Site deploy: master only (no branch or commit argument) and the post-deploy checks before the edge time (main, 7 Oct 2026 22:1x BST): /api/live network == igneum-devnet-3, the launch-first chip line and the git.igneum.network link on the index, \"Not legal advice\" on the litepaper, at least 30 /miners rows; any mismatch prints DEPLOY RED <field> and exits 1; --self-test-checks known-failed first (a wrong network, a missing string). push-inputs.sh honours IGNEUM_WORKERS_DIR and IGNEUM_NODE_SRC

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
igneum-labs 2026-10-07 21:16:45 +00:00
parent 76fd6b0bc8
commit 786fcdbad8
2 changed files with 46 additions and 4 deletions

View file

@ -54,13 +54,18 @@ for dll in lib/libstdc++-6.dll lib/libgcc_s_seh-1.dll bin/libwinpthread-1.dll; d
else echo "note: $name not in the mingw toolchain (the node exe is linked -static, so it may not need it)"; fi
done
"$(dirname "$0")/check-runtime-dlls.sh" "$STAGE"
if [ -f "$NVRTC_DIR/igneum-worker-cuda.exe" ]; then
# IGNEUM_WORKERS_DIR (7 October 2026, the 0.3.23 re-push from a worktree without proto-cuda/nvrtc builds): a flat folder holding the
# prebuilt workers, the NVRTC DLLs, the licence texts and the telemetry exe, taken ahead of the repository paths (make-payload.sh's rule)
if [ -n "${IGNEUM_WORKERS_DIR:-}" ] && [ -d "$IGNEUM_WORKERS_DIR" ]; then
for f in "$IGNEUM_WORKERS_DIR"/igneum-worker-*.exe "$IGNEUM_WORKERS_DIR"/igneum-gpu-telemetry.exe "$IGNEUM_WORKERS_DIR"/nvrtc*.dll "$IGNEUM_WORKERS_DIR"/LICENSE-*.txt "$IGNEUM_WORKERS_DIR"/THIRD-PARTY.md; do [ -f "$f" ] && cp "$f" "$STAGE/"; done
echo "workers from IGNEUM_WORKERS_DIR: $(cd "$STAGE" && ls igneum-worker-*.exe igneum-gpu-telemetry.exe nvrtc*.dll 2>/dev/null | tr '\n' ' ')"
elif [ -f "$NVRTC_DIR/igneum-worker-cuda.exe" ]; then
cp "$NVRTC_DIR/igneum-worker-cuda.exe" "$STAGE/"
for f in "$NVRTC_DIR"/redist/bin/nvrtc*.dll "$NVRTC_DIR"/redist/LICENSE-*.txt "$NVRTC_DIR/THIRD-PARTY.md"; do [ -f "$f" ] && cp "$f" "$STAGE/"; done
ls "$STAGE"/nvrtc64_*_0.dll >/dev/null 2>&1 || echo "warning: igneum-worker-cuda.exe without nvrtc64_*_0.dll (run $NVRTC_DIR/fetch-redist.sh)"
else echo "warning: no $NVRTC_DIR/igneum-worker-cuda.exe (run $NVRTC_DIR/build-windows.sh); the app will build the CUDA worker on the PC"; fi
[ -f "$CL_WORKER" ] && cp "$CL_WORKER" "$STAGE/" || echo "warning: no $CL_WORKER"
[ -f "$TELEMETRY" ] && cp "$TELEMETRY" "$STAGE/" || echo "warning: no $TELEMETRY (AMD cards show no draw or temperature)"
[ -f "$STAGE/igneum-worker-opencl.exe" ] || { [ -f "$CL_WORKER" ] && cp "$CL_WORKER" "$STAGE/" || echo "warning: no $CL_WORKER"; }
[ -f "$STAGE/igneum-gpu-telemetry.exe" ] || { [ -f "$TELEMETRY" ] && cp "$TELEMETRY" "$STAGE/" || echo "warning: no $TELEMETRY (AMD cards show no draw or temperature)"; }
# the signer, built from the app crate (it includes src/manifest.rs and src/inputs.rs, so it signs what the runner verifies)
KEY="$HOME/.config/igneum/ota-signing-key"

View file

@ -5,8 +5,42 @@
# site project (.vercel/project.json of ~/Projects/igneum/site). Reads nothing from GitHub. Prints the commit served and the
# production URL with the UTC time; the worktree is removed after.
#
# tools/site-deploy-from-mirror.sh [<commit or ref, default build/master>]
# tools/site-deploy-from-mirror.sh deploy the mirror's master (the ONLY ref a site deploy takes: main, 7 October
# 2026 21:2x UK, after a branch deploy was overwritten by the next master deploy)
# tools/site-deploy-from-mirror.sh --self-test-checks the post-deploy checks against the live site as it stands (known-failed first)
#
# POST-DEPLOY CHECKS (main, 7 October 2026 22:1x UK), before the edge time is printed: /api/live's network must equal LIVE_NETWORK
# (igneum-devnet-3), the index must carry INDEX_STRINGS (the launch-first chip line, the git.igneum.network link), LEGAL_PAGE must
# carry "Not legal advice" (the litepaper: no commit on master puts it on the index) and /miners must carry at least MINERS_MIN_ROWS table rows; any mismatch prints "DEPLOY RED <field>: ..." and exits 1. The
# edge serves the previous deployment for some seconds after the CLI returns, so the checks retry for up to 90 s before the verdict.
set -euo pipefail
LIVE_NETWORK="${LIVE_NETWORK:-igneum-devnet-3}"
INDEX_STRINGS=("At launch the strongest chip in our public model" "git.igneum.network/igneum-network/")
LEGAL_PAGE="${LEGAL_PAGE:-/litepaper}"; LEGAL_STRING="Not legal advice" # the legal line lives on the litepaper in master's tree (22:16 UK: no commit put it on the index)
MINERS_MIN_ROWS="${MINERS_MIN_ROWS:-30}"
SITE="${SITE_URL:-https://igneum.network}"
post_checks() { # one pass: prints the first mismatch as "field: detail" and returns 1, or returns 0 silently
local j n idx m rows
j=$(curl -fsS --max-time 20 "$SITE/api/live?x=$RANDOM" 2>/dev/null) || { echo "api/live: not reachable"; return 1; }
n=$(printf '%s' "$j" | python3 -c 'import sys,json; print(json.load(sys.stdin)["state"]["network"])' 2>/dev/null || echo "?")
[ "$n" = "$LIVE_NETWORK" ] || { echo "api/live network: $n (want $LIVE_NETWORK)"; return 1; }
idx=$(curl -fsS --max-time 20 "$SITE/?x=$RANDOM" 2>/dev/null) || { echo "index: not reachable"; return 1; }
for m in "${INDEX_STRINGS[@]}"; do printf '%s' "$idx" | /usr/bin/grep -qF -- "$m" || { echo "index string missing: \"$m\""; return 1; }; done
curl -fsS --max-time 20 "$SITE$LEGAL_PAGE?x=$RANDOM" 2>/dev/null | /usr/bin/grep -qiF -- "$LEGAL_STRING" || { echo "legal string missing on $LEGAL_PAGE: \"$LEGAL_STRING\""; return 1; }
rows=$(curl -fsS --max-time 20 "$SITE/miners?x=$RANDOM" 2>/dev/null | /usr/bin/grep -c '<tr class="row"' || true)
[ "${rows:-0}" -ge "$MINERS_MIN_ROWS" ] || { echo "miners rows: ${rows:-0} (want at least $MINERS_MIN_ROWS)"; return 1; }
echo "ok: api/live $n, ${#INDEX_STRINGS[@]} index strings, the legal line on $LEGAL_PAGE, $rows miners rows"
}
if [ "${1:-}" = --self-test-checks ]; then
# known-failed first: a network constant the live site cannot carry must read RED with the field; then the live read as it stands
LIVE_NETWORK="igneum-no-such-network" post_checks >/dev/null 2>&1 && { echo "post-deploy self-test: FAIL: a wrong network passed"; exit 1; }
out=$(LIVE_NETWORK="igneum-no-such-network" post_checks 2>&1 || true); case "$out" in "api/live network:"*) ;; *) echo "post-deploy self-test: FAIL: the wrong-network line was '$out'"; exit 1 ;; esac
INDEX_STRINGS=("no such string on any page 7f3a") LIVE_NETWORK="$(curl -fsS --max-time 20 "$SITE/api/live" | python3 -c 'import sys,json; print(json.load(sys.stdin)["state"]["network"])')" post_checks >/dev/null 2>&1 && { echo "post-deploy self-test: FAIL: a missing index string passed"; exit 1; }
echo "post-deploy self-test: a wrong network and a missing index string read RED with the field"
echo "live site now: $(post_checks 2>&1 || true)"
exit 0
fi
case "${1:-}" in "") ;; build/master|master) ;; *) echo "a site deploy takes the mirror's master only (main, 7 Oct 2026); no branch or commit argument" >&2; exit 2 ;; esac
cd "$(git rev-parse --show-toplevel)"
REF="${1:-build/master}"
git fetch -q build master
@ -26,5 +60,8 @@ echo "site export at $SHORT ($(git log -1 --format='%ci %s' "$SHA" | cut -c1-90)
echo "deploying $(TZ=UTC date +%H:%M:%SZ)"
OUT=$( cd "$W" && npx --yes vercel@latest --global-config "$HOME/.config/igneum/vercel" --scope igneum deploy --prod --yes 2>&1 ) || { echo "$OUT" | tail -5 >&2; exit 1; }
URL=$(echo "$OUT" | grep -oE 'https://[a-z0-9.-]*vercel\.app' | tail -1)
# the post-deploy checks, retried while the edge still serves the previous deployment (up to 90 s)
verdict=""; for i in $(seq 1 18); do verdict=$(post_checks 2>&1) && break; sleep 5; done
case "$verdict" in ok:*) echo "post-deploy checks $verdict" ;; *) echo "DEPLOY RED $verdict (commit $SHORT at the edge $URL, $(TZ=Europe/London date +%H:%M) BST)" >&2; exit 1 ;; esac
echo "SITE DEPLOYED commit $SHORT at $(TZ=UTC date +%H:%M:%SZ) UTC ($(TZ=Europe/London date +%H:%M) BST): $URL -> https://igneum.network"
echo "$OUT" | grep -iE "Production:|Aliased|error" | head -3