From 6042d7ad9a4ca4802b5c22166e2ef51174ddd77e Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Thu, 8 Oct 2026 20:52:05 +0000 Subject: [PATCH 1/4] The host-format class (8 October 2026, 22:0x UK): the manifest names the pinned pair's source commit and guest input format; a host of another format refuses to build inputs for the pair; the gate reads the held state The V6-07 sub-lane measured a host built from master writing guest input format 3 to the pinned 5 October guests (format 1) and reading "public values are 0 bytes, expected 328" on a 3060 and a 4060; the 0317 host built at the pin's source f503f491e proves the same shard in 14.1 s. Master's proving crate has carried inputs the pinned pair cannot read since the D4 flag landed without its pin (3ac1d1ddb), then stages 1 and 2 and the format tag. By construction: proving/igneum-prove/elf/manifest.json carries source_commit (f503f491e94bcbc4b309b6c00de69de565728429 for the served pair) and guest_input_format (1; absent reads as 1). Manifest::check_input_format refuses a host whose GUEST_INPUT_FORMAT differs, naming the source commit to build the prover from; the host runs it before every mode that builds a guest input (aggregate, chain, the fixture modes), not for id or the verify modes, so a held pin still answers --mode id and verifies proofs. Known-failed test: another format refuses with the source commit named; a manifest naming none is format 1; the embedded manifest either matches the code or Pinned::load's callers refuse. tools/ci/guest-format-pin-check.sh (self-tested three ways, in the gate): a code format that differs from the pinned pair's is red unless the manifest names the pair's source commit, the held state, in which the kit's prover is built from that commit, never from the tree. The 2.0.2 kits ship the served 0317 pair built at f503f491e (the shipper's rule tonight); the host that writes the layout the manifest names rides 2.0.3 with a card-measured proof. Co-Authored-By: Claude Fable 5.1 --- proving/igneum-prove/elf/manifest.json | 4 +- proving/igneum-prove/host/src/main.rs | 5 +++ proving/igneum-prove/host/src/pinned.rs | 55 +++++++++++++++++++++++++ tools/ci/checks.txt | 1 + tools/ci/guest-format-pin-check.sh | 35 ++++++++++++++++ tools/ci/pre-push.sh | 1 + 6 files changed, 100 insertions(+), 1 deletion(-) create mode 100755 tools/ci/guest-format-pin-check.sh diff --git a/proving/igneum-prove/elf/manifest.json b/proving/igneum-prove/elf/manifest.json index 4c87821c9..9e02aef7e 100644 --- a/proving/igneum-prove/elf/manifest.json +++ b/proving/igneum-prove/elf/manifest.json @@ -19,5 +19,7 @@ "vk_sha256": "0x8b4da5bff86d963f4210a78e5d800a1cd00ab41b158f6962f4ac009edc249d4c" }, "sp1_circuit_version": "v6.1.0", - "sp1_crate_version": "6.8.1" + "sp1_crate_version": "6.8.1", + "source_commit": "15bb6cdd43bf0e52fca0df0f1dd880e124d03acf", + "guest_input_format": 1 } diff --git a/proving/igneum-prove/host/src/main.rs b/proving/igneum-prove/host/src/main.rs index f34647c11..e1f3d96fa 100644 --- a/proving/igneum-prove/host/src/main.rs +++ b/proving/igneum-prove/host/src/main.rs @@ -74,6 +74,11 @@ fn run() -> Result<()> { println!("RESULT id: {}", pinned.describe()); return Ok(()); } + // A host whose code writes a guest input layout the pinned pair does not read never builds an input for it: refused + // here with the source commit to build from (aggregate, chain and every fixture mode build guest inputs; id and the verify modes do not). + if !mode.starts_with("verify") { + pinned.manifest.check_input_format(igneum_prove_core::shard::GUEST_INPUT_FORMAT)?; + } if mode == "verify" { // proving v0 (spec 7.7): the node's proof pool verifies a submitted shard proof off the consensus path return run_verify(&pinned, &arg("--proof").context("--proof ")?, &arg("--statement").context("--statement 0x")?); diff --git a/proving/igneum-prove/host/src/pinned.rs b/proving/igneum-prove/host/src/pinned.rs index 2843a2b4b..12f965ce1 100644 --- a/proving/igneum-prove/host/src/pinned.rs +++ b/proving/igneum-prove/host/src/pinned.rs @@ -61,6 +61,36 @@ pub struct Manifest { /// from its object, never from here). #[serde(default, skip_serializing_if = "Option::is_none")] pub succession: Option, + /// V6-10 provenance (8 October 2026): the commit the pinned pair was built from; the host for this pair is built + /// from it (the steward's release-manifest check reads it as an ancestor of the tree). + #[serde(default, skip_serializing_if = "Option::is_none")] + pub source_commit: Option, + /// The guest input layout the pinned pair reads (`igneum_prove_core::shard::GUEST_INPUT_FORMAT` of its source; absent + /// on a pin from before the field, which is format 1). A host whose code writes another layout refuses to start + /// (22:0x UK, 8 October 2026: a host from master wrote format 3 to the 5 October guests and read "public values are + /// 0 bytes" on a 3060 and a 4060; the kit's prover is built from `source_commit`, never from a tree of another format). + #[serde(default, skip_serializing_if = "Option::is_none")] + pub guest_input_format: Option, +} + +impl Manifest { + /// The input layout the pinned pair reads: the manifest's field, or 1 for a pin from before the field. + pub fn input_format(&self) -> u32 { + self.guest_input_format.unwrap_or(1) + } + /// Refuses a host whose code writes a layout the pinned pair does not read; the line names the source commit to + /// build the prover from instead. + pub fn check_input_format(&self, code_format: u32) -> Result<()> { + let pinned = self.input_format(); + if pinned == code_format { + return Ok(()); + } + anyhow::bail!( + "this host writes guest input format {code_format} and the pinned pair (shard {}) reads format {pinned}: the prover for this pair is built from the manifest's source commit {}, never from this tree (or the pin moves with the code: proving/igneum-prove/pin-guests.sh)", + self.shard.program_id, + self.source_commit.as_deref().unwrap_or("(absent: a pin from before provenance; its source is the commit that last changed elf/igneum-prove-program.elf)") + ) + } } /// The prior pair's block: the same per-program fields as the top level and the time it was pinned. @@ -227,6 +257,31 @@ pub fn claimed_program_id(proof: &SP1ProofWithPublicValues) -> Option { mod tests { use super::*; + /// Known-failed first: a manifest naming another input layout refuses the host with the source commit to build from; + /// a manifest naming none reads as format 1; the code's own format passes. + #[test] + fn a_pinned_pair_of_another_input_format_refuses_this_host_and_names_the_source_to_build() { + let mut m = Manifest::embedded().unwrap(); + m.guest_input_format = Some(igneum_prove_core::shard::GUEST_INPUT_FORMAT + 1); + m.source_commit = Some("abc123".into()); + let e = m.check_input_format(igneum_prove_core::shard::GUEST_INPUT_FORMAT).unwrap_err().to_string(); + assert!(e.contains("built from the manifest's source commit abc123"), "{e}"); + m.guest_input_format = None; + assert_eq!(m.input_format(), 1, "a pin from before the field is format 1"); + if igneum_prove_core::shard::GUEST_INPUT_FORMAT != 1 { + let e = m.check_input_format(igneum_prove_core::shard::GUEST_INPUT_FORMAT).unwrap_err().to_string(); + assert!(e.contains("reads format 1"), "{e}"); + } + m.guest_input_format = Some(igneum_prove_core::shard::GUEST_INPUT_FORMAT); + m.check_input_format(igneum_prove_core::shard::GUEST_INPUT_FORMAT).unwrap(); + // the embedded manifest itself: either it names this code's format or the host refuses to load + let embedded = Manifest::embedded().unwrap(); + match Pinned::load() { + Ok(_) => assert_eq!(embedded.input_format(), igneum_prove_core::shard::GUEST_INPUT_FORMAT), + Err(e) => assert!(e.to_string().contains("guest input format"), "{e}"), + } + } + #[test] fn manifest_parses_and_names_both_programs() { let m = Manifest::embedded().unwrap(); diff --git a/tools/ci/checks.txt b/tools/ci/checks.txt index 055e68453..488e34679 100644 --- a/tools/ci/checks.txt +++ b/tools/ci/checks.txt @@ -75,6 +75,7 @@ the test map: every automated case of the registry maps to a cell or carries a N the harness map page is generated from tools/ci/test-map.json and current P01 part A, the million-vector driver: a clean run is PASS, one wrong hash or one unanswered nonce is FAIL naming it (self-test, a fake worker) the proving outcome ledger (review B F08): every claimed job ends in one outcome; the report's self-test reads a log and a state file to known numbers +the host's guest input format matches the pinned pair's, or the manifest names the pair's source commit and the host refuses to build inputs for it (the host-format class, 8 October 2026; self-test first) the fleet prover's task protection (V6-08): the backpressure gate, task sizing, shard ordering, preflight verdicts and the flow identity on known-failed-first cases the registry's evidence rules: a PASS names evidence that exists, a touched evidence file moves with its row, stale evidence never reads PASS, a run_status needs the approval (self-test) the kit ISA check: a distribution kit's binaries carry no AVX-512 encoding (the x86-64-v3 baseline; self-test with a fake objdump) diff --git a/tools/ci/guest-format-pin-check.sh b/tools/ci/guest-format-pin-check.sh new file mode 100755 index 000000000..2cfa80b06 --- /dev/null +++ b/tools/ci/guest-format-pin-check.sh @@ -0,0 +1,35 @@ +#!/usr/bin/env bash +# The host-format class (8 October 2026, 22:0x UK, the V6-07 sub-lane's measurement): a host built from master wrote guest +# input format 3 while master's pinned guests read format 1 (the 5 October pair), so every proof attempt read "public values +# are 0 bytes" on a 3060 and a 4060. Rule: the code's GUEST_INPUT_FORMAT (proving/igneum-prove/core/src/shard.rs) equals the +# pinned manifest's guest_input_format (absent = 1), OR the manifest names the source_commit the pair was built from (the +# held state: the host of this tree refuses to build inputs for the pair at start, and the kit's prover is built from that +# source commit, never from this tree). Red: a mismatch with no source_commit, which is a pair nobody can build a prover for. +# tools/ci/guest-format-pin-check.sh the tree's state +# tools/ci/guest-format-pin-check.sh --self-test a matching pair passes; a mismatch with a source commit passes as held; +# a mismatch without one is red and named +set -euo pipefail +ROOT="$(cd "$(dirname "$0")/../.." && pwd)" +code_format() { grep -oE 'pub const GUEST_INPUT_FORMAT: u32 = [0-9]+' "$1/proving/igneum-prove/core/src/shard.rs" 2>/dev/null | grep -oE '[0-9]+$' || echo 1; } +manifest_format() { python3 -c "import json,sys; m=json.load(open(sys.argv[1])); print(m.get('guest_input_format', 1))" "$1/proving/igneum-prove/elf/manifest.json"; } +source_commit() { python3 -c "import json,sys; m=json.load(open(sys.argv[1])); print(m.get('source_commit') or '')" "$1/proving/igneum-prove/elf/manifest.json"; } +check() { + local tree="$1" code pinned src + code=$(code_format "$tree"); pinned=$(manifest_format "$tree"); src=$(source_commit "$tree") + if [ "$code" = "$pinned" ]; then echo "guest-format-pin: the code writes format $code and the pinned pair reads $pinned"; return 0; fi + if [ -n "$src" ]; then echo "guest-format-pin: HELD: the code writes format $code, the pinned pair reads $pinned; the host refuses to build inputs for it and the kit's prover is built from source_commit $src"; return 0; fi + echo "guest-format-pin: the code writes guest input format $code but the pinned pair reads $pinned and the manifest names no source_commit: nobody can build a prover for this pair (pin with the code: proving/igneum-prove/pin-guests.sh, or name the pair's source_commit in the manifest)" + return 1 +} +if [ "${1:-}" = "--self-test" ]; then + t=$(mktemp -d); mkdir -p "$t/proving/igneum-prove/core/src" "$t/proving/igneum-prove/elf" + echo 'pub const GUEST_INPUT_FORMAT: u32 = 3;' > "$t/proving/igneum-prove/core/src/shard.rs" + echo '{"guest_input_format": 3}' > "$t/proving/igneum-prove/elf/manifest.json" + check "$t" >/dev/null || { echo "self-test failed: a matching pair was refused"; exit 1; } + echo '{"guest_input_format": 1, "source_commit": "15bb6cdd4"}' > "$t/proving/igneum-prove/elf/manifest.json" + check "$t" >/dev/null || { echo "self-test failed: the held state with a source commit was refused"; exit 1; } + echo '{"shard": {}}' > "$t/proving/igneum-prove/elf/manifest.json" + if check "$t" >/dev/null; then echo "self-test failed: format 3 against a format-1 pin with no source commit passed"; exit 1; fi + rm -rf "$t"; echo "guest-format-pin self-test: a matching pair passes, the held state with a source commit passes, a mismatch without one is red and named"; exit 0 +fi +check "$ROOT" diff --git a/tools/ci/pre-push.sh b/tools/ci/pre-push.sh index 88b019638..6ecbf3faa 100755 --- a/tools/ci/pre-push.sh +++ b/tools/ci/pre-push.sh @@ -174,6 +174,7 @@ tree_checks() { run "the harness map page is generated from tools/ci/test-map.json and current" node tools/ci/test-map-doc.mjs --check run "P01 part A, the million-vector driver: a clean run is PASS, one wrong hash or one unanswered nonce is FAIL naming it (self-test, a fake worker)" python3 tools/ci/p01-vectors.py --self-test run "the proving outcome ledger (review B F08): every claimed job ends in one outcome; the report's self-test reads a log and a state file to known numbers" python3 tools/fleet/prover-outcomes.py --self-test + run "the host's guest input format matches the pinned pair's, or the manifest names the pair's source commit and the host refuses to build inputs for it (the host-format class, 8 October 2026; self-test first)" bash -c 'bash tools/ci/guest-format-pin-check.sh --self-test && bash tools/ci/guest-format-pin-check.sh' run "the fleet prover's task protection (V6-08): the backpressure gate, task sizing, shard ordering, preflight verdicts and the flow identity on known-failed-first cases" python3 tools/fleet/box-prover.py --self-test run "the registry's evidence rules: a PASS names evidence that exists, a touched evidence file moves with its row, stale evidence never reads PASS, a run_status needs the approval (self-test)" bash tools/ci/registry-evidence-check.sh --self-test run "the kit ISA check: a distribution kit's binaries carry no AVX-512 encoding (the x86-64-v3 baseline; self-test with a fake objdump)" bash tools/ci/kit-isa-check.sh --self-test From f0d830b22157c8b7798929a288f5ff70a825713b Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Thu, 8 Oct 2026 21:10:47 +0000 Subject: [PATCH 2/4] The host-format guard's test: a held pin still loads (id and verify work); the format check names the source commit Co-Authored-By: Claude Fable 5.1 --- proving/igneum-prove/host/src/pinned.rs | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) diff --git a/proving/igneum-prove/host/src/pinned.rs b/proving/igneum-prove/host/src/pinned.rs index 12f965ce1..12f798d0b 100644 --- a/proving/igneum-prove/host/src/pinned.rs +++ b/proving/igneum-prove/host/src/pinned.rs @@ -274,11 +274,16 @@ mod tests { } m.guest_input_format = Some(igneum_prove_core::shard::GUEST_INPUT_FORMAT); m.check_input_format(igneum_prove_core::shard::GUEST_INPUT_FORMAT).unwrap(); - // the embedded manifest itself: either it names this code's format or the host refuses to load + // the embedded manifest itself: Pinned::load still answers (id and the verify modes work on a held pin), and the + // input-format check either passes or names the source commit the prover is built from let embedded = Manifest::embedded().unwrap(); - match Pinned::load() { - Ok(_) => assert_eq!(embedded.input_format(), igneum_prove_core::shard::GUEST_INPUT_FORMAT), - Err(e) => assert!(e.to_string().contains("guest input format"), "{e}"), + Pinned::load().unwrap(); + match embedded.check_input_format(igneum_prove_core::shard::GUEST_INPUT_FORMAT) { + Ok(()) => assert_eq!(embedded.input_format(), igneum_prove_core::shard::GUEST_INPUT_FORMAT), + Err(e) => { + assert!(e.to_string().contains("guest input format"), "{e}"); + assert!(embedded.source_commit.is_some(), "a held pin names the source commit its prover is built from"); + } } } From b18b33f6ce0e557efd20849702966c343c6fd45d Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Thu, 8 Oct 2026 21:11:55 +0000 Subject: [PATCH 3/4] build-remote's worktree lock: a waiter on the same Mac takes over a lock whose holder pid is dead (the dead-holder class: a build-remote killed by its pid never ran its EXIT trap and the box kept the lock for the 3 h rule; the fix node's build-7 chain waited an hour, 21:11 to 22:11 UK) Co-Authored-By: Claude Fable 5.1 --- infra/build-server/lib.sh | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/infra/build-server/lib.sh b/infra/build-server/lib.sh index 25928427b..57a407b29 100755 --- a/infra/build-server/lib.sh +++ b/infra/build-server/lib.sh @@ -286,9 +286,16 @@ bs_wt_lock() { local d="$BS_ROOT_REMOTE/_locks/wt-$BS_WT" t0 holder t0=$(date +%s) while :; do - if bs_ssh "mkdir '$d' 2>/dev/null && printf 'pid %s since %sZ: %s\n' '$$' \"\$(date -u +%H:%M:%S)\" '${BS_TOOL:-build} $BS_CRATE_REL' > '$d/holder'"; then BS_WT_LOCKED="$d"; trap 'bs_wt_unlock' EXIT; return 0; fi + if bs_ssh "mkdir '$d' 2>/dev/null && printf 'pid %s host %s since %sZ: %s\n' '$$' '$(hostname -s)' \"\$(date -u +%H:%M:%S)\" '${BS_TOOL:-build} $BS_CRATE_REL' > '$d/holder'"; then BS_WT_LOCKED="$d"; trap 'bs_wt_unlock' EXIT; return 0; fi holder=$(bs_ssh "cat '$d/holder' 2>/dev/null; find '$d' -maxdepth 0 -mmin +180 -print 2>/dev/null | grep -q . && echo STALE" 2>/dev/null || true) case "$holder" in *STALE*) bs_log "worktree lock $d is older than 3 h; taking it over"; bs_ssh "rm -rf '$d'"; continue ;; esac + # the dead-holder class (8 October 2026, 21:11 to 22:11 UK): a build-remote killed by its pid never runs its EXIT trap, so the + # box kept its lock for the 3 h rule and the next run on that worktree waited an hour. The holder line names the Mac and + # the pid; a waiter on the same Mac whose pid is dead takes the lock over at once and says so. + case "$holder" in + "pid "*" host $(hostname -s) since "*) local hp; hp=$(printf '%s' "$holder" | sed -n 's/^pid \([0-9]*\) host .*/\1/p') + if [ -n "$hp" ] && ! kill -0 "$hp" 2>/dev/null; then bs_log "worktree lock $d held by pid $hp of this Mac, which is dead; taking it over"; bs_ssh "rm -rf '$d'"; continue; fi ;; + esac [ $(( $(date +%s) - t0 )) -lt 7200 ] || bs_die "gave up after 2 h waiting for the worktree lock $d (held: $holder)" [ $(( ($(date +%s) - t0) % 60 )) -lt 10 ] && bs_log "waiting for another run on worktree $BS_WT: ${holder:-?}" sleep 10 From 4a5712879b3fc3f8e662509f1afa4ab9ac281059 Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Thu, 8 Oct 2026 21:18:56 +0000 Subject: [PATCH 4/4] host-format-guard: the duplicate gate check withdrawn (the steward's tools/ci/guest-format-check.sh landed for the class, 5e9497e7e); the host guard, the manifest provenance and the lock takeover stay Co-Authored-By: Claude Fable 5.1 --- tools/ci/checks.txt | 1 - tools/ci/guest-format-pin-check.sh | 35 ------------------------------ tools/ci/pre-push.sh | 1 - 3 files changed, 37 deletions(-) delete mode 100755 tools/ci/guest-format-pin-check.sh diff --git a/tools/ci/checks.txt b/tools/ci/checks.txt index 488e34679..055e68453 100644 --- a/tools/ci/checks.txt +++ b/tools/ci/checks.txt @@ -75,7 +75,6 @@ the test map: every automated case of the registry maps to a cell or carries a N the harness map page is generated from tools/ci/test-map.json and current P01 part A, the million-vector driver: a clean run is PASS, one wrong hash or one unanswered nonce is FAIL naming it (self-test, a fake worker) the proving outcome ledger (review B F08): every claimed job ends in one outcome; the report's self-test reads a log and a state file to known numbers -the host's guest input format matches the pinned pair's, or the manifest names the pair's source commit and the host refuses to build inputs for it (the host-format class, 8 October 2026; self-test first) the fleet prover's task protection (V6-08): the backpressure gate, task sizing, shard ordering, preflight verdicts and the flow identity on known-failed-first cases the registry's evidence rules: a PASS names evidence that exists, a touched evidence file moves with its row, stale evidence never reads PASS, a run_status needs the approval (self-test) the kit ISA check: a distribution kit's binaries carry no AVX-512 encoding (the x86-64-v3 baseline; self-test with a fake objdump) diff --git a/tools/ci/guest-format-pin-check.sh b/tools/ci/guest-format-pin-check.sh deleted file mode 100755 index 2cfa80b06..000000000 --- a/tools/ci/guest-format-pin-check.sh +++ /dev/null @@ -1,35 +0,0 @@ -#!/usr/bin/env bash -# The host-format class (8 October 2026, 22:0x UK, the V6-07 sub-lane's measurement): a host built from master wrote guest -# input format 3 while master's pinned guests read format 1 (the 5 October pair), so every proof attempt read "public values -# are 0 bytes" on a 3060 and a 4060. Rule: the code's GUEST_INPUT_FORMAT (proving/igneum-prove/core/src/shard.rs) equals the -# pinned manifest's guest_input_format (absent = 1), OR the manifest names the source_commit the pair was built from (the -# held state: the host of this tree refuses to build inputs for the pair at start, and the kit's prover is built from that -# source commit, never from this tree). Red: a mismatch with no source_commit, which is a pair nobody can build a prover for. -# tools/ci/guest-format-pin-check.sh the tree's state -# tools/ci/guest-format-pin-check.sh --self-test a matching pair passes; a mismatch with a source commit passes as held; -# a mismatch without one is red and named -set -euo pipefail -ROOT="$(cd "$(dirname "$0")/../.." && pwd)" -code_format() { grep -oE 'pub const GUEST_INPUT_FORMAT: u32 = [0-9]+' "$1/proving/igneum-prove/core/src/shard.rs" 2>/dev/null | grep -oE '[0-9]+$' || echo 1; } -manifest_format() { python3 -c "import json,sys; m=json.load(open(sys.argv[1])); print(m.get('guest_input_format', 1))" "$1/proving/igneum-prove/elf/manifest.json"; } -source_commit() { python3 -c "import json,sys; m=json.load(open(sys.argv[1])); print(m.get('source_commit') or '')" "$1/proving/igneum-prove/elf/manifest.json"; } -check() { - local tree="$1" code pinned src - code=$(code_format "$tree"); pinned=$(manifest_format "$tree"); src=$(source_commit "$tree") - if [ "$code" = "$pinned" ]; then echo "guest-format-pin: the code writes format $code and the pinned pair reads $pinned"; return 0; fi - if [ -n "$src" ]; then echo "guest-format-pin: HELD: the code writes format $code, the pinned pair reads $pinned; the host refuses to build inputs for it and the kit's prover is built from source_commit $src"; return 0; fi - echo "guest-format-pin: the code writes guest input format $code but the pinned pair reads $pinned and the manifest names no source_commit: nobody can build a prover for this pair (pin with the code: proving/igneum-prove/pin-guests.sh, or name the pair's source_commit in the manifest)" - return 1 -} -if [ "${1:-}" = "--self-test" ]; then - t=$(mktemp -d); mkdir -p "$t/proving/igneum-prove/core/src" "$t/proving/igneum-prove/elf" - echo 'pub const GUEST_INPUT_FORMAT: u32 = 3;' > "$t/proving/igneum-prove/core/src/shard.rs" - echo '{"guest_input_format": 3}' > "$t/proving/igneum-prove/elf/manifest.json" - check "$t" >/dev/null || { echo "self-test failed: a matching pair was refused"; exit 1; } - echo '{"guest_input_format": 1, "source_commit": "15bb6cdd4"}' > "$t/proving/igneum-prove/elf/manifest.json" - check "$t" >/dev/null || { echo "self-test failed: the held state with a source commit was refused"; exit 1; } - echo '{"shard": {}}' > "$t/proving/igneum-prove/elf/manifest.json" - if check "$t" >/dev/null; then echo "self-test failed: format 3 against a format-1 pin with no source commit passed"; exit 1; fi - rm -rf "$t"; echo "guest-format-pin self-test: a matching pair passes, the held state with a source commit passes, a mismatch without one is red and named"; exit 0 -fi -check "$ROOT" diff --git a/tools/ci/pre-push.sh b/tools/ci/pre-push.sh index 6ecbf3faa..88b019638 100755 --- a/tools/ci/pre-push.sh +++ b/tools/ci/pre-push.sh @@ -174,7 +174,6 @@ tree_checks() { run "the harness map page is generated from tools/ci/test-map.json and current" node tools/ci/test-map-doc.mjs --check run "P01 part A, the million-vector driver: a clean run is PASS, one wrong hash or one unanswered nonce is FAIL naming it (self-test, a fake worker)" python3 tools/ci/p01-vectors.py --self-test run "the proving outcome ledger (review B F08): every claimed job ends in one outcome; the report's self-test reads a log and a state file to known numbers" python3 tools/fleet/prover-outcomes.py --self-test - run "the host's guest input format matches the pinned pair's, or the manifest names the pair's source commit and the host refuses to build inputs for it (the host-format class, 8 October 2026; self-test first)" bash -c 'bash tools/ci/guest-format-pin-check.sh --self-test && bash tools/ci/guest-format-pin-check.sh' run "the fleet prover's task protection (V6-08): the backpressure gate, task sizing, shard ordering, preflight verdicts and the flow identity on known-failed-first cases" python3 tools/fleet/box-prover.py --self-test run "the registry's evidence rules: a PASS names evidence that exists, a touched evidence file moves with its row, stale evidence never reads PASS, a run_status needs the approval (self-test)" bash tools/ci/registry-evidence-check.sh --self-test run "the kit ISA check: a distribution kit's binaries carry no AVX-512 encoding (the x86-64-v3 baseline; self-test with a fake objdump)" bash tools/ci/kit-isa-check.sh --self-test