Stale-build class closed: every script that copies sources re-stamps them before building, CI check, repo rule

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
igneum-labs 2026-10-05 09:12:38 +00:00
parent 140fb8a898
commit 95ba619cd3
7 changed files with 33 additions and 1 deletions

View file

@ -61,5 +61,7 @@ jobs:
run: node tools/ci/link-check.mjs
- name: identity grep of the public export list
run: bash tools/ci/identity-check.sh
- name: copied sources are re-stamped before a build
run: bash tools/ci/copied-sources-check.sh
- name: relay unit tests (parsers, secret compare, the wake endpoint)
run: node --test relay/test/parse.test.mjs relay/test/auth.test.mjs relay/test/wake.test.mjs

View file

@ -284,6 +284,9 @@ pub fn extract_script(p: &BuildParams, job_id: &str, zip_wsl: &str) -> String {
s.push_str("rm -rf \"$B/src\" && mkdir -p \"$B/src\" && cp \"$ZIP\" \"$B/inputs.zip\" || { echo \"RESULT extract cannot copy the zip into $B\"; exit 2; }\n");
s.push_str("unzip -q -o \"$B/inputs.zip\" -d \"$B/src\" || { echo \"RESULT extract unzip failed\"; exit 2; }\n");
s.push_str("[ -f \"$SRC/manifest.json\" ] || { echo \"RESULT extract no manifest.json under $SRC\"; exit 2; }\n");
// the stale-build class (5 October 2026): the target dir persists and cargo rebuilds by mtime, so every extracted
// source is stamped now, else a file older than the last build links against the cached crate of the old version
s.push_str("find \"$B/src\" -type f -exec touch {} + 2>/dev/null || true\n");
s.push_str("echo \"RESULT extract ok $(find \"$B/src\" -type f | wc -l) files, $(du -sh \"$B/src\" | cut -f1) at $(now)\"\n");
s
}

View file

@ -20,7 +20,7 @@ fi
cd /root
if [ -f src.tar.gz ]; then
rm -rf src; tar -xzf src.tar.gz; log "unpacked src.tar.gz"
rm -rf src; tar -xzf src.tar.gz; find src -type f -exec touch {} +; log "unpacked src.tar.gz (sources re-stamped: cargo rebuilds by mtime)"
fi
[ -d src/vendor/igneum-node ] || { echo "no src/vendor/igneum-node"; exit 1; }
cd src/vendor/igneum-node

View file

@ -13,6 +13,8 @@ cp "$HERE/SETUP-PROVER.bat" "$HERE/setup-prover.ps1" "$HERE/setup-wsl.sh" "$HERE
rsync -a --exclude "target*" --exclude Cargo.lock "$ROOT/proving/igneum-prove" "$PKG/proving/"
cp "$ROOT/proving/igneum-prove/Cargo.lock" "$PKG/proving/igneum-prove/" 2>/dev/null || true
rsync -a "$ROOT/proving/fixtures" "$PKG/proving/"
# the package travels to a PC and is built there against a kept target dir: stamp every file now (cargo rebuilds by mtime)
find "$PKG" -type f -exec touch {} +
rsync -a --exclude target "$ROOT/vendor/igneum-node-exec/igneum/evm-types" "$PKG/vendor/igneum-node-exec/igneum/"
# evm-types inherits thiserror from the node's workspace; pin it inline (the node's Cargo.toml line 346: 2.0.18) so the crate builds alone.
perl -pi -e 's/^thiserror\.workspace = true/thiserror = { version = "2.0.18", default-features = false }/' "$PKG/vendor/igneum-node-exec/igneum/evm-types/Cargo.toml"

View file

@ -38,6 +38,9 @@ PY
# Fresh sources from the package (edits on the Windows side are picked up), build with the cuda feature.
mkdir -p "$DEST"
rsync -a --delete --exclude target "$HERE/package/" "$DEST/" 2>/dev/null || cp -r "$HERE/package/." "$DEST/"
# Re-stamp every copied source: rsync keeps the Mac's dates and cargo rebuilds by mtime, so a file older than the last build
# here would be taken as unchanged (the stale-build class, 4 and 5 October 2026).
find "$DEST" -path "$DEST/*/target" -prune -o -type f -exec touch {} + 2>/dev/null || true
cd "$DEST/proving/igneum-prove"
echo "building (first time: 10 to 30 minutes, approximate; both guests are compiled by cargo-prove inside the host build)"
if ! cargo build --release -p igneum-prove-host --features igneum-prove-host/cuda 2>&1 | tail -3; then

View file

@ -60,6 +60,9 @@ log "5/5 copying the proving sources into the Linux file system (cargo on /mnt/c
DEST="$HOME/igneum-prove"
mkdir -p "$DEST"
rsync -a --delete --exclude target "$HERE/package/" "$DEST/" 2>/dev/null || cp -r "$HERE/package/." "$DEST/"
# Re-stamp every copied source: rsync keeps the Mac's dates and cargo rebuilds by mtime, so a file older than the last build
# here would be taken as unchanged (the stale-build class, 4 and 5 October 2026).
find "$DEST" -path "$DEST/*/target" -prune -o -type f -exec touch {} + 2>/dev/null || true
cd "$DEST/proving/igneum-prove"
# The guest is built by host/build.rs through cargo-prove; the host links sp1-sdk with the cuda feature.
cargo build --release -p igneum-prove-export -p igneum-prove-host --features igneum-prove-host/cuda 2>&1 | tail -5

View file

@ -0,0 +1,19 @@
#!/usr/bin/env bash
# The stale-build class (4 and 5 October 2026): a script copies a source tree to another machine (rsync, unzip, tar,
# Expand-Archive keep the Mac's file dates) and builds it there against a cargo target dir that survives between
# runs; cargo rebuilds by mtime, so sources older than the last build are taken as unchanged and the new code links
# against stale crates (shard run 2 on 4 October, the 0.3.6 PC build on 5 October). Rule: every script that copies
# sources and then runs cargo re-stamps the copied files (`touch`) before building. This check fails CI when a
# script copies AND builds without a touch. Scripts that copy binaries only are listed in the allow list below.
set -euo pipefail
cd "$(dirname "$0")/../.."
ALLOW='^(packaging/windows/make-payload\.sh|app/igneum-app/src/jobrun\.rs)$'
fail=0
while IFS= read -r f; do
[[ "$f" =~ $ALLOW ]] && continue
if grep -qE 'rsync|unzip|tar -x|tar x|Expand-Archive|Copy-Item' "$f" && grep -qE 'cargo (build|test)' "$f"; then
if ! grep -qE '\btouch\b' "$f"; then echo "copied-sources: $f copies sources and runs cargo without re-stamping them (touch)"; fail=1; fi
fi
done < <(git ls-files 'packaging/**' 'proving/**' 'infra/**' 'tools/**' 'relay/playbooks/**' 'app/igneum-app/src/**' | grep -E '\.(sh|ps1|mjs|rs)$')
[ "$fail" = 0 ] && echo "copied-sources: every copying build script re-stamps its sources"
exit $fail