diff --git a/tools/ci/playbook-quit-check.sh b/tools/ci/playbook-quit-check.sh index 20c7713d5..b0c178f85 100755 --- a/tools/ci/playbook-quit-check.sh +++ b/tools/ci/playbook-quit-check.sh @@ -25,11 +25,11 @@ if [ "${1:-}" = "--self-test" ]; then if ! check_file "$t/good.ps1"; then echo "self-test FAILED: the good playbook failed"; exit 1; fi rm -rf "$t"; echo "self-test passed: the installed app's URL file with a quit fails, a scratch URL file passes"; exit 0 fi -# allowed senders: the installer's own stop step (the update-now path the rule names), and, pending the rule owner's -# word (6 October 2026, 15:10 UTC): tools/proving-v1/pc2-agg-cost.ps1 and its restore step pc2-agg-cost-restore.ps1, which switch the 5090 off through /api/cards -# and falls back to /api/pause with /api/resume in its finally block (the aggregation-cost agent's measurement; the -# rule's letter forbids pause and resume of the installed app, its owner decides whether a card switch's fallback is one) -ALLOW='^(packaging/windows/stop-igneum\.ps1|tools/proving-v1/pc2-agg-cost\.ps1|tools/proving-v1/pc2-agg-cost-restore\.ps1)$' +# the one allowed sender is the installer's own stop step (the update-now path the rule names). Ruled 6 October 2026, +# 15:30 UTC: a job script never pauses or resumes the installed app's miners through /api/pause or /api/resume, not even +# as a fallback with a finally block (a script that dies before its finally leaves the box paused unattended); the +# job runner's --stop-miners is the sanctioned way (it stops them around the job and restarts them on any exit). +ALLOW='^packaging/windows/stop-igneum\.ps1$' fail=0 while IFS= read -r f; do [[ "$f" =~ $ALLOW ]] && continue; check_file "$f" || fail=1; done < <(git ls-files 'relay/playbooks/**' 'tools/windows/**' 'tools/proving-v1/**' 'packaging/**' | grep -E '\.(ps1|sh)$') [ "$fail" = 0 ] && echo "playbook-quit: no playbook quits, pauses or resumes the installed app"