows block on the relay lane's clock. No fleet, hive or windows entry publishes on this record; the Mac entry published on its PASS block at 02:20 UK. Kit 1's 94e4c6ba FAIL (the wedge) stands as that sha's record. The recorder's rule: a measured FAIL on one block is a FAIL on the case. Re-recorded 9 October 2026 04:3x UK with the hive block (lp-4090-43, FAIL at sync on the lost-proof loop) and the re-shaped fleet block (no sync.feed object).",
"at": "2026-10-09T07:18:00.541Z",
"note": "mac PASS (the Mac entry published on it 02:20 UK); fleet FAIL at sync (lp-4090-11, 04:04 UK: the walk bound at the reference chain's fifth cut under fix 2); hive FAIL (lp-4090-43: the lost-proof loop at the first class v5 cut, 'the proofs of 2 carried records are not held yet'); no windows block (the Windows order's default fired: no push without a proved shard). No fleet, hive or windows 2.0.2 entry publishes on this record. | Kit 2 (tip 1176efb9, node 5d53a591): the mac block PASS under tools/ci/canary-check.sh (the project's macOS machine: synced from empty in 2,016 s, 18 blocks in five minutes at 12.65 MH/s, 0 refusals, shard n/a on Apple silicon, the tip inside ten of the age-adjusted feed, quit in 4 s); the fleet block FAIL at sync (lp-4090-11, 04:04 UK: a fresh 2.0.2 node walls at the reference chain's fifth cut under fix 2's walk bound, 'passed 7200 blocks (2 x epoch_blocks) without meeting a block this executor holds a record of'; the kit ran clean; build-1:/srv/canary/1176efb9/lp-4090-11/fleet-block.json); the hive block reads about 05:30 UK, the windows block on the relay lane's clock. No fleet, hive or windows entry publishes on this record; the Mac entry published on its PASS block at 02:20 UK. Kit 1's 94e4c6ba FAIL (the wedge) stands as that sha's record. The recorder's rule: a measured FAIL on one block is a FAIL on the case. Re-recorded 9 October 2026 04:3x UK with the hive block (lp-4090-43, FAIL at sync on the lost-proof loop) and the re-shaped fleet block (no sync.feed object). Cell note brought up to the record's three blocks at 08:1x UK (the hive landing had re-recorded the batch note only).",
"network_label": "on an island, not a network"
},
"evidence_records": {
@ -15545,7 +15545,7 @@
"cell": "canary:fresh-install",
"manifest_sha": "5d53a591",
"run_id": "canary-202-20261009-01",
"evidence": "tools/ci/canary/1176efb9.json; build-1:/srv/canary/1176efb9/mini/00-verdict.txt; build-1:/srv/canary/1176efb9/lp-4090-11/fleet-block.json",
"evidence": "tools/ci/canary/1176efb9.json; build-1:/srv/canary/1176efb9/mini/00-verdict.txt; build-1:/srv/canary/1176efb9/lp-4090-11/fleet-block.json; build-1:/srv/canary/1176efb9/lp-4090-43/00-verdict.txt",
"in_progress": false,
"coverage": "partial: V6-12's clean-install half (one published object installed fresh, synced, mined, proved and paid on one host per artefact); the cross-host agreement half (node, pool, CPU verifier, each GPU host across activation) is harness:same-work's",
"release_identity": {
@ -15558,8 +15558,8 @@
},
"claim_impact": "INT-07's clean-install half on kit 2 reads FAIL on the fleet canary (the walk bound at the fifth cut); the mac block PASS stands as the Mac entry's evidence; no fleet, hive or windows entry publishes until a record reads PASS on its own block",
"reviewer": "",
"at": "2026-10-09T03:47:40.335Z",
"note": "mac PASS, fleet FAIL at sync (the walk bound at the reference chain's fifth cut under fix 2), hive and windows pending | Kit 2 (tip 1176efb9, node 5d53a591): the mac block PASS under tools/ci/canary-check.sh (the project's macOS machine: synced from empty in 2,016 s, 18 blocks in five minutes at 12.65 MH/s, 0 refusals, shard n/a on Apple silicon, the tip inside ten of the age-adjusted feed, quit in 4 s); the fleet block FAIL at sync (lp-4090-11, 04:04 UK: a fresh 2.0.2 node walls at the reference chain's fifth cut under fix 2's walk bound, 'passed 7200 blocks (2 x epoch_blocks) without meeting a block this executor holds a record of'; the kit ran clean; build-1:/srv/canary/1176efb9/lp-4090-11/fleet-block.json); the hive block reads about 05:30 UK, the windows block on the relay lane's clock. No fleet, hive or windows entry publishes on this record; the Mac entry published on its PASS block at 02:20 UK. Kit 1's 94e4c6ba FAIL (the wedge) stands as that sha's record. The recorder's rule: a measured FAIL on one block is a FAIL on the case. Re-recorded 9 October 2026 04:3x UK with the hive block (lp-4090-43, FAIL at sync on the lost-proof loop) and the re-shaped fleet block (no sync.feed object).",
"at": "2026-10-09T07:18:00.541Z",
"note": "mac PASS (the Mac entry published on it 02:20 UK); fleet FAIL at sync (lp-4090-11, 04:04 UK: the walk bound at the reference chain's fifth cut under fix 2); hive FAIL (lp-4090-43: the lost-proof loop at the first class v5 cut, 'the proofs of 2 carried records are not held yet'); no windows block (the Windows order's default fired: no push without a proved shard). No fleet, hive or windows 2.0.2 entry publishes on this record. | Kit 2 (tip 1176efb9, node 5d53a591): the mac block PASS under tools/ci/canary-check.sh (the project's macOS machine: synced from empty in 2,016 s, 18 blocks in five minutes at 12.65 MH/s, 0 refusals, shard n/a on Apple silicon, the tip inside ten of the age-adjusted feed, quit in 4 s); the fleet block FAIL at sync (lp-4090-11, 04:04 UK: a fresh 2.0.2 node walls at the reference chain's fifth cut under fix 2's walk bound, 'passed 7200 blocks (2 x epoch_blocks) without meeting a block this executor holds a record of'; the kit ran clean; build-1:/srv/canary/1176efb9/lp-4090-11/fleet-block.json); the hive block reads about 05:30 UK, the windows block on the relay lane's clock. No fleet, hive or windows entry publishes on this record; the Mac entry published on its PASS block at 02:20 UK. Kit 1's 94e4c6ba FAIL (the wedge) stands as that sha's record. The recorder's rule: a measured FAIL on one block is a FAIL on the case. Re-recorded 9 October 2026 04:3x UK with the hive block (lp-4090-43, FAIL at sync on the lost-proof loop) and the re-shaped fleet block (no sync.feed object). Cell note brought up to the record's three blocks at 08:1x UK (the hive landing had re-recorded the batch note only).",
"network_label": "on an island, not a network"
}
},

View file

@ -23,20 +23,24 @@ echo "$OVJSON" | python3 -c 'import json,sys; o=json.load(sys.stdin); assert isi
[ "$(strings "$BIN" | grep -c "$COMMIT")" -gt 0 ] || { echo "$BIN is not the $COMMIT node (a 0.3.5 node refuses an override file with fees_v1_activation_daa)"; exit 1; }
cp -p "$OV" "$OV.prev-$(date -u +%Y%m%dT%H%M%SZ)" 2>/dev/null || true
printf '%s\n' "$OVJSON" > "$OV"
# the pid is an igneumd process, never a shell whose command line carries the pattern's text (6 October 2026: pgrep -f matched the
# caller's own zsh -c "..." and the stop waited 11 minutes on it)
stop() { local p; p=$( { for c in $(pgrep -f "$1" || true); do if [ "$(ps -o comm= -p "$c" 2>/dev/null | xargs basename 2>/dev/null)" = igneumd ]; then echo "$c"; fi; done; true; } | head -1 ); if [ -n "$p" ]; then kill -INT "$p"; while kill -0 "$p" 2>/dev/null; do sleep 1; done; fi; } # the filter never fails the pipeline (17:43Z: a trailing caffeinate pid made the loop exit 1 and set -e ended the script before node 1)
# 8 October 2026 (the kill rule's fourth instance, the steward's check): a stop reads a PID FILE and nothing else; never a
# listing by pattern (pgrep -f matched the caller's own shell on 6 October and a pattern sweep killed a running miner tonight).
# Every node this script starts writes $appdir.pid (the nohup child's pid) and the stop takes that file; a node started before
# this script wrote pid files is not stopped here: its pid is written by the operator into the file first.
stop() { local f="$1.pid" p; [ -s "$f" ] || { echo "no pid file $f: nothing stopped (write the running node's pid there first)"; return 0; }; p=$(cat "$f"); if kill -0 "$p" 2>/dev/null; then kill -INT "$p"; while kill -0 "$p" 2>/dev/null; do sleep 1; done; fi; rm -f "$f"; }
lines() { sleep 10; grep -E "Calibrated v1 fees from the override file|Fees on igneum-devnet|Consensus params digest" "$1" | tail -3 || true; }
# the observer first
stop "igneumd --devnet.*observer-v4"
stop /tmp/igneum-devnet/observer-v4
reset_exec /tmp/igneum-devnet/observer-v4
nohup "$BIN" --devnet --nodnsseed --disable-upnp --appdir=/tmp/igneum-devnet/observer-v4 --rpclisten=127.0.0.1:26640 --rpclisten-json=127.0.0.1:28640 --listen=127.0.0.1:26641 \
--addpeer=127.0.0.1:26611 --addpeer=188.245.5.161:26611 --addpeer=192.168.68.67:26611 --override-params-file="$OV" $SNAPARG --nologfiles --yes >> /tmp/igneum-devnet/observer-v4.out 2>&1 &
echo $! > /tmp/igneum-devnet/observer-v4.pid
lines /tmp/igneum-devnet/observer-v4.out
# node 1, under caffeinate as it runs today
stop "igneumd --devnet.*appdir=/tmp/igneum-devnet/node1 "
stop /tmp/igneum-devnet/node1
reset_exec /tmp/igneum-devnet/node1
nohup caffeinate -dims "$BIN" --devnet --nodnsseed --disable-upnp --enable-unsynced-mining --appdir=/tmp/igneum-devnet/node1 --rpclisten=0.0.0.0:26610 --listen=0.0.0.0:26611 --evm-rpclisten=127.0.0.1:26791 \
--addpeer=188.245.5.161:26611 --addpeer=192.168.68.67:26611 --override-params-file="$OV" $SNAPARG --nologfiles --yes >> /tmp/igneum-devnet/node1.out 2>&1 &
echo $! > /tmp/igneum-devnet/node1.pid
lines /tmp/igneum-devnet/node1.out
echo "running now:"; ps -o pid=,lstart=,command= -p "$(pgrep -f '[i]gneumd --devnet' | tr '\n' ',' | sed 's/,$//')" | cut -c1-160
echo "running now (by the pid files):"; for n in observer-v4 node1; do p=$(cat /tmp/igneum-devnet/$n.pid 2>/dev/null); [ -n "$p" ] && ps -o pid=,lstart=,command= -p "$p" | cut -c1-160; done

View file

@ -15,7 +15,7 @@
"profile_hashes": ""
},
"claim_impact": "INT-07's clean-install half on kit 2 reads FAIL on the fleet canary (the walk bound at the fifth cut); the mac block PASS stands as the Mac entry's evidence; no fleet, hive or windows entry publishes until a record reads PASS on its own block",
"note": "Kit 2 (tip 1176efb9, node 5d53a591): the mac block PASS under tools/ci/canary-check.sh (the project's macOS machine: synced from empty in 2,016 s, 18 blocks in five minutes at 12.65 MH/s, 0 refusals, shard n/a on Apple silicon, the tip inside ten of the age-adjusted feed, quit in 4 s); the fleet block FAIL at sync (lp-4090-11, 04:04 UK: a fresh 2.0.2 node walls at the reference chain's fifth cut under fix 2's walk bound, 'passed 7200 blocks (2 x epoch_blocks) without meeting a block this executor holds a record of'; the kit ran clean; build-1:/srv/canary/1176efb9/lp-4090-11/fleet-block.json); the hive block reads about 05:30 UK, the windows block on the relay lane's clock. No fleet, hive or windows entry publishes on this record; the Mac entry published on its PASS block at 02:20 UK. Kit 1's 94e4c6ba FAIL (the wedge) stands as that sha's record. The recorder's rule: a measured FAIL on one block is a FAIL on the case. Re-recorded 9 October 2026 04:3x UK with the hive block (lp-4090-43, FAIL at sync on the lost-proof loop) and the re-shaped fleet block (no sync.feed object).",
"note": "Kit 2 (tip 1176efb9, node 5d53a591): the mac block PASS under tools/ci/canary-check.sh (the project's macOS machine: synced from empty in 2,016 s, 18 blocks in five minutes at 12.65 MH/s, 0 refusals, shard n/a on Apple silicon, the tip inside ten of the age-adjusted feed, quit in 4 s); the fleet block FAIL at sync (lp-4090-11, 04:04 UK: a fresh 2.0.2 node walls at the reference chain's fifth cut under fix 2's walk bound, 'passed 7200 blocks (2 x epoch_blocks) without meeting a block this executor holds a record of'; the kit ran clean; build-1:/srv/canary/1176efb9/lp-4090-11/fleet-block.json); the hive block reads about 05:30 UK, the windows block on the relay lane's clock. No fleet, hive or windows entry publishes on this record; the Mac entry published on its PASS block at 02:20 UK. Kit 1's 94e4c6ba FAIL (the wedge) stands as that sha's record. The recorder's rule: a measured FAIL on one block is a FAIL on the case. Re-recorded 9 October 2026 04:3x UK with the hive block (lp-4090-43, FAIL at sync on the lost-proof loop) and the re-shaped fleet block (no sync.feed object). Cell note brought up to the record's three blocks at 08:1x UK (the hive landing had re-recorded the batch note only).",
"cells": [
{
"cell": "canary:fresh-install",
@ -24,9 +24,9 @@
],
"status": "FAIL",
"method": "team-reported",
"evidence": "tools/ci/canary/1176efb9.json; build-1:/srv/canary/1176efb9/mini/00-verdict.txt; build-1:/srv/canary/1176efb9/lp-4090-11/fleet-block.json",
"evidence": "tools/ci/canary/1176efb9.json; build-1:/srv/canary/1176efb9/mini/00-verdict.txt; build-1:/srv/canary/1176efb9/lp-4090-11/fleet-block.json; build-1:/srv/canary/1176efb9/lp-4090-43/00-verdict.txt",
"network_label": "on an island, not a network",
"note": "mac PASS, fleet FAIL at sync (the walk bound at the reference chain's fifth cut under fix 2), hive and windows pending"
"note": "mac PASS (the Mac entry published on it 02:20 UK); fleet FAIL at sync (lp-4090-11, 04:04 UK: the walk bound at the reference chain's fifth cut under fix 2); hive FAIL (lp-4090-43: the lost-proof loop at the first class v5 cut, 'the proofs of 2 carried records are not held yet'); no windows block (the Windows order's default fired: no push without a proved shard). No fleet, hive or windows 2.0.2 entry publishes on this record."
}
]
}

View file

@ -24,6 +24,15 @@
# only when it is anchored on the exact command line (`^/full/path` or `^command`), is the bracket form, a variable, -x on a
# binary name or -F on a pid file; a bare path, a log name or a word is red. The fix is a pid file or the anchored pattern.
#
# 6. (8 October 2026, 23:4x UK, the fourth instance: the V6-07 sub-lane's scratch socket sweep killed a running miner despite the
# pkill and killall shims, because the shims cover two commands and the class is ANY kill chosen by a pattern) `kill` fed by a
# pattern is flagged wherever it appears: `kill $(pgrep ...)`, `kill $(lsof -t ...)`, `kill $(ps ... | grep ...)`, `fuser -k`,
# `ss`/`netstat`/`lsof` pipelines ending in kill, `| xargs kill`, and a loop that kills pids it did not record
# (`for p in $(pgrep|lsof|ps|ss|netstat ...); do kill`). The allowed forms stay: a recorded pid variable (`kill "$PID"`, `kill $!`),
# the pid file (`kill "$(cat <pidfile>)"`, `kill "$(cut -d' ' -f1 <pidfile>)"`, `pkill -F`), `tools/fleet/fleet-bg.sh stop`, and the
# children of a recorded pid (`pgrep -P "$pid"`: an exact process tree, no pattern).
# The rule covers every tracked script and every job body (the playbooks under tools/fleet and tools/jobs included).
#
# tools/ci/kill-by-name-check.sh # exit 1 with file:line and the reason
# tools/ci/kill-by-name-check.sh --self-test # fires on each banned shape, passes each allowed one
set -euo pipefail
@ -68,10 +77,42 @@ check_line() { # <line> -> prints the reason, returns 1, when the line carrie
fi
if [[ "$code" =~ (^|[^A-Za-z0-9_])ps[[:space:]][^|]*\|[[:space:]]*grep[[:space:]]+(-[A-Za-z]+[[:space:]]+)*(\"[^\"]*\"|\'[^\']*\'|[^[:space:]|;\)]+) ]]; then
pat="${BASH_REMATCH[3]}"; pat="${pat#[\"\']}"; pat="${pat%[\"\']}"
[[ "$pat" == *'$'* ]] && return 0
[[ "$pat" =~ ^\[.\] ]] && return 0
[[ "$pat" == grep ]] && return 0 # `grep -v grep`
echo "ps | grep with a plain literal ($pat): it matches the grep itself; use the bracket form ([${pat:0:1}]${pat:1}) or pgrep -x"; return 1
if ! { [[ "$pat" == *'$'* ]] || [[ "$pat" =~ ^\[.\] ]] || [[ "$pat" == grep ]]; }; then # a variable, the bracket form, `grep -v grep` are fine; rule 6 still reads the line
echo "ps | grep with a plain literal ($pat): it matches the grep itself; use the bracket form ([${pat:0:1}]${pat:1}) or pgrep -x"; return 1
fi
fi
# rule 6: a kill chosen by a pattern (the socket-sweep class): the pids a kill takes come from a recorded variable or a pid file, never
# from pgrep, lsof, fuser, ss, netstat or a ps pipeline, and never through xargs or a loop over such a listing
if [[ "$code" =~ (^|[^A-Za-z0-9_./-])fuser[[:space:]]+(-[A-Za-z]*k|-[A-Za-z]+[[:space:]]+-[A-Za-z]*k) ]]; then
echo "fuser -k: a kill chosen by a socket or file pattern (rule 6, the socket-sweep class); record the pid you start and kill that pid, or use a pid file"; return 1
fi
local xargs_re='[|][[:space:]]*xargs[[:space:]]+(-[A-Za-z0-9]+[[:space:]]+)*kill([[:space:]]|$)'
if [[ "$code" =~ $xargs_re ]]; then
echo "| xargs kill: the pids come from a listing, not from a record (rule 6, the socket-sweep class); kill the pid you recorded or use a pid file"; return 1
fi
local tree_re='[$][(]pgrep[[:space:]]+-P[[:space:]]+("[$][A-Za-z0-9_{}!]+"|[$][A-Za-z0-9_{}!]+|[0-9]+)' # the parent pid is a variable (quoted or bare, $1 and $! included) or a number
local kill_re='(^|[^A-Za-z0-9_./-])kill[[:space:]]+(-[A-Za-z0-9]+[[:space:]]+)*[^[:space:]]*[$][(](pgrep|lsof|fuser|ss|netstat|ps)([[:space:]]|[)])'
local tool=""
if [[ "$code" =~ $kill_re ]]; then
tool="${BASH_REMATCH[3]}"
if ! { [[ "$tool" == pgrep ]] && [[ "$code" =~ $tree_re ]]; }; then
echo "kill \$($tool ...): a kill chosen by a pattern (rule 6, the socket-sweep class); the allowed forms are a recorded pid, \$(cat <pidfile>), \$(cut -d' ' -f1 <pidfile>), pkill -F, fleet-bg.sh stop, pgrep -P <recorded pid>"; return 1
fi
fi
local bt_re='(^|[^A-Za-z0-9_./-])kill[[:space:]]+(-[A-Za-z0-9]+[[:space:]]+)*[^[:space:]]*`(pgrep|lsof|fuser|ss|netstat|ps)[[:space:]]'
if [[ "$code" =~ $bt_re ]]; then
echo "kill \`${BASH_REMATCH[3]} ...\`: a kill chosen by a pattern (rule 6); kill a recorded pid or a pid file's"; return 1
fi
local loop_re='for[[:space:]]+[A-Za-z_][A-Za-z0-9_]*[[:space:]]+in[[:space:]]+[^;]*[$][(](pgrep|lsof|fuser|ss|netstat|ps)([[:space:]]|[)])[^;]*[;][[:space:]]*do[[:space:]].*kill'
if [[ "$code" =~ $loop_re ]]; then
tool="${BASH_REMATCH[1]}"
if ! { [[ "$tool" == pgrep ]] && [[ "$code" =~ $tree_re ]]; }; then # pgrep -P <recorded pid> walks that pid's own children: an exact tree, no pattern (allowed)
echo "a loop over \$($tool ...) that kills: the pids were listed, not recorded (rule 6, the socket-sweep class)"; return 1
fi
fi
local pipe_re='(^|[^A-Za-z0-9_./-])(pgrep|lsof|ss|netstat)[[:space:]][^|]*[|].*kill([[:space:]]|$)'
if [[ "$code" =~ $pipe_re ]] && [[ "$code" != *"xargs"* ]]; then
echo "a ${BASH_REMATCH[2]} pipeline ending in kill: a kill chosen by a pattern (rule 6, the socket-sweep class); record the pid or use a pid file"; return 1
fi
return 0
}
@ -85,6 +126,14 @@ if [ "${1:-}" = "--self-test" ]; then
'pkill -x node'
'pkill -f "[p]re-push.sh"'
'pgrep -f merge-to-master'
'kill $(pgrep -x igneum-miner)'
'kill -9 $(lsof -t -i :26611)'
'fuser -k 26611/tcp'
'lsof -t -i :26611 | xargs kill'
'ss -ltnp | grep 26611 | awk "{print $7}" | cut -d, -f2 | xargs kill -9'
'for p in $(pgrep -f "[i]gneum-worker"); do kill "$p"; done'
'pids=$(ps aux | grep "[w]orker" | awk "{print $2}"); kill $pids 2>/dev/null; kill $(pgrep -x worker)'
'kill `pgrep -x igneumd`'
'pkill -f "^igneum-gate:"'
'pkill cargo'
'pkill -f igneum-roll.log'
@ -108,6 +157,15 @@ if [ "${1:-}" = "--self-test" ]; then
'pkill -P "$keeper"'
'pkill -x igneumd'
'pgrep -f "[i]gneumd" >/dev/null'
'kill "$(cut -d'"'"' '"'"' -f1 "$PIDFILE")"'
'kill "$(cat /srv/canary/miner.pid)"'
'kill "$MINER_PID"; wait "$MINER_PID"'
'kill $! 2>/dev/null'
'bash tools/fleet/fleet-bg.sh stop miner-1'
'pkill -F /srv/run/miner.pid'
'for p in "${RECORDED[@]}"; do kill "$p"; done'
'for c in $(pgrep -P "$1" 2>/dev/null); do kill -TERM "$c"; done'
'kill $(pgrep -P $PID)'
"pkill -f '[n]ode tools/fleet/wave.mjs'"
'pgrep -x igneumd'
'pkill -x igneum-miner'
@ -127,7 +185,7 @@ if [ "${1:-}" = "--self-test" ]; then
)
for l in "${bad[@]}"; do if check_line "$l" >/dev/null; then echo "self-test failed: accepted: $l"; fails=1; fi; done
for l in "${good[@]}"; do if ! out="$(check_line "$l")"; then echo "self-test failed: rejected: $l ($out)"; fails=1; fi; done
[ "$fails" = 0 ] && echo "self-test passed: ${#bad[@]} banned shapes fail (a log or out file name under pkill/pgrep, a plain literal under -f, the second pkill on a line, ps | grep with a literal); ${#good[@]} allowed shapes pass (bracket form, -x, -F pidfile, kill \$(cat pidfile), a variable, a full path, comments)"
[ "$fails" = 0 ] && echo "self-test passed: ${#bad[@]} banned shapes fail (a kill fed by pgrep, lsof, fuser -k, an ss or netstat pipeline, xargs kill or a loop over a listing (rule 6); a log or out file name under pkill/pgrep, a plain literal under -f, the second pkill on a line, ps | grep with a literal); ${#good[@]} allowed shapes pass (bracket form, -x, -F pidfile, kill \$(cat pidfile), a variable, a full path, comments)"
exit $fails
fi
@ -137,6 +195,6 @@ fail=0; n=0
while IFS= read -r hit; do
f="${hit%%:*}"; rest="${hit#*:}"; ln="${rest%%:*}"; line="${rest#*:}"; n=$((n + 1))
if ! why="$(check_line "$line")"; then echo "kill-by-name: $f:$ln: $why"; fail=1; fi
done < <(git grep -nE '(^|[^A-Za-z0-9_./-])(pgrep|pkill)([[:space:]]|$)|(^|[^A-Za-z0-9_])ps[[:space:]][^|]*\|[[:space:]]*grep' -- '*.sh' '*.bash' '*.mjs' '*.js' '*.py' '*.ps1' '*.bat' ':!vendor/**' ':!**/node_modules/**' ':!tools/ci/kill-by-name-check.sh' || true)
[ "$fail" = 0 ] && echo "kill-by-name: $n pgrep/pkill/ps-grep lines, none kills or finds a process by a plain name or a file name"
done < <(git grep -nE '(^|[^A-Za-z0-9_./-])(pgrep|pkill|fuser)([[:space:]]|$)|(^|[^A-Za-z0-9_])ps[[:space:]][^|]*\|[[:space:]]*grep|(^|[^A-Za-z0-9_./-])kill([[:space:]]|$)|xargs[[:space:]]+(-[A-Za-z0-9]+[[:space:]]+)*kill' -- '*.sh' '*.bash' '*.mjs' '*.js' '*.py' '*.ps1' '*.bat' '*.yml' '*.yaml' '*.json' ':!vendor/**' ':!**/node_modules/**' ':!tools/ci/kill-by-name-check.sh' || true)
[ "$fail" = 0 ] && echo "kill-by-name: $n pgrep/pkill/ps-grep/kill lines, none kills or finds a process by a plain name, a file name or a pattern-chosen pid"
exit $fail