From bfc0f23a8812885cf66dd1d2d023e4ff63357692 Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Wed, 7 Oct 2026 18:52:48 +0000 Subject: [PATCH] No PC job raises a UAC prompt (standing rule, the project lead through main, 7 October 2026): publish-jobs.sh refuses --elevated; playbook-quit-check rule 3 fails a script that launches with -Verb RunAs or runas /user The known-failed case: run-ca3-pc1-v4-eff-5090-20261007 as published at 18:27Z (--elevated) waited two minutes for a click and died with exit 251, the card switched off for nothing. The rights path is the installed app's Igneum Power Helper task (app/igneum-app/src/powertask.rs: Start-ScheduledTask by the owning user, the fixed verbs through its cmd.txt), which tools/ca3-v4-amend/pc1-v4-efficiency.ps1 uses; a job without the task reports the fact and takes its measured-only rows. Self-tests: a -Verb RunAs launch fails, a Power Helper task start passes, the publisher refuses --elevated (exit 3). Co-Authored-By: Claude Fable 5.1 --- packaging/ota/publish-jobs.sh | 12 ++++++++++-- tools/ci/playbook-quit-check.sh | 15 ++++++++++++++- 2 files changed, 24 insertions(+), 3 deletions(-) diff --git a/packaging/ota/publish-jobs.sh b/packaging/ota/publish-jobs.sh index 38d2fdc2..f9dcfda9 100755 --- a/packaging/ota/publish-jobs.sh +++ b/packaging/ota/publish-jobs.sh @@ -9,7 +9,7 @@ # public key compiled into src/manifest.rs, runs each job that targets it ONCE per id, and reports to the log intake # as run_id job-- (read back with tools/jobs.mjs). # -# packaging/ota/publish-jobs.sh add --kind run --target 1ccfe586 --script path.ps1 [--elevated] [--stop-miners] \ +# packaging/ota/publish-jobs.sh add --kind run --target 1ccfe586 --script path.ps1 [--stop-miners] \ (--elevated is REFUSED: the 7 Oct 2026 no-prompt rule) # [--cards-off key,key] [--timeout-minutes 60] [--shell powershell|bash] --title "..." [--expires-hours 48] [--deploy] # (--cards-off: the RUNNER switches these cards off through the app's own card path before the script and puts them # back exactly on any exit, done, failed, timeout, aborted or the app quitting; keys with or without the device @@ -70,7 +70,15 @@ while [ $# -gt 0 ]; do --expires-hours) EXPIRES_H="$2"; shift 2 ;; --script) SCRIPT="$2"; shift 2 ;; --shell) SHELL_KIND="$2"; shift 2 ;; - --elevated) ELEVATED=1; shift ;; + --elevated) + # STANDING RULE (the project lead through main, 7 October 2026, 18:5x UTC): no PC job may raise a UAC prompt or need a click, ever. A run + # job published --elevated launches the script through an administrator prompt on the PC (the 18:27Z job + # run-ca3-pc1-v4-eff-5090-20261007 waited 2 minutes for a click and died with exit 251, the card switched off for nothing). + # Anything needing rights goes through the installed app's Igneum Power Helper task (app/igneum-app/src/powertask.rs, + # present when Power control is on); a job reads the task's presence first and, without it, reports + # "no elevation path: Power control off on " with the measured-only rows it can still take. The flag is refused here. + echo "publish-jobs: --elevated is refused (standing rule of 7 October 2026: no PC job raises a UAC prompt; use the Igneum Power Helper task from the script, see app/igneum-app/src/powertask.rs and tools/ca3-v4-amend/pc1-v4-efficiency.ps1)" >&2 + exit 3 ;; --stop-miners) STOP_MINERS=1; shift ;; --cards-off) CARDS_OFF="$2"; shift 2 ;; --timeout-minutes) TIMEOUT_MIN="$2"; shift 2 ;; diff --git a/tools/ci/playbook-quit-check.sh b/tools/ci/playbook-quit-check.sh index aa0f4841..9d3c4919 100755 --- a/tools/ci/playbook-quit-check.sh +++ b/tools/ci/playbook-quit-check.sh @@ -22,6 +22,14 @@ check_file() { if grep -vE '^\s*#' "$f" | grep -qE "api/cards"; then echo "playbook-quit: $f sends a request to the installed app's api/cards (a script never switches cards; ask the runner: publish-jobs.sh add --kind run --cards-off )"; bad=1 fi + # rule 3 (STANDING RULE, the project lead through main, 7 October 2026, 18:5x UTC): no PC job raises a UAC prompt or needs a click, ever. + # A script that launches anything with -Verb RunAs (or runas.exe) raises one; the rights path is the installed app's Igneum + # Power Helper task (Start-ScheduledTask by the owning user, commands through its cmd.txt: app/igneum-app/src/powertask.rs). + # publish-jobs.sh refuses --elevated for the same reason (the 18:27Z job run-ca3-pc1-v4-eff-5090-20261007: exit 251 after + # two minutes waiting for a click). + if grep -vE '^\s*#' "$f" | grep -qiE -e "(-Verb +['\"]?RunAs)|(\brunas(\.exe)? +/user)"; then + echo "playbook-quit: $f raises an administrator prompt (-Verb RunAs or runas): no PC job prompts; use the Igneum Power Helper task (app/igneum-app/src/powertask.rs)"; bad=1 + fi grep -qE "api/(quit|pause|resume)" "$f" || return $bad if grep -vE '^\s*#' "$f" | grep -qE "igneum\\\\app\\\\app\.url|igneum/app/app\.url|Application Support/Igneum/app/app\.url|IGNEUM_APP_DIR[^\n]*app\.url|\\\$appDir[^\n]*'app\.url'"; then echo "playbook-quit: $f reads the installed app's URL file and sends quit, pause or resume to it (a job may only quit an engine it started: its own scratch URL file)"; bad=1 @@ -38,7 +46,12 @@ if [ "${1:-}" = "--self-test" ]; then if ! check_file "$t/good.ps1"; then echo "self-test FAILED: the good playbook failed"; exit 1; fi if check_file "$t/cards.ps1" >/dev/null; then echo "self-test FAILED: the api/cards switch passed"; exit 1; fi if ! check_file "$t/state.ps1"; then echo "self-test FAILED: a read of api/state (api/cards only in a comment) failed"; exit 1; fi - rm -rf "$t"; echo "self-test passed: the installed app's URL file with a quit fails, a scratch URL file passes, a request to api/cards fails, a read of api/state passes"; exit 0 + printf '%s\n' '$p = Start-Process powershell.exe -Verb RunAs -ArgumentList @("-File", $s) -Wait -PassThru' > "$t/runas.ps1" + printf '%s\n' '# the old shape ran Start-Process -Verb RunAs; now the Power Helper task carries the rights' 'Start-ScheduledTask -TaskName "Igneum Power Helper"' > "$t/helper.ps1" + if check_file "$t/runas.ps1" >/dev/null; then echo "self-test FAILED: the RunAs launch passed"; exit 1; fi + if ! check_file "$t/helper.ps1"; then echo "self-test FAILED: the Power Helper task start (RunAs only in a comment) failed"; exit 1; fi + if ! bash packaging/ota/publish-jobs.sh add --kind run --target ae432dc7 --id self-test-elevated --elevated --script "$t/helper.ps1" --title "self-test" --dest "$t/dest" >/dev/null 2>&1; then :; else echo "self-test FAILED: publish-jobs.sh accepted --elevated (the 18:27Z job as published)"; exit 1; fi + rm -rf "$t"; echo "self-test passed: the installed app's URL file with a quit fails, a scratch URL file passes, a request to api/cards fails, a read of api/state passes, a -Verb RunAs launch fails, a Power Helper task start passes, publish-jobs.sh refuses --elevated"; exit 0 fi # allowed senders: the installer's own stop step (the update-now path the rule names), and, pending the rule owner's # word (6 October 2026, 15:10 UTC): tools/proving-v1/pc2-agg-cost.ps1 and its restore step pc2-agg-cost-restore.ps1, which switch the 5090 off through /api/cards